Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupLuminousMoth | LuminousMoth has collected files and data from compromised machines. |
| T1030 Data Transfer Size Limits |
GroupLuminousMoth | LuminousMoth has split archived files into multiple parts to bypass a 5MB limit. |
| T1033 System Owner/User Discovery |
GroupLuminousMoth | LuminousMoth has used a malicious DLL to collect the username from compromised hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLuminousMoth | LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`. |
| T1041 Exfiltration Over C2 Channel |
GroupLuminousMoth | LuminousMoth has used malware that exfiltrates stolen data to its C2 server. |
| T1053.005 Scheduled Task |
GroupLuminousMoth | LuminousMoth has created scheduled tasks to establish persistence for their tools. |
| T1071.001 Web Protocols |
GroupLuminousMoth | LuminousMoth has used HTTP for C2. |
| T1083 File and Directory Discovery |
GroupLuminousMoth | LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives. |
| T1091 Replication Through Removable Media |
GroupLuminousMoth | LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| T1105 Ingress Tool Transfer |
GroupLuminousMoth | LuminousMoth has downloaded additional malware and tools onto a compromised host. |
| T1112 Modify Registry |
GroupLuminousMoth | LuminousMoth has used malware that adds Registry keys for persistence. |
| T1204.001 Malicious Link |
GroupLuminousMoth | LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing. |
| T1539 Steal Web Session Cookie |
GroupLuminousMoth | LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLuminousMoth | LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`. |
| T1553.002 Code Signing |
GroupLuminousMoth | LuminousMoth has signed their malware with a valid digital signature. |
| T1557.002 ARP Cache Poisoning |
GroupLuminousMoth | LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website. |
| T1560 Archive Collected Data |
GroupLuminousMoth | LuminousMoth has manually archived stolen files from victim machines before exfiltration. |
| T1564.001 Hidden Files and Directories |
GroupLuminousMoth | LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives. |
| T1566.002 Spearphishing Link |
GroupLuminousMoth | LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLuminousMoth | LuminousMoth has exfiltrated data to Google Drive. |
| T1574.001 DLL |
GroupLuminousMoth | LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware. |
| T1587.001 Malware |
GroupLuminousMoth | LuminousMoth has used unique malware for information theft and exfiltration. |
| T1588.001 Malware |
GroupLuminousMoth | LuminousMoth has obtained and used malware such as Cobalt Strike. |
| T1588.002 Tool |
GroupLuminousMoth | LuminousMoth has obtained an ARP spoofing tool from GitHub. |
| T1588.004 Digital Certificates |
GroupLuminousMoth | LuminousMoth has used a valid digital certificate for some of their malware. |
| T1608.001 Upload Malware |
GroupLuminousMoth | LuminousMoth has hosted malicious payloads on Dropbox. |
| T1608.004 Drive-by Target |
GroupLuminousMoth | LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection. |
| T1608.005 Link Target |
GroupLuminousMoth | LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.