Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT38 | APT38 has collected data from a compromised host. |
| T1027.002 Software Packing |
GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1033 System Owner/User Discovery |
GroupAPT38 | APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT38 | APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| T1036.006 Space after Filename |
GroupAPT38 | APT38 has put several spaces before a file extension to avoid detection and suspicion. |
| T1049 System Network Connections Discovery |
GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1053.003 Cron |
GroupAPT38 | APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| T1053.005 Scheduled Task |
GroupAPT38 | APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| T1055 Process Injection |
GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1056.001 Keylogging |
GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1057 Process Discovery |
GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1059.001 PowerShell |
GroupAPT38 | APT38 has used PowerShell to execute commands and other operational tasks. |
| T1059.003 Windows Command Shell |
GroupAPT38 | APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1070.004 File Deletion |
GroupAPT38 | APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
| T1070.006 Timestomp |
GroupAPT38 | APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host. |
| T1071.001 Web Protocols |
GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| T1082 System Information Discovery |
GroupAPT38 | APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs. |
| T1083 File and Directory Discovery |
GroupAPT38 | APT38 have enumerated files and directories, or searched in specific locations within a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT38 | APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine. |
| T1106 Native API |
GroupAPT38 | APT38 has used the Windows API to execute code within a victim's system. |
| T1110 Brute Force |
GroupAPT38 | APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable. |
| T1112 Modify Registry |
GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| T1115 Clipboard Data |
GroupAPT38 | APT38 used a Trojan called KEYLIME to collect data from the clipboard. |
| T1135 Network Share Discovery |
GroupAPT38 | APT38 has enumerated network shares on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT38 | APT38 has used the RC4 algorithm to decrypt configuration data. |
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1204.001 Malicious Link |
GroupAPT38 | APT38 has used links to execute a malicious Visual Basic script. |
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1217 Browser Information Discovery |
GroupAPT38 | APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources. |
| T1218.001 Compiled HTML File |
GroupAPT38 | APT38 has used CHM files to move concealed payloads. |
| T1218.005 Mshta |
GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| T1218.007 Msiexec |
GroupAPT38 | APT38 has used `msiexec.exe` to execute malicious files. |
| T1218.011 Rundll32 |
GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| T1480.002 Mutual Exclusion |
GroupAPT38 | APT38 has created a mutex to avoid duplicate execution. |
| T1485 Data Destruction |
GroupAPT38 | APT38 has used a custom secure delete function to make deleted files unrecoverable. |
| T1486 Data Encrypted for Impact |
GroupAPT38 | APT38 has used Hermes ransomware to encrypt files with AES256. |
| T1505.003 Web Shell |
GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1529 System Shutdown/Reboot |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR. |
| T1543.003 Windows Service |
GroupAPT38 | APT38 has installed a new Windows service to establish persistence. |
| T1548.002 Bypass User Account Control |
GroupAPT38 | APT38 has used the legitimate application `ieinstal.exe` to bypass UAC. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT38 | APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures. |
| T1561.002 Disk Structure Wipe |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. |
| T1565.001 Stored Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions. |
| T1565.002 Transmitted Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer. |
| T1565.003 Runtime Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user. |
| T1566.001 Spearphishing Attachment |
GroupAPT38 | APT38 has conducted spearphishing campaigns using malicious email attachments. |
| T1569.002 Service Execution |
GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| T1583.001 Domains |
GroupAPT38 | APT38 has created fake domains to imitate legitimate venture capital or bank domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.