Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
GroupStorm-1811 | Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator. |
| T1033 System Owner/User Discovery |
GroupFIN7 | FIN7 has used the command `cmd.exe /C quser` to collect user session information. |
| T1033 System Owner/User Discovery |
GroupSandworm Team | Sandworm Team has collected the username from a compromised host. |
| T1033 System Owner/User Discovery |
GroupSidewinder | Sidewinder has used tools to identify the user of a compromised host. |
| T1033 System Owner/User Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2. |
| T1033 System Owner/User Discovery |
GroupAPT39 | |
| T1033 System Owner/User Discovery |
GroupAPT37 | APT37 identifies the victim username. |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1033 System Owner/User Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1033 System Owner/User Discovery |
GroupAquatic Panda | Aquatic Panda gathers information on recently logged-in users on victim devices. |
| T1033 System Owner/User Discovery |
GroupKe3chang | Ke3chang has used implants capable of collecting the signed-in username. |
| T1033 System Owner/User Discovery |
GroupWinter Vivern | Winter Vivern PowerShell scripts execute `whoami` to identify the executing user. |
| T1033 System Owner/User Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the registered user and primary owner name via WMI. |
| T1033 System Owner/User Discovery |
GroupChimera | Chimera has used the |
| T1033 System Owner/User Discovery |
GroupMirrorFace | MirrorFace has used Windows native tools to enumerate user information. |
| T1033 System Owner/User Discovery |
GroupMedusa Group | Medusa Group has utilized PsExec to execute `quser` to discover the user session information. |
| T1033 System Owner/User Discovery |
GroupWindshift | Windshift has used malware to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
GroupLuminousMoth | LuminousMoth has used a malicious DLL to collect the username from compromised hosts. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1033 System Owner/User Discovery |
GroupEarth Lusca | Earth Lusca collected information on user accounts via the |
| T1033 System Owner/User Discovery |
GroupWizard Spider | Wizard Spider has used "whoami" to identify the local user and their privileges. |
| T1033 System Owner/User Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions. |
| T1033 System Owner/User Discovery |
GroupHEXANE | HEXANE has run `whoami` on compromised machines to identify the current user. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1033 System Owner/User Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `whoami` to collect system user information. |
| T1033 System Owner/User Discovery |
GroupFIN10 | FIN10 has used Meterpreter to enumerate users on remote systems. |
| T1033 System Owner/User Discovery |
GroupFIN8 | FIN8 has executed the command `quser` to display the session details of a compromised machine. |
| T1033 System Owner/User Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
| T1036 Masquerading |
GroupmenuPass | menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files. |
| T1036 Masquerading |
GroupAPT32 | APT32 has disguised a Cobalt Strike beacon as a Flash Installer. |
| T1036 Masquerading |
GroupStorm-1811 | Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations. |
| T1036 Masquerading |
GroupTeamTNT | TeamTNT has disguised their scripts with docker-related file names. |
| T1036 Masquerading |
GroupSandworm Team | Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries. |
| T1036 Masquerading |
GroupZIRCONIUM | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1036 Masquerading |
GroupContagious Interview | Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Sekoia ClickFake 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1036 Masquerading |
GroupOilRig | OilRig has used .doc file extensions to mask malicious executables. |
| T1036 Masquerading |
GroupAoqin Dragon | Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads. |
| T1036 Masquerading |
GroupWinter Vivern | Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns. |
| T1036 Masquerading |
GroupBRONZE BUTLER | BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| T1036 Masquerading |
GroupTA551 | TA551 has masked malware DLLs as dat and jpg files. |
| T1036 Masquerading |
GroupEmber Bear | Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| T1036 Masquerading |
GroupLazyScripter | LazyScripter has used several different security software icons to disguise executables. |
| T1036 Masquerading |
GroupWindshift | Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1036 Masquerading |
GroupAgrius | Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| T1036 Masquerading |
GroupAPT28 | APT28 has renamed the WinRAR utility to avoid detection. |
| T1036 Masquerading |
GroupPLATINUM | PLATINUM has renamed rar.exe to avoid detection. |
| T1036 Masquerading |
GroupFIN13 | FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file. |
| T1036 Masquerading |
GroupNomadic Octopus | Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface. |
| T1036.001 Invalid Code Signature |
GroupAPT37 | APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.” |
| T1036.001 Invalid Code Signature |
GroupWindshift | Windshift has used revoked certificates to sign malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.