ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1052×

54 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.013
Encrypted/Encoded File
GroupContagious Interview

Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.

T1036
Masquerading
GroupContagious Interview

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

T1059.003
Windows Command Shell
GroupContagious Interview

Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file.

T1059.004
Unix Shell
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

T1059.005
Visual Basic
GroupContagious Interview

Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs.

T1059.006
Python
GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.007
JavaScript
GroupContagious Interview

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

T1070.004
File Deletion
GroupContagious Interview

Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration.

T1071.003
Mail Protocols
GroupContagious Interview

Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement.

T1082
System Information Discovery
GroupContagious Interview

Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser.

T1083
File and Directory Discovery
GroupContagious Interview

Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration.

T1090
Proxy
GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

T1204.001
Malicious Link
GroupContagious Interview

Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories.

T1204.002
Malicious File
GroupContagious Interview

Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test.

T1204.004
Malicious Copy and Paste
GroupContagious Interview

Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1219.002
Remote Desktop Software
GroupContagious Interview

Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities.

T1480
Execution Guardrails
GroupContagious Interview

Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads.

T1497
Virtualization/Sandbox Evasion
GroupContagious Interview

Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection.

T1543.001
Launch Agent
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist.

T1546.004
Unix Shell Configuration Modification
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`.

T1547.001
Registry Run Keys / Startup Folder
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder.

T1547.013
XDG Autostart Entries
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create a .desktop entry to run on startup on GNOME-based Linux devices.

T1555.001
Keychain
GroupContagious Interview

Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain.

T1566.003
Spearphishing via Service
GroupContagious Interview

Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims.

T1567
Exfiltration Over Web Service
GroupContagious Interview

Contagious Interview has leveraged Telegram API to exfiltrate stolen data.

T1567.002
Exfiltration to Cloud Storage
GroupContagious Interview

Contagious Interview has exfiltrated stolen passwords to Dropbox.

T1571
Non-Standard Port
GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

T1573.001
Symmetric Cryptography
GroupContagious Interview

Contagious Interview has encrypted C2 traffic using RC4.

T1583
Acquire Infrastructure
GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.003
Virtual Private Server
GroupContagious Interview

Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1585.001
Social Media Accounts
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1585.002
Email Accounts
GroupContagious Interview

Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1587.001
Malware
GroupContagious Interview

Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail.

T1588.002
Tool
GroupContagious Interview

Contagious Interview has used remote management and monitoring software such as “AnyDesk”.

T1588.007
Artificial Intelligence
GroupContagious Interview

Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns.

T1589
Gather Victim Identity Information
GroupContagious Interview

Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.

T1593
Search Open Websites/Domains
GroupContagious Interview

Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail.

T1593.001
Social Media
GroupContagious Interview

Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram.

T1593.003
Code Repositories
GroupContagious Interview

Contagious Interview had identified and solicited victims through code repositories such as GitHub.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

T1681
Search Threat Vendor Data
GroupContagious Interview

Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.