ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1124
System Time Discovery
MalwareAgent Tesla

Agent Tesla can collect the timestamp from the victim’s machine.

T1124
System Time Discovery
MalwareStarProxy

StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value.

T1124
System Time Discovery
MalwareShadowPad

ShadowPad has collected the current date and time of the victim system.

T1124
System Time Discovery
MalwareAstaroth

Astaroth collects the timestamp from the infected machine.

T1124
System Time Discovery
MalwareQakBot

QakBot can identify the system time on a targeted host.

T1124
System Time Discovery
MalwareDEADWOOD

DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately.

T1124
System Time Discovery
MalwareAzorult

Azorult can collect the time zone information from the system.

T1124
System Time Discovery
MalwareUPPERCUT

UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine.

T1124
System Time Discovery
MalwareStrifeWater

StrifeWater can collect the time zone from the victim's machine.

T1124
System Time Discovery
ToolNet

The net time command can be used in Net to determine the local or remote system time.

T1124
System Time Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect start time information from a compromised host.

T1124
System Time Discovery
ToolAsyncRAT

AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration.

T1124
System Time Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host.

T1124
System Time Discovery
MalwareCanisterWorm

CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.”

T1125
Video Capture
MalwareEvilGrab

EvilGrab has the capability to capture video from a victim machine.

T1125
Video Capture
MalwareCrimson

Crimson can capture webcam video on targeted systems.

T1125
Video Capture
MalwareMachete

Machete takes photos from the computer’s web camera.

T1125
Video Capture
MalwareInvisiMole

InvisiMole can remotely activate the victim’s webcam to capture content.

T1125
Video Capture
MalwareKazuar

Kazuar captures images from the webcam.

T1125
Video Capture
MalwareDarkComet

DarkComet can access the victim’s webcam to take pictures.

T1125
Video Capture
MalwareObliqueRAT

ObliqueRAT can capture images from webcams on compromised hosts.

T1125
Video Capture
MalwareClambling

Clambling can record screen content in AVI format.

T1125
Video Capture
MalwareBandook

Bandook has modules that are capable of capturing video from a victim's webcam.

T1125
Video Capture
MalwareT9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.

T1125
Video Capture
MalwareSDBbot

SDBbot has the ability to record video on a compromised host.

T1125
Video Capture
MalwareDerusbi

Derusbi is capable of capturing video.

T1125
Video Capture
MalwareCobian RAT

Cobian RAT has a feature to access the webcam on the victim’s machine.

T1125
Video Capture
MalwareNanoCore

NanoCore can access the victim's webcam and capture data.

T1125
Video Capture
MalwareTajMahal

TajMahal has the ability to capture webcam video.

T1125
Video Capture
MalwareRevenge RAT

Revenge RAT has the ability to access the webcam.

T1125
Video Capture
MalwarePoetRAT

PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts.

T1125
Video Capture
MalwareZxShell

ZxShell has a command to perform video device spying.

T1125
Video Capture
MalwarenjRAT

njRAT can access the victim's webcam.

T1125
Video Capture
MalwareAgent Tesla

Agent Tesla can access the victim’s webcam and record video.

T1125
Video Capture
MalwarejRAT

jRAT has the capability to capture video from a webcam.

T1125
Video Capture
MalwareWarzoneRAT

WarzoneRAT can access the webcam on a victim's machine.

T1125
Video Capture
ToolEmpire

Empire can capture webcam data on Windows and macOS systems.

T1125
Video Capture
ToolPcShare

PcShare can capture camera video as part of its collection process.

T1125
Video Capture
ToolAsyncRAT

AsyncRAT can record screen content on targeted systems.

T1125
Video Capture
ToolRemcos

Remcos can access a system’s webcam and take pictures.

T1125
Video Capture
ToolConnectWise

ConnectWise can record video on remote hosts.

T1125
Video Capture
ToolImminent Monitor

Imminent Monitor has a remote webcam monitoring capability.

T1125
Video Capture
ToolPupy

Pupy can access a connected webcam and capture pictures.

T1125
Video Capture
ToolQuasarRAT

QuasarRAT can perform webcam viewing.

T1125
Video Capture
ToolQuick Assist

Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity.

T1127.001
MSBuild
MalwarePlugX

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.

T1127.001
MSBuild
MalwareNOOPLDR

NOOPLDR can be executed via MSBuild.

T1127.001
MSBuild
ToolEmpire

Empire can use built-in modules to abuse trusted utilities like MSBuild.exe.

T1129
Shared Modules
MalwareBLINDINGCAN

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

T1129
Shared Modules
MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.