ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1033×

196 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareTrickBot

TrickBot can identify the user and groups the user belongs to on a compromised host.

T1033
System Owner/User Discovery
MalwarePowerDuke

PowerDuke has commands to get the current user's name and SID.

T1033
System Owner/User Discovery
MalwareRCSession

RCSession can gather system owner information, including user and administrator privileges.

T1033
System Owner/User Discovery
MalwareSpark

Spark has run the whoami command and has a built-in command to identify the user logged in.

T1033
System Owner/User Discovery
MalwareSynAck

SynAck gathers user names from infected hosts.

T1033
System Owner/User Discovery
MalwareBumblebee

Bumblebee has the ability to identify the user name.

T1033
System Owner/User Discovery
MalwareAmadey

Amadey has collected the user name from a compromised host using `GetUserNameA`.

T1033
System Owner/User Discovery
MalwareNOKKI

NOKKI can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
Malwareyty

yty collects the victim’s username.

T1033
System Owner/User Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects the current username from the victim.

T1033
System Owner/User Discovery
MalwareIronWind

IronWind can enumerate the username on victim's systems.

T1033
System Owner/User Discovery
MalwareGet2

Get2 has the ability to identify the current username of an infected host.

T1033
System Owner/User Discovery
MalwarePOWRUNER

POWRUNER may collect information about the currently logged in user by running whoami on a victim.

T1033
System Owner/User Discovery
MalwareKOPILUWAK

KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details.

T1033
System Owner/User Discovery
MalwareLinux Rabbit

Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain.

T1033
System Owner/User Discovery
MalwareExaramel for Linux

Exaramel for Linux can run whoami to identify the system owner.

T1033
System Owner/User Discovery
MalwareHAWKBALL

HAWKBALL can collect the user name of the system.

T1033
System Owner/User Discovery
MalwareRedLeaves

RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions.

T1033
System Owner/User Discovery
MalwareFelismus

Felismus collects the current username and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareHavoc

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1033
System Owner/User Discovery
MalwareGravityRAT

GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status).

T1033
System Owner/User Discovery
MalwareInvisibleFerret

InvisibleFerret has identified the user’s UUID and username through the "pay" module.

T1033
System Owner/User Discovery
MalwareHAPPYWORK

can collect the victim user name.

T1033
System Owner/User Discovery
MalwareWinMM

WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system.

T1033
System Owner/User Discovery
MalwareTONESHELL

TONESHELL has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwarePyDCrypt

PyDCrypt has probed victim machines with whoami and has collected the username from the machine.

T1033
System Owner/User Discovery
MalwareBOOKWORM

BOOKWORM has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwareSslMM

SslMM sends the logged-on username to its hard-coded C2.

T1033
System Owner/User Discovery
MalwareAria-body

Aria-body has the ability to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareEmotet

Emotet has enumerated all users connected to network shares.

T1033
System Owner/User Discovery
MalwareCrimson

Crimson can identify the user on a targeted system.

T1033
System Owner/User Discovery
MalwareTurian

Turian can retrieve usernames.

T1033
System Owner/User Discovery
MalwareBADHATCH

BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`.

T1033
System Owner/User Discovery
MalwareAction RAT

Action RAT has the ability to collect the username from an infected host.

T1033
System Owner/User Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about the current user name.

T1033
System Owner/User Discovery
MalwarePUBLOAD

PUBLOAD has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwareWellMess

WellMess can collect the username on the victim machine to send to C2.

T1033
System Owner/User Discovery
MalwareWoody RAT

Woody RAT can retrieve a list of user accounts and usernames from an infected machine.

T1033
System Owner/User Discovery
MalwareMafalda

Mafalda can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareSquirrelwaffle

Squirrelwaffle can collect the user name from a compromised host.

T1033
System Owner/User Discovery
MalwareHexEval Loader

HexEval Loader has collected the username from the victim host.

T1033
System Owner/User Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareAgent.btz

Agent.btz obtains the victim username and saves it to a file.

T1033
System Owner/User Discovery
MalwareSombRAT

SombRAT can execute getinfo to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareFlawedAmmyy

FlawedAmmyy enumerates the current user during the initial infection.

T1033
System Owner/User Discovery
MalwareRifdoor

Rifdoor has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can discover and send the username from a compromised host to C2.

T1033
System Owner/User Discovery
MalwareInvisiMole

InvisiMole lists local users and session information.

T1033
System Owner/User Discovery
MalwareWINERACK

WINERACK can gather information on the victim username.

T1033
System Owner/User Discovery
MalwareOkrum

Okrum can collect the victim username.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.