ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1030×

22 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAgrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

T1003.002
Security Account Manager
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

T1005
Data from Local System
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1018
Remote System Discovery
GroupAgrius

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

T1021.001
Remote Desktop Protocol
GroupAgrius

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.

T1036
Masquerading
GroupAgrius

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.

T1041
Exfiltration Over C2 Channel
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1046
Network Service Discovery
GroupAgrius

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.

T1059.003
Windows Command Shell
GroupAgrius

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

T1074.001
Local Data Staging
GroupAgrius

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

T1078.002
Domain Accounts
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1110
Brute Force
GroupAgrius

Agrius engaged in various brute forcing activities via SMB in victim environments.

T1110.003
Password Spraying
GroupAgrius

Agrius engaged in password spraying via SMB in victim environments.

T1119
Automated Collection
GroupAgrius

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

T1140
Deobfuscate/Decode Files or Information
GroupAgrius

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.

T1190
Exploit Public-Facing Application
GroupAgrius

Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity.

T1505.003
Web Shell
GroupAgrius

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.

T1543.003
Windows Service
GroupAgrius

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.

T1560.001
Archive via Utility
GroupAgrius

Agrius used 7zip to archive extracted data in preparation for exfiltration.

T1570
Lateral Tool Transfer
GroupAgrius

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.

T1583
Acquire Infrastructure
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

T1685
Disable or Modify Tools
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.