ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0082×

56 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT38

APT38 has collected data from a compromised host.

T1027.002
Software Packing
GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1033
System Owner/User Discovery
GroupAPT38

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

T1036.003
Rename Legitimate Utilities
GroupAPT38

APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection.

T1036.006
Space after Filename
GroupAPT38

APT38 has put several spaces before a file extension to avoid detection and suspicion.

T1049
System Network Connections Discovery
GroupAPT38

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

T1053.003
Cron
GroupAPT38

APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system.

T1053.005
Scheduled Task
GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1055
Process Injection
GroupAPT38

APT38 has injected malicious payloads into the `explorer.exe` process.

T1056.001
Keylogging
GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1057
Process Discovery
GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1059.001
PowerShell
GroupAPT38

APT38 has used PowerShell to execute commands and other operational tasks.

T1059.003
Windows Command Shell
GroupAPT38

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1070.004
File Deletion
GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

T1070.006
Timestomp
GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1071.001
Web Protocols
GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

T1082
System Information Discovery
GroupAPT38

APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs.

T1083
File and Directory Discovery
GroupAPT38

APT38 have enumerated files and directories, or searched in specific locations within a compromised host.

T1105
Ingress Tool Transfer
GroupAPT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine.

T1106
Native API
GroupAPT38

APT38 has used the Windows API to execute code within a victim's system.

T1110
Brute Force
GroupAPT38

APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable.

T1112
Modify Registry
GroupAPT38

APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys.

T1115
Clipboard Data
GroupAPT38

APT38 used a Trojan called KEYLIME to collect data from the clipboard.

T1135
Network Share Discovery
GroupAPT38

APT38 has enumerated network shares on a compromised host.

T1140
Deobfuscate/Decode Files or Information
GroupAPT38

APT38 has used the RC4 algorithm to decrypt configuration data.

T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1204.001
Malicious Link
GroupAPT38

APT38 has used links to execute a malicious Visual Basic script.

T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1217
Browser Information Discovery
GroupAPT38

APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.

T1218.001
Compiled HTML File
GroupAPT38

APT38 has used CHM files to move concealed payloads.

T1218.005
Mshta
GroupAPT38

APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files.

T1218.007
Msiexec
GroupAPT38

APT38 has used `msiexec.exe` to execute malicious files.

T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1480.002
Mutual Exclusion
GroupAPT38

APT38 has created a mutex to avoid duplicate execution.

T1485
Data Destruction
GroupAPT38

APT38 has used a custom secure delete function to make deleted files unrecoverable.

T1486
Data Encrypted for Impact
GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

T1505.003
Web Shell
GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

T1518.001
Security Software Discovery
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

T1529
System Shutdown/Reboot
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR.

T1543.003
Windows Service
GroupAPT38

APT38 has installed a new Windows service to establish persistence.

T1548.002
Bypass User Account Control
GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

T1553.005
Mark-of-the-Web Bypass
GroupAPT38

APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures.

T1561.002
Disk Structure Wipe
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable.

T1565.001
Stored Data Manipulation
GroupAPT38

APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.

T1565.002
Transmitted Data Manipulation
GroupAPT38

APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer.

T1565.003
Runtime Data Manipulation
GroupAPT38

APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user.

T1566.001
Spearphishing Attachment
GroupAPT38

APT38 has conducted spearphishing campaigns using malicious email attachments.

T1569.002
Service Execution
GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

T1583.001
Domains
GroupAPT38

APT38 has created fake domains to imitate legitimate venture capital or bank domains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.