Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupCURIUM | CURIUM has exfiltrated data from a compromised machine. |
| T1041 Exfiltration Over C2 Channel |
GroupCURIUM | CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupCURIUM | CURIUM has used SMTPS to exfiltrate collected data from victims. |
| T1059.001 PowerShell |
GroupCURIUM | CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments. |
| T1082 System Information Discovery |
GroupCURIUM | CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information. |
| T1124 System Time Discovery |
GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| T1189 Drive-by Compromise |
GroupCURIUM | CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. |
| T1204.002 Malicious File |
GroupCURIUM | CURIUM has lured users into opening malicious files delivered via social media. |
| T1505.003 Web Shell |
GroupCURIUM | CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks. |
| T1566.001 Spearphishing Attachment |
GroupCURIUM | CURIUM has used phishing with malicious attachments for initial access to victim environments. |
| T1566.003 Spearphishing via Service |
GroupCURIUM | CURIUM has used social media to deliver malicious files to victims. |
| T1583.001 Domains |
GroupCURIUM | CURIUM created domains to facilitate strategic website compromise and credential capture activities. |
| T1583.003 Virtual Private Server |
GroupCURIUM | CURIUM created virtual private server instances to facilitate use of malicious domains and other items. |
| T1583.004 Server |
GroupCURIUM | CURIUM has created dedicated servers for command and control and exfiltration purposes. |
| T1584.006 Web Services |
GroupCURIUM | CURIUM has compromised legitimate websites to enable strategic website compromise attacks. |
| T1585.001 Social Media Accounts |
GroupCURIUM | CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman. |
| T1585.002 Email Accounts |
GroupCURIUM | CURIUM has created dedicated email accounts for use with tools such as IMAPLoader. |
| T1598.003 Spearphishing Link |
GroupCURIUM | CURIUM used malicious links to adversary-controlled resources for credential harvesting. |
| T1608.004 Drive-by Target |
GroupCURIUM | CURIUM used strategic website compromise to fingerprint then target victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.