ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
ToolIronNetInjector

IronNetInjector has the ability to decrypt embedded .NET and PE payloads.

T1140
Deobfuscate/Decode Files or Information
ToolExpand

Expand can be used to decompress a local or remote CAB file into an executable.

T1140
Deobfuscate/Decode Files or Information
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to decrypt obfuscated payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareCanisterWorm

CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload.

T1140
Deobfuscate/Decode Files or Information
MalwareBADFLICK

BADFLICK can decode shellcode using a custom rotating XOR cipher.

T1176.001
Browser Extensions
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.

T1176.001
Browser Extensions
MalwareMispadu

Mispadu utilizes malicious Google Chrome browser extensions to steal financial data.

T1176.001
Browser Extensions
MalwareLumma Stealer

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

T1176.001
Browser Extensions
MalwareBundlore

Bundlore can install malicious browser extensions that are used to hijack user searches.

T1176.001
Browser Extensions
MalwareGrandoreiro

Grandoreiro can use malicious browser extensions to steal cookies and other user information.

T1176.001
Browser Extensions
MalwareOSX/Shlayer

OSX/Shlayer can install malicious Safari browser extensions to serve ads.

T1185
Browser Session Hijacking
MalwareTrickBot

TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page.

T1185
Browser Session Hijacking
MalwareUrsnif

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).

T1185
Browser Session Hijacking
MalwareTRANSLATEXT

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1185
Browser Session Hijacking
MalwareChaes

Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1185
Browser Session Hijacking
MalwareXLoader

XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1185
Browser Session Hijacking
MalwareMelcoz

Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background.

T1185
Browser Session Hijacking
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareQakBot

QakBot can use advanced web injects to steal web banking credentials.

T1185
Browser Session Hijacking
MalwareDridex

Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies.

T1185
Browser Session Hijacking
Toolevilginx2

evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions.

T1185
Browser Session Hijacking
MalwareKali365

Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.

T1187
Forced Authentication
MalwareEnvyScout

EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure.

T1189
Drive-by Compromise
MalwareBad Rabbit

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

T1189
Drive-by Compromise
MalwareKARAE

KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.

T1189
Drive-by Compromise
MalwareSnip3

Snip3 has been delivered to targets via downloads from malicious domains.

T1189
Drive-by Compromise
MalwareIcedID

IcedID has cloned legitimate websites/applications to distribute the malware.

T1189
Drive-by Compromise
MalwarePOORAIM

POORAIM has been delivered through compromised sites acting as watering holes.

T1189
Drive-by Compromise
MalwareSocGholish

SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates.

T1189
Drive-by Compromise
MalwareBundlore

Bundlore has been spread through malicious advertisements on websites.

T1189
Drive-by Compromise
MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1189
Drive-by Compromise
MalwareLoudMiner

LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

T1190
Exploit Public-Facing Application
MalwareCOATHANGER

COATHANGER is installed following exploitation of a vulnerable FortiGate device.

T1190
Exploit Public-Facing Application
MalwareBOLDMOVE

BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS.

T1190
Exploit Public-Facing Application
MalwareSiloscape

Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability.

T1190
Exploit Public-Facing Application
MalwareZxShell

ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.

T1190
Exploit Public-Facing Application
MalwareQilin

Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.

T1190
Exploit Public-Facing Application
MalwareSoreFang

SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries.

T1190
Exploit Public-Facing Application
Toolsqlmap

sqlmap can be used to automate exploitation of SQL injection vulnerabilities.

T1190
Exploit Public-Facing Application
ToolHavij

Havij is used to automate SQL injection.

T1195
Supply Chain Compromise
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

T1195
Supply Chain Compromise
MalwareRaccoon Stealer

Raccoon Stealer has been distributed through cracked software downloads.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareTsundere Botnet

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.