Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
GroupConfucius | Confucius has exfiltrated stolen files to its C2 server. |
| T1053.005 Scheduled Task |
GroupConfucius | Confucius has created scheduled tasks to maintain persistence on a compromised host. |
| T1059.001 PowerShell |
GroupConfucius | Confucius has used PowerShell to execute malicious files and payloads. |
| T1059.005 Visual Basic |
GroupConfucius | Confucius has used VBScript to execute malicious code. |
| T1071.001 Web Protocols |
GroupConfucius | Confucius has used HTTP for C2 communications. |
| T1083 File and Directory Discovery |
GroupConfucius | Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions. |
| T1105 Ingress Tool Transfer |
GroupConfucius | Confucius has downloaded additional files and payloads onto a compromised host following initial access. |
| T1119 Automated Collection |
GroupConfucius | Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
| T1203 Exploitation for Client Execution |
GroupConfucius | Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802. |
| T1204.001 Malicious Link |
GroupConfucius | Confucius has lured victims into clicking on a malicious link sent through spearphishing. |
| T1204.002 Malicious File |
GroupConfucius | Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics. |
| T1218.005 Mshta |
GroupConfucius | Confucius has used mshta.exe to execute malicious VBScript. |
| T1221 Template Injection |
GroupConfucius | Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupConfucius | Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence. |
| T1566.001 Spearphishing Attachment |
GroupConfucius | Confucius has crafted and sent victims malicious attachments to gain initial access. |
| T1566.002 Spearphishing Link |
GroupConfucius | Confucius has sent malicious links to victims through email campaigns. |
| T1567.002 Exfiltration to Cloud Storage |
GroupConfucius | Confucius has exfiltrated victim data to cloud storage service accounts. |
| T1583.006 Web Services |
GroupConfucius | Confucius has obtained cloud storage service accounts to host stolen data. |
| T1680 Local Storage Discovery |
GroupConfucius | Confucius has used a file stealer that can examine system drives, including those other than the C drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.