ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1564.005
Hidden File System
GroupStrider

Strider has used a hidden file system that is stored as a file on disk.

T1564.005
Hidden File System
GroupEquation

Equation has used an encrypted virtual file system stored in the Windows Registry.

T1564.008
Email Hiding Rules
GroupScattered Spider

Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products.

T1564.008
Email Hiding Rules
GroupFIN4

FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities.

T1564.011
Ignore Process Interrupts
GroupKimsuky

Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events.

T1564.011
Ignore Process Interrupts
GroupUNC3886

UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted.

T1564.011
Ignore Process Interrupts
GroupSea Turtle

Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.

T1564.012
File/Path Exclusions
GroupTurla

Turla has placed LunarWeb install files into directories that are excluded from scanning.

T1565
Data Manipulation
GroupFIN13

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.

T1565.001
Stored Data Manipulation
GroupAPT38

APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.

T1565.002
Transmitted Data Manipulation
GroupAPT38

APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer.

T1565.003
Runtime Data Manipulation
GroupAPT38

APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user.

T1566
Phishing
GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

T1566
Phishing
GroupAppleJeus

AppleJeus has used spearphishing emails to distribute malicious payloads.

T1566
Phishing
GroupMuddyWater

MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.

T1566
Phishing
GroupSea Turtle

Sea Turtle used spear phishing to gain initial access to victims.

T1566
Phishing
GroupAxiom

Axiom has used spear phishing to initially compromise victims.

T1566
Phishing
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines.

T1566
Phishing
GroupINC Ransom

INC Ransom has used phishing to gain initial access.

T1566
Phishing
GroupVOID MANTICORE

VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector.

T1566.001
Spearphishing Attachment
GroupAPT38

APT38 has conducted spearphishing campaigns using malicious email attachments.

T1566.001
Spearphishing Attachment
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupSideCopy

SideCopy has sent spearphishing emails with malicious hta file attachments.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1566.001
Spearphishing Attachment
GroupEXOTIC LILY

EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments.

T1566.001
Spearphishing Attachment
Groupadmin@338

admin@338 has sent emails with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1566.001
Spearphishing Attachment
GroupAPT41

APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.

T1566.001
Spearphishing Attachment
GroupDragonfly

Dragonfly has sent emails with malicious attachments to gain initial access.

T1566.001
Spearphishing Attachment
GroupGorgon Group

Gorgon Group sent emails to victims with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1566.001
Spearphishing Attachment
GroupNaikon

Naikon has used malicious e-mail attachments to deliver malware.

T1566.001
Spearphishing Attachment
GroupFIN6

FIN6 has targeted victims with e-mails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1566.001
Spearphishing Attachment
GroupGallmaker

Gallmaker sent emails with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

T1566.001
Spearphishing Attachment
GroupMachete

Machete has delivered spearphishing emails that contain a zipped file with malicious contents.

T1566.001
Spearphishing Attachment
GroupAndariel

Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments.

T1566.001
Spearphishing Attachment
GroupCURIUM

CURIUM has used phishing with malicious attachments for initial access to victim environments.

T1566.001
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments often crafted for specific targets.

T1566.001
Spearphishing Attachment
GroupMustang Panda

Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

T1566.001
Spearphishing Attachment
GroupTA2541

TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents.

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

T1566.001
Spearphishing Attachment
GroupHigaisa

Higaisa has sent spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.