ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0143×

35 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAquatic Panda

Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.

T1005
Data from Local System
GroupAquatic Panda

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1007
System Service Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

T1021
Remote Services
GroupAquatic Panda

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.

T1021.001
Remote Desktop Protocol
GroupAquatic Panda

Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.

T1021.002
SMB/Windows Admin Shares
GroupAquatic Panda

Aquatic Panda used remote shares to enable lateral movement in victim environments.

T1021.004
SSH
GroupAquatic Panda

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.

T1027.010
Command Obfuscation
GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

T1033
System Owner/User Discovery
GroupAquatic Panda

Aquatic Panda gathers information on recently logged-in users on victim devices.

T1036.004
Masquerade Task or Service
GroupAquatic Panda

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

T1036.005
Match Legitimate Resource Name or Location
GroupAquatic Panda

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.

T1047
Windows Management Instrumentation
GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

T1059.001
PowerShell
GroupAquatic Panda

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.

T1059.003
Windows Command Shell
GroupAquatic Panda

Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to cmd /C.

T1059.004
Unix Shell
GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

T1070.003
Clear Command History
GroupAquatic Panda

Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.

T1070.004
File Deletion
GroupAquatic Panda

Aquatic Panda has deleted malicious executables from compromised machines.

T1078.002
Domain Accounts
GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

T1082
System Information Discovery
GroupAquatic Panda

Aquatic Panda has used native OS commands to understand privilege levels and system details.

T1087
Account Discovery
GroupAquatic Panda

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.

T1105
Ingress Tool Transfer
GroupAquatic Panda

Aquatic Panda has downloaded additional malware onto compromised hosts.

T1112
Modify Registry
GroupAquatic Panda

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.

T1218.011
Rundll32
GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

T1518.001
Security Software Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.

T1543.003
Windows Service
GroupAquatic Panda

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

T1550.002
Pass the Hash
GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

T1560.001
Archive via Utility
GroupAquatic Panda

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1574.006
Dynamic Linker Hijacking
GroupAquatic Panda

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.

T1588.001
Malware
GroupAquatic Panda

Aquatic Panda has acquired and used njRAT in its operations.

T1588.002
Tool
GroupAquatic Panda

Aquatic Panda has acquired and used Cobalt Strike in its operations.

T1595.002
Vulnerability Scanning
GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

T1654
Log Enumeration
GroupAquatic Panda

Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.

T1685
Disable or Modify Tools
GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

T1685.005
Clear Windows Event Logs
GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.