Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1114.001 Local Email Collection |
MalwareSmoke Loader | Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.). |
| T1114.001 Local Email Collection |
MalwareCosmicDuke | CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration. |
| T1114.001 Local Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that scrapes email data from Outlook. |
| T1114.001 Local Email Collection |
MalwareCrimson | Crimson contains a command to collect and exfiltrate emails from Outlook. |
| T1114.001 Local Email Collection |
MalwareCarbanak | Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server. |
| T1114.001 Local Email Collection |
MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| T1114.001 Local Email Collection |
MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| T1114.001 Local Email Collection |
MalwareQakBot | QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns. |
| T1114.001 Local Email Collection |
ToolEmpire | Empire has the ability to collect emails on a target system. |
| T1114.001 Local Email Collection |
ToolOut1 | Out1 can parse e-mails on a target machine. |
| T1114.001 Local Email Collection |
ToolPupy | Pupy can interact with a victim’s Outlook session and look through folders and emails. |
| T1114.002 Remote Email Collection |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1114.002 Remote Email Collection |
MalwareLightNeuron | LightNeuron collects Exchange emails matching rules specified in its configuration. |
| T1114.002 Remote Email Collection |
MalwareValak | Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise. |
| T1114.002 Remote Email Collection |
ToolMailSniper | MailSniper can be used for searching through email in Exchange and Office 365 environments. |
| T1115 Clipboard Data |
MalwarePAKLOG | PAKLOG has monitored and extracted clipboard contents. |
| T1115 Clipboard Data |
MalwareZeus Panda | Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect. |
| T1115 Clipboard Data |
MalwareInvisibleFerret | InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations. |
| T1115 Clipboard Data |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
| T1115 Clipboard Data |
MalwareCosmicDuke | CosmicDuke copies and exfiltrates the clipboard contents every 30 seconds. |
| T1115 Clipboard Data |
MalwareMachete | Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events. |
| T1115 Clipboard Data |
MalwareFlawedAmmyy | FlawedAmmyy can collect clipboard data. |
| T1115 Clipboard Data |
MalwareMispadu | Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host. |
| T1115 Clipboard Data |
MalwareVERMIN | VERMIN collects data stored in the clipboard. |
| T1115 Clipboard Data |
MalwareMarkiRAT | MarkiRAT can capture clipboard content. |
| T1115 Clipboard Data |
MalwareDarkComet | DarkComet can steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture content from the clipboard. |
| T1115 Clipboard Data |
MalwareDarkTortilla | DarkTortilla can download a clipboard information stealer module. |
| T1115 Clipboard Data |
MalwareROKRAT | ROKRAT can extract clipboard data from a compromised host. |
| T1115 Clipboard Data |
MalwareRunningRAT | RunningRAT contains code to open and copy data from the clipboard. |
| T1115 Clipboard Data |
MalwareExplosive | Explosive has a function to use the OpenClipboard wrapper. |
| T1115 Clipboard Data |
MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| T1115 Clipboard Data |
MalwareDarkGate | DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file. |
| T1115 Clipboard Data |
MalwareMetamorfo | Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's. |
| T1115 Clipboard Data |
MalwareKONNI | KONNI had a feature to steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareJHUHUGIT | A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image. |
| T1115 Clipboard Data |
MalwareCatchamas | Catchamas steals data stored in the clipboard. |
| T1115 Clipboard Data |
MalwareAttor | Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs. |
| T1115 Clipboard Data |
MalwareRTM | RTM collects data from the clipboard. |
| T1115 Clipboard Data |
MalwareGrandoreiro | Grandoreiro can capture clipboard data from a compromised host. |
| T1115 Clipboard Data |
MalwareXLoader | XLoader can collect data stored in the victim's clipboard. |
| T1115 Clipboard Data |
MalwareMgBot | MgBot can capture clipboard data. |
| T1115 Clipboard Data |
MalwareCadelspy | Cadelspy has the ability to steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareTajMahal | TajMahal has the ability to steal data from the clipboard of an infected host. |
| T1115 Clipboard Data |
MalwareTinyZBot | TinyZBot contains functionality to collect information from the clipboard. |
| T1115 Clipboard Data |
MalwareMelcoz | Melcoz can monitor content saved to the clipboard. |
| T1115 Clipboard Data |
MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| T1115 Clipboard Data |
MalwareRemexi | Remexi collects text from the clipboard. |
| T1115 Clipboard Data |
MalwareAstaroth | Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. |
| T1115 Clipboard Data |
MalwarejRAT | jRAT can capture clipboard data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.