Real-world descriptions of how a group, tool or campaign used a technique.
151 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
MalwareRCSession | RCSession can capture screenshots from a compromised host. |
| T1113 Screen Capture |
MalwareQuietSieve | QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`. |
| T1113 Screen Capture |
MalwareGRIFFON | GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system. |
| T1113 Screen Capture |
Malwareyty | yty collects screenshots of the victim machine. |
| T1113 Screen Capture |
MalwareDOGCALL | DOGCALL is capable of capturing screenshots of the victim's machine. |
| T1113 Screen Capture |
MalwarePOWRUNER | POWRUNER can capture a screenshot from a victim. |
| T1113 Screen Capture |
MalwareSharpStage | SharpStage has the ability to capture the victim's screen. |
| T1113 Screen Capture |
MalwareHALFBAKED | HALFBAKED can obtain screenshots from the victim. |
| T1113 Screen Capture |
MalwareKEYMARBLE | KEYMARBLE can capture screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareUrsnif | Ursnif has used hooked APIs to take screenshots. |
| T1113 Screen Capture |
MalwareZLib | ZLib has the ability to obtain screenshots of the compromised system. |
| T1113 Screen Capture |
MalwareRedLeaves | RedLeaves can capture screenshots. |
| T1113 Screen Capture |
MalwareZeus Panda | Zeus Panda can take screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
| T1113 Screen Capture |
MalwareMatryoshka | Matryoshka is capable of performing screen captures. |
| T1113 Screen Capture |
MalwareJanicab | Janicab captured screenshots and sent them out to a C2 server. |
| T1113 Screen Capture |
MalwareTONESHELL | TONESHELL has conducted screen capturing. |
| T1113 Screen Capture |
MalwareKasidet | Kasidet has the ability to initiate keylogging and screen captures. |
| T1113 Screen Capture |
MalwareRainyDay | RainyDay has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| T1113 Screen Capture |
MalwareNETWIRE | NETWIRE can capture the victim's screen. |
| T1113 Screen Capture |
MalwareCosmicDuke | CosmicDuke takes periodic screenshots and exfiltrates them. |
| T1113 Screen Capture |
MalwareEvilGrab | EvilGrab has the capability to capture screenshots. |
| T1113 Screen Capture |
MalwareAria-body | Aria-body has the ability to capture screenshots on compromised hosts. |
| T1113 Screen Capture |
MalwareCrimson | Crimson contains a command to perform screen captures. |
| T1113 Screen Capture |
MalwareDUSTTRAP | DUSTTRAP can capture screenshots. |
| T1113 Screen Capture |
MalwareTurian | Turian has the ability to take screenshots. |
| T1113 Screen Capture |
MalwareBADHATCH | BADHATCH can take screenshots and send them to an actor-controlled C2 server. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1113 Screen Capture |
MalwarePrikormka | Prikormka contains a module that captures screenshots of the victim's desktop. |
| T1113 Screen Capture |
MalwareWoody RAT | Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+. |
| T1113 Screen Capture |
MalwareMafalda | Mafalda can take a screenshot of the target machine and save it to a file. |
| T1113 Screen Capture |
MalwareSHUTTERSPEED | SHUTTERSPEED can capture screenshots. |
| T1113 Screen Capture |
MalwareFlawedAmmyy | FlawedAmmyy can capture screenshots. |
| T1113 Screen Capture |
MalwareCuckoo Stealer | Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts. |
| T1113 Screen Capture |
MalwareInvisiMole | InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping. |
| T1113 Screen Capture |
MalwareFruitFly | FruitFly takes screenshots of the user's desktop. |
| T1113 Screen Capture |
MalwareRDAT | RDAT can take a screenshot on the infected system. |
| T1113 Screen Capture |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag. |
| T1113 Screen Capture |
MalwareMispadu | Mispadu has the ability to capture screenshots on compromised hosts. |
| T1113 Screen Capture |
MalwareVERMIN | VERMIN can perform screen captures of the victim’s machine. |
| T1113 Screen Capture |
MalwareHTTPTroy | HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server. |
| T1113 Screen Capture |
MalwareMarkiRAT | MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’. |
| T1113 Screen Capture |
MalwareKazuar | Kazuar captures screenshots of the victim’s screen. |
| T1113 Screen Capture |
MalwarePOORAIM | POORAIM can perform screen capturing. |
| T1113 Screen Capture |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk. |
| T1113 Screen Capture |
MalwareBlackEnergy | BlackEnergy is capable of taking screenshots. |
| T1113 Screen Capture |
MalwareChrommme | Chrommme has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareObliqueRAT | ObliqueRAT can capture a screenshot of the current screen. |
| T1113 Screen Capture |
MalwareXAgentOSX | XAgentOSX contains the takeScreenShot (along with startTakeScreenShot and stopTakeScreenShot) functions to take screenshots using the CGGetActiveDisplayList, CGDisplayCreateImage, and NSImage:initWithCGImage methods. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.