ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1552.001
Credentials In Files
GroupTA505

TA505 has used malware to gather credentials from FTP clients and Outlook.

T1552.001
Credentials In Files
GroupRedCurl

RedCurl used LaZagne to obtain passwords in files.

T1552.001
Credentials In Files
GroupEmber Bear

Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials.

T1552.001
Credentials In Files
GroupFox Kitten

Fox Kitten has accessed files to gain valid credentials.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.001
Credentials In Files
GroupFIN13

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.

T1552.001
Credentials In Files
GroupShinyHunters

ShinyHunters has gathered PII from database infrastructure.

T1552.002
Credentials in Registry
GroupAPT32

APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry.

T1552.002
Credentials in Registry
GroupRedCurl

RedCurl used LaZagne to obtain passwords in the Registry.

T1552.002
Credentials in Registry
GroupVOID MANTICORE

VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM.

T1552.004
Private Keys
GroupKimsuky

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.

T1552.004
Private Keys
GroupVolt Typhoon

Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser.

T1552.004
Private Keys
GroupTeamTNT

TeamTNT has searched for unsecured SSH keys.

T1552.004
Private Keys
GroupRocke

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.

T1552.004
Private Keys
GroupScattered Spider

Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host.

T1552.004
Private Keys
GroupStorm-0501

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.

T1552.004
Private Keys
GroupTeamPCP

TeamPCP has used malware to extract SSH and GPG keys from victim environments.

T1552.005
Cloud Instance Metadata API
GroupTeamTNT

TeamTNT has queried the AWS instance metadata service for credentials.

T1552.006
Group Policy Preferences
GroupWizard Spider

Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy.

T1552.006
Group Policy Preferences
GroupAPT33

APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.

T1552.008
Chat Messages
GroupLAPSUS$

LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.

T1553
Subvert Trust Controls
GroupAxiom

Axiom has used digital certificates to deliver malware.

T1553.002
Code Signing
GroupGALLIUM

GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC.

T1553.002
Code Signing
GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

T1553.002
Code Signing
GroupPatchwork

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1553.002
Code Signing
GroupmenuPass

menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures.

T1553.002
Code Signing
GroupFIN6

FIN6 has used Comodo code-signing certificates.

T1553.002
Code Signing
GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
GroupScattered Spider

Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC.

T1553.002
Code Signing
GroupMoses Staff

Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.

T1553.002
Code Signing
GroupOilRig

OilRig has signed its malware with stolen certificates.

T1553.002
Code Signing
GroupSuckfly

Suckfly has used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupSaint Bear

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

T1553.002
Code Signing
GroupMirrorFace

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.

T1553.002
Code Signing
GroupMedusa Group

Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

T1553.002
Code Signing
GroupLuminousMoth

LuminousMoth has signed their malware with a valid digital signature.

T1553.002
Code Signing
GroupWinnti Group

Winnti Group used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupLazarus Group

Lazarus Group has digitally signed malware and utilities to evade detection.

T1553.002
Code Signing
GroupSilence

Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot).

T1553.002
Code Signing
GroupCopyKittens

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

T1553.002
Code Signing
GroupWizard Spider

Wizard Spider has used Digicert code-signing certificates for some of its malware.

T1553.002
Code Signing
GroupMolerats

Molerats has used forged Microsoft code-signing certificates on malware.

T1553.002
Code Signing
GroupPROMETHIUM

PROMETHIUM has signed code with self-signed certificates.

T1553.002
Code Signing
GroupDaggerfly

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

T1553.002
Code Signing
GroupTeamPCP

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.