ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

169 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTrickBot

TrickBot collects local files and information from the victim’s local machine.

T1005
Data from Local System
MalwareBLINDINGCAN

BLINDINGCAN has uploaded files from victim machines.

T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1005
Data from Local System
MalwareQuietSieve

QuietSieve can collect files from a compromised host.

T1005
Data from Local System
MalwareBumblebee

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1005
Data from Local System
MalwareBRICKSTORM

BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.

T1005
Data from Local System
MalwareAmadey

Amadey can collect information from a compromised host.

T1005
Data from Local System
MalwareProxysvc

Proxysvc searches the local system and gathers data.

T1005
Data from Local System
Malwareyty

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.

T1005
Data from Local System
MalwareKOPILUWAK

KOPILUWAK can gather information from compromised hosts.

T1005
Data from Local System
MalwareSardonic

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1005
Data from Local System
MalwareMisdat

Misdat has collected files and data from a compromised host.

T1005
Data from Local System
MalwareUrsnif

Ursnif has collected files from victim machines, including certificates and cookies.

T1005
Data from Local System
MalwareCASTLETAP

CASTLETAP can execute a C2 command to transfer files from victim machines.

T1005
Data from Local System
MalwareThreatNeedle

ThreatNeedle can collect data and files from a compromised host.

T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1005
Data from Local System
MalwareFrameworkPOS

FrameworkPOS can collect elements related to credit card data from process memory.

T1005
Data from Local System
MalwareGravityRAT

GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1005
Data from Local System
MalwareInvisibleFerret

InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password.

T1005
Data from Local System
MalwareBankshot

Bankshot collects files from the local system.

T1005
Data from Local System
MalwareSharpDisco

SharpDisco has dropped a recent-files stealer plugin to `C:\Users\Public\WinSrcNT\It11.exe`.

T1005
Data from Local System
MalwarexCaon

xCaon has uploaded files from victims' machines.

T1005
Data from Local System
MalwareNebulae

Nebulae has the capability to upload collected files to C2.

T1005
Data from Local System
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host.

T1005
Data from Local System
MalwareAppleSeed

AppleSeed can collect data on a compromised host.

T1005
Data from Local System
MalwareTinyTurla

TinyTurla can upload files from a compromised host.

T1005
Data from Local System
MalwareCosmicDuke

CosmicDuke steals user files from local hard drives with file extensions that match a predefined list.

T1005
Data from Local System
MalwareEnvyScout

EnvyScout can collect sensitive NTLM material from a compromised host.

T1005
Data from Local System
MalwareCrimson

Crimson can collect information from a compromised host.

T1005
Data from Local System
MalwareTomiris

Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration.

T1005
Data from Local System
MalwareDUSTTRAP

DUSTTRAP can gather data from infected systems.

T1005
Data from Local System
MalwareMachete

Machete searches the File system for files of interest.

T1005
Data from Local System
MalwarePowerLess

PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines.

T1005
Data from Local System
MalwareAction RAT

Action RAT can collect local data from an infected machine.

T1005
Data from Local System
MalwarePingPull

PingPull can collect data from a compromised host.

T1005
Data from Local System
MalwareWellMess

WellMess can send files from the victim machine to C2.

T1005
Data from Local System
MalwareWoody RAT

Woody RAT can collect information from a compromised host.

T1005
Data from Local System
MalwareMafalda

Mafalda can collect files and information from a compromised host.

T1005
Data from Local System
MalwareAuTo Stealer

AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.

T1005
Data from Local System
MalwareSombRAT

SombRAT has collected data and files from a compromised host.

T1005
Data from Local System
MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book.

T1005
Data from Local System
MalwareFlawedAmmyy

FlawedAmmyy has collected information and files from a compromised machine.

T1005
Data from Local System
MalwareLoFiSe

LoFiSe can collect files of interest from targeted systems.

T1005
Data from Local System
MalwareMobileOrder

MobileOrder exfiltrates data collected from the victim mobile device.

T1005
Data from Local System
MalwareInvisiMole

InvisiMole can collect data from the system, and can monitor changes in specified directories.

T1005
Data from Local System
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to copy files on a compromised host.

T1005
Data from Local System
MalwareNeoichor

Neoichor can upload files from a victim's machine.

T1005
Data from Local System
MalwareMarkiRAT

MarkiRAT can upload data from the victim's machine to the C2 server.

T1005
Data from Local System
MalwareKazuar

Kazuar uploads files from a specified directory to the C2 server.

T1005
Data from Local System
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can collect files from compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.