Real-world descriptions of how a group, tool or campaign used a technique.
48 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1012 Query Registry |
GroupBlackByte | BlackByte queried registry values to determine system language settings. |
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1018 Remote System Discovery |
GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1021.001 Remote Desktop Protocol |
GroupBlackByte | BlackByte has used RDP to access other hosts within victim networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1036.008 Masquerade File Type |
GroupBlackByte | BlackByte masqueraded configuration files containing encryption keys as PNG files. |
| T1041 Exfiltration Over C2 Channel |
GroupBlackByte | BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1046 Network Service Discovery |
GroupBlackByte | BlackByte has used tools such as NetScan to enumerate network services in victim environments. |
| T1047 Windows Management Instrumentation |
GroupBlackByte | BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| T1053.005 Scheduled Task |
GroupBlackByte | BlackByte created scheduled tasks for payload execution. |
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1055.012 Process Hollowing |
GroupBlackByte | BlackByte used process hollowing for defense evasion purposes. |
| T1059.001 PowerShell |
GroupBlackByte | BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1059.003 Windows Command Shell |
GroupBlackByte | BlackByte executed ransomware using the Windows command shell. |
| T1068 Exploitation for Privilege Escalation |
GroupBlackByte | BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1071.001 Web Protocols |
GroupBlackByte | BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure. |
| T1078 Valid Accounts |
GroupBlackByte | BlackByte has gained access to victim environments through legitimate VPN credentials. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1087.002 Domain Account |
GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| T1105 Ingress Tool Transfer |
GroupBlackByte | BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1134.003 Make and Impersonate Token |
GroupBlackByte | BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution. |
| T1135 Network Share Discovery |
GroupBlackByte | BlackByte enumerated network shares on victim devices. |
| T1136.002 Domain Account |
GroupBlackByte | BlackByte created privileged domain accounts during intrusions. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
| T1480 Execution Guardrails |
GroupBlackByte | BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute. |
| T1482 Domain Trust Discovery |
GroupBlackByte | BlackByte enumerated Active Directory information and trust relationships during operations. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1490 Inhibit System Recovery |
GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| T1491.001 Internal Defacement |
GroupBlackByte | BlackByte left ransom notes in all directories where encryption takes place. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1518.001 Security Software Discovery |
GroupBlackByte | BlackByte enumerated installed security products during operations. |
| T1543.003 Windows Service |
GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBlackByte | BlackByte has used Registry Run keys for persistence. |
| T1560 Archive Collected Data |
GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| T1567 Exfiltration Over Web Service |
GroupBlackByte | BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1570 Lateral Tool Transfer |
GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| T1583.003 Virtual Private Server |
GroupBlackByte | BlackByte staged encryption keys on virtual private servers operated by the adversary. |
| T1608.001 Upload Malware |
GroupBlackByte | BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites. |
| T1614.001 System Language Discovery |
GroupBlackByte | BlackByte identified system language settings to determine follow-on execution. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.