ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1043×

48 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1012
Query Registry
GroupBlackByte

BlackByte queried registry values to determine system language settings.

T1016
System Network Configuration Discovery
GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1018
Remote System Discovery
GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

T1021.001
Remote Desktop Protocol
GroupBlackByte

BlackByte has used RDP to access other hosts within victim networks.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1036.008
Masquerade File Type
GroupBlackByte

BlackByte masqueraded configuration files containing encryption keys as PNG files.

T1041
Exfiltration Over C2 Channel
GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1046
Network Service Discovery
GroupBlackByte

BlackByte has used tools such as NetScan to enumerate network services in victim environments.

T1047
Windows Management Instrumentation
GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1053.005
Scheduled Task
GroupBlackByte

BlackByte created scheduled tasks for payload execution.

T1055
Process Injection
GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1055.012
Process Hollowing
GroupBlackByte

BlackByte used process hollowing for defense evasion purposes.

T1059.001
PowerShell
GroupBlackByte

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1059.003
Windows Command Shell
GroupBlackByte

BlackByte executed ransomware using the Windows command shell.

T1068
Exploitation for Privilege Escalation
GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1071.001
Web Protocols
GroupBlackByte

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.

T1078
Valid Accounts
GroupBlackByte

BlackByte has gained access to victim environments through legitimate VPN credentials.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1087.002
Domain Account
GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

T1105
Ingress Tool Transfer
GroupBlackByte

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.

T1112
Modify Registry
GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

T1134.003
Make and Impersonate Token
GroupBlackByte

BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.

T1135
Network Share Discovery
GroupBlackByte

BlackByte enumerated network shares on victim devices.

T1136.002
Domain Account
GroupBlackByte

BlackByte created privileged domain accounts during intrusions.

T1140
Deobfuscate/Decode Files or Information
GroupBlackByte

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender.

T1190
Exploit Public-Facing Application
GroupBlackByte

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.

T1219
Remote Access Tools
GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

T1480
Execution Guardrails
GroupBlackByte

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.

T1482
Domain Trust Discovery
GroupBlackByte

BlackByte enumerated Active Directory information and trust relationships during operations.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1490
Inhibit System Recovery
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

T1491.001
Internal Defacement
GroupBlackByte

BlackByte left ransom notes in all directories where encryption takes place.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1518.001
Security Software Discovery
GroupBlackByte

BlackByte enumerated installed security products during operations.

T1543.003
Windows Service
GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

T1547.001
Registry Run Keys / Startup Folder
GroupBlackByte

BlackByte has used Registry Run keys for persistence.

T1560
Archive Collected Data
GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

T1567
Exfiltration Over Web Service
GroupBlackByte

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1570
Lateral Tool Transfer
GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

T1583.003
Virtual Private Server
GroupBlackByte

BlackByte staged encryption keys on virtual private servers operated by the adversary.

T1608.001
Upload Malware
GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

T1614.001
System Language Discovery
GroupBlackByte

BlackByte identified system language settings to determine follow-on execution.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.