Real-world descriptions of how a group, tool or campaign used a technique.
42 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
GroupIndrik Spider | Indrik Spider has used WMIC to execute commands on remote computers. |
| T1047 Windows Management Instrumentation |
GroupBlackByte | BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| T1047 Windows Management Instrumentation |
GroupGALLIUM | GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1047 Windows Management Instrumentation |
GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| T1047 Windows Management Instrumentation |
GroupmenuPass | menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
| T1047 Windows Management Instrumentation |
GroupAPT32 | APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1047 Windows Management Instrumentation |
GroupNaikon | Naikon has used WMIC.exe for lateral movement. |
| T1047 Windows Management Instrumentation |
GroupFIN6 | FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1047 Windows Management Instrumentation |
GroupFIN7 | FIN7 has used WMI to install malware on targeted systems. |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1047 Windows Management Instrumentation |
GroupMustang Panda | Mustang Panda has executed PowerShell scripts via WMI. |
| T1047 Windows Management Instrumentation |
GroupTA2541 | TA2541 has used WMI to query targeted systems for security products. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| T1047 Windows Management Instrumentation |
GroupLeviathan | Leviathan has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe to set environment variables. |
| T1047 Windows Management Instrumentation |
GroupLotus Blossom | Lotus Blossom has used WMI to enable lateral movement. |
| T1047 Windows Management Instrumentation |
GroupStealth Falcon | Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI). |
| T1047 Windows Management Instrumentation |
GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1047 Windows Management Instrumentation |
GroupCinnamon Tempest | Cinnamon Tempest has used Impacket for lateral movement via WMI. |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1047 Windows Management Instrumentation |
GroupMirrorFace | MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1047 Windows Management Instrumentation |
GroupMedusa Group | Medusa Group has utilized Windows Management Instrumentation to query system information. |
| T1047 Windows Management Instrumentation |
GroupDeep Panda | The Deep Panda group is known to utilize WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
GroupEmber Bear | Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupWindshift | Windshift has used WMI to collect information about target machines. |
| T1047 Windows Management Instrumentation |
GroupToddyCat | ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1047 Windows Management Instrumentation |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
GroupAPT-C-36 | APT-C-36 has used WMI to execute PowerShell. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupEarth Lusca | Earth Lusca used a VBA script to execute WMI. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupVelvet Ant | Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI. |
| T1047 Windows Management Instrumentation |
GroupVOID MANTICORE | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1047 Windows Management Instrumentation |
GroupMagic Hound | Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
| T1047 Windows Management Instrumentation |
GroupThreat Group-3390 | A Threat Group-3390 tool can use WMI to execute a binary. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1047 Windows Management Instrumentation |
GroupFIN13 | FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.