ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1114.001
Local Email Collection
MalwareSmoke Loader

Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.).

T1114.001
Local Email Collection
MalwareCosmicDuke

CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration.

T1114.001
Local Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

T1114.001
Local Email Collection
MalwareCrimson

Crimson contains a command to collect and exfiltrate emails from Outlook.

T1114.001
Local Email Collection
MalwareCarbanak

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.

T1114.001
Local Email Collection
MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

T1114.001
Local Email Collection
MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1114.001
Local Email Collection
ToolEmpire

Empire has the ability to collect emails on a target system.

T1114.001
Local Email Collection
ToolOut1

Out1 can parse e-mails on a target machine.

T1114.001
Local Email Collection
ToolPupy

Pupy can interact with a victim’s Outlook session and look through folders and emails.

T1114.002
Remote Email Collection
MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1114.002
Remote Email Collection
MalwareLightNeuron

LightNeuron collects Exchange emails matching rules specified in its configuration.

T1114.002
Remote Email Collection
MalwareValak

Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise.

T1114.002
Remote Email Collection
ToolMailSniper

MailSniper can be used for searching through email in Exchange and Office 365 environments.

T1115
Clipboard Data
MalwarePAKLOG

PAKLOG has monitored and extracted clipboard contents.

T1115
Clipboard Data
MalwareZeus Panda

Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect.

T1115
Clipboard Data
MalwareInvisibleFerret

InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations.

T1115
Clipboard Data
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard.

T1115
Clipboard Data
MalwareCosmicDuke

CosmicDuke copies and exfiltrates the clipboard contents every 30 seconds.

T1115
Clipboard Data
MalwareMachete

Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events.

T1115
Clipboard Data
MalwareFlawedAmmyy

FlawedAmmyy can collect clipboard data.

T1115
Clipboard Data
MalwareMispadu

Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host.

T1115
Clipboard Data
MalwareVERMIN

VERMIN collects data stored in the clipboard.

T1115
Clipboard Data
MalwareMarkiRAT

MarkiRAT can capture clipboard content.

T1115
Clipboard Data
MalwareDarkComet

DarkComet can steal data from the clipboard.

T1115
Clipboard Data
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture content from the clipboard.

T1115
Clipboard Data
MalwareDarkTortilla

DarkTortilla can download a clipboard information stealer module.

T1115
Clipboard Data
MalwareROKRAT

ROKRAT can extract clipboard data from a compromised host.

T1115
Clipboard Data
MalwareRunningRAT

RunningRAT contains code to open and copy data from the clipboard.

T1115
Clipboard Data
MalwareExplosive

Explosive has a function to use the OpenClipboard wrapper.

T1115
Clipboard Data
MalwareClambling

Clambling has the ability to capture and store clipboard data.

T1115
Clipboard Data
MalwareDarkGate

DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file.

T1115
Clipboard Data
MalwareMetamorfo

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.

T1115
Clipboard Data
MalwareKONNI

KONNI had a feature to steal data from the clipboard.

T1115
Clipboard Data
MalwareJHUHUGIT

A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.

T1115
Clipboard Data
MalwareCatchamas

Catchamas steals data stored in the clipboard.

T1115
Clipboard Data
MalwareAttor

Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs.

T1115
Clipboard Data
MalwareRTM

RTM collects data from the clipboard.

T1115
Clipboard Data
MalwareGrandoreiro

Grandoreiro can capture clipboard data from a compromised host.

T1115
Clipboard Data
MalwareXLoader

XLoader can collect data stored in the victim's clipboard.

T1115
Clipboard Data
MalwareMgBot

MgBot can capture clipboard data.

T1115
Clipboard Data
MalwareCadelspy

Cadelspy has the ability to steal data from the clipboard.

T1115
Clipboard Data
MalwareTajMahal

TajMahal has the ability to steal data from the clipboard of an infected host.

T1115
Clipboard Data
MalwareTinyZBot

TinyZBot contains functionality to collect information from the clipboard.

T1115
Clipboard Data
MalwareMelcoz

Melcoz can monitor content saved to the clipboard.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1115
Clipboard Data
MalwareRemexi

Remexi collects text from the clipboard.

T1115
Clipboard Data
MalwareAstaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries.

T1115
Clipboard Data
MalwarejRAT

jRAT can capture clipboard data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.