ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0099×

38 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.013
Encrypted/Encoded File
GroupAPT-C-36

APT-C-36 has used encoded and obfuscated files, images, and executables.

T1027.016
Junk Code Insertion
GroupAPT-C-36

APT-C-36 has used junk characters to obfuscate malicious scripts.

T1036.004
Masquerade Task or Service
GroupAPT-C-36

APT-C-36 has disguised its scheduled tasks as those used by Google.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT-C-36

APT-C-36 has disguised malicious executables to appear as legitimate files.

T1047
Windows Management Instrumentation
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

T1053.005
Scheduled Task
GroupAPT-C-36

APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.

T1055.012
Process Hollowing
GroupAPT-C-36

APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes.

T1059.001
PowerShell
GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1059.007
JavaScript
GroupAPT-C-36

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

T1105
Ingress Tool Transfer
GroupAPT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

T1133
External Remote Services
GroupAPT-C-36

APT-C-36 has used VPNs in their operational infrastructure.

T1204.001
Malicious Link
GroupAPT-C-36

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1480
Execution Guardrails
GroupAPT-C-36

APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites.

T1534
Internal Spearphishing
GroupAPT-C-36

APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization.

T1564.003
Hidden Window
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

T1566.001
Spearphishing Attachment
GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

T1566.002
Spearphishing Link
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1571
Non-Standard Port
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

T1574.001
DLL
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.003
Virtual Private Server
GroupAPT-C-36

APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1584.005
Botnet
GroupAPT-C-36

APT-C-36 has used a botnet management interface to control large numbers of compromised hosts.

T1586.002
Email Accounts
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

T1586.003
Cloud Accounts
GroupAPT-C-36

APT-C-36 has used compromised Google Drive accounts including one associated with a Colombian government organization.

T1587.001
Malware
GroupAPT-C-36

APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1588.002
Tool
GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

T1593
Search Open Websites/Domains
GroupAPT-C-36

APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1683.001
Written Content
GroupAPT-C-36

APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads.

T1683.002
Audio-Visual Content
GroupAPT-C-36

APT-C-36 has used phishing pages appearing like legitimate banking login portals to compromise credentials.

T1684.001
Impersonation
GroupAPT-C-36

APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.