Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1027.013 Encrypted/Encoded File |
GroupDarkhotel | Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupDarkhotel | Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1056.001 Keylogging |
GroupDarkhotel | Darkhotel has used a keylogger. |
| T1057 Process Discovery |
GroupDarkhotel | Darkhotel malware can collect a list of running processes on a system. |
| T1059.003 Windows Command Shell |
GroupDarkhotel | Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file. |
| T1080 Taint Shared Content |
GroupDarkhotel | Darkhotel used a virus that propagates by infecting executables stored on shared drives. |
| T1082 System Information Discovery |
GroupDarkhotel | Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine. |
| T1083 File and Directory Discovery |
GroupDarkhotel | Darkhotel has used malware that searched for files with specific patterns. |
| T1091 Replication Through Removable Media |
GroupDarkhotel | Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| T1105 Ingress Tool Transfer |
GroupDarkhotel | Darkhotel has used first-stage payloads that download additional malware from C2 servers. |
| T1124 System Time Discovery |
GroupDarkhotel | Darkhotel malware can obtain system time from a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
GroupDarkhotel | Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1189 Drive-by Compromise |
GroupDarkhotel | Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1203 Exploitation for Client Execution |
GroupDarkhotel | Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution. |
| T1204.002 Malicious File |
GroupDarkhotel | Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments. |
| T1497 Virtualization/Sandbox Evasion |
GroupDarkhotel | Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection. |
| T1497.001 System Checks |
GroupDarkhotel | Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with |
| T1497.002 User Activity Based Checks |
GroupDarkhotel | Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system. |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDarkhotel | Darkhotel has been known to establish persistence by adding programs to the Run Registry key. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| T1566.001 Spearphishing Attachment |
GroupDarkhotel | Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments. |
| T1573.001 Symmetric Cryptography |
GroupDarkhotel | Darkhotel has used AES-256 and 3DES for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.