ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1023×

29 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT5

APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive.

T1003.002
Security Account Manager
GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1021.001
Remote Desktop Protocol
GroupAPT5

APT5 has moved laterally throughout victim environments using RDP.

T1021.004
SSH
GroupAPT5

APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT5

APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern.

T1049
System Network Connections Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

T1053.003
Cron
GroupAPT5

APT5 has made modifications to the crontab file including in `/var/cron/tabs/`.

T1055
Process Injection
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

T1056.001
Keylogging
GroupAPT5

APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities.

T1057
Process Discovery
GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1059.001
PowerShell
GroupAPT5

APT5 has used PowerShell to accomplish tasks within targeted environments.

T1059.003
Windows Command Shell
GroupAPT5

APT5 has used cmd.exe for execution on compromised systems.

T1070
Indicator Removal
GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070.003
Clear Command History
GroupAPT5

APT5 has cleared the command history on targeted ESXi servers.

T1070.004
File Deletion
GroupAPT5

APT5 has deleted scripts and web shells to evade detection.

T1070.006
Timestomp
GroupAPT5

APT5 has modified file timestamps.

T1074.001
Local Data Staging
GroupAPT5

APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`.

T1078.002
Domain Accounts
GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

T1078.004
Cloud Accounts
GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

T1083
File and Directory Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs.

T1098.007
Additional Local or Domain Groups
GroupAPT5

APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation.

T1136.001
Local Account
GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

T1190
Exploit Public-Facing Application
GroupAPT5

APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers.

T1505.003
Web Shell
GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

T1554
Compromise Host Software Binary
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

T1560.001
Archive via Utility
GroupAPT5

APT5 has used the JAR/ZIP file format for exfiltrated files.

T1583.005
Botnet
GroupAPT5

APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities.

T1654
Log Enumeration
GroupAPT5

APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs.

T1685
Disable or Modify Tools
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.