Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupBlue Mockingbird | Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory. |
| T1021.001 Remote Desktop Protocol |
GroupBlue Mockingbird | Blue Mockingbird has used Remote Desktop to log on to servers interactively and manually copy files to remote hosts. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB. |
| T1027.013 Encrypted/Encoded File |
GroupBlue Mockingbird | Blue Mockingbird has obfuscated the wallet address in the payload binary. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBlue Mockingbird | Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file. |
| T1047 Windows Management Instrumentation |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe to set environment variables. |
| T1053.005 Scheduled Task |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts. |
| T1059.001 PowerShell |
GroupBlue Mockingbird | Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection. |
| T1059.003 Windows Command Shell |
GroupBlue Mockingbird | Blue Mockingbird has used batch script files to automate execution and deployment of payloads. |
| T1082 System Information Discovery |
GroupBlue Mockingbird | Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information. |
| T1090 Proxy |
GroupBlue Mockingbird | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections. |
| T1112 Modify Registry |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload. |
| T1134 Access Token Manipulation |
GroupBlue Mockingbird | Blue Mockingbird has used JuicyPotato to abuse the |
| T1190 Exploit Public-Facing Application |
GroupBlue Mockingbird | Blue Mockingbird has gained initial access by exploiting CVE-2019-18935, a vulnerability within Telerik UI for ASP.NET AJAX. |
| T1218.010 Regsvr32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe. |
| T1218.011 Rundll32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe. |
| T1496.001 Compute Hijacking |
GroupBlue Mockingbird | Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems. |
| T1543.003 Windows Service |
GroupBlue Mockingbird | Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupBlue Mockingbird | Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file. |
| T1569.002 Service Execution |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service. |
| T1574.012 COR_PROFILER |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR. |
| T1588.002 Tool |
GroupBlue Mockingbird | Blue Mockingbird has obtained and used tools such as Mimikatz. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.