ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0142×

19 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

T1053.005
Scheduled Task
GroupConfucius

Confucius has created scheduled tasks to maintain persistence on a compromised host.

T1059.001
PowerShell
GroupConfucius

Confucius has used PowerShell to execute malicious files and payloads.

T1059.005
Visual Basic
GroupConfucius

Confucius has used VBScript to execute malicious code.

T1071.001
Web Protocols
GroupConfucius

Confucius has used HTTP for C2 communications.

T1083
File and Directory Discovery
GroupConfucius

Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions.

T1105
Ingress Tool Transfer
GroupConfucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1119
Automated Collection
GroupConfucius

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

T1203
Exploitation for Client Execution
GroupConfucius

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.

T1204.001
Malicious Link
GroupConfucius

Confucius has lured victims into clicking on a malicious link sent through spearphishing.

T1204.002
Malicious File
GroupConfucius

Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics.

T1218.005
Mshta
GroupConfucius

Confucius has used mshta.exe to execute malicious VBScript.

T1221
Template Injection
GroupConfucius

Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit.

T1547.001
Registry Run Keys / Startup Folder
GroupConfucius

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.

T1566.001
Spearphishing Attachment
GroupConfucius

Confucius has crafted and sent victims malicious attachments to gain initial access.

T1566.002
Spearphishing Link
GroupConfucius

Confucius has sent malicious links to victims through email campaigns.

T1567.002
Exfiltration to Cloud Storage
GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

T1583.006
Web Services
GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

T1680
Local Storage Discovery
GroupConfucius

Confucius has used a file stealer that can examine system drives, including those other than the C drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.