Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
ToolIronNetInjector | IronNetInjector has the ability to decrypt embedded .NET and PE payloads. |
| T1140 Deobfuscate/Decode Files or Information |
ToolExpand | Expand can be used to decompress a local or remote CAB file into an executable. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to decrypt obfuscated payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCanisterWorm | CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBADFLICK | BADFLICK can decode shellcode using a custom rotating XOR cipher. |
| T1176.001 Browser Extensions |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data. |
| T1176.001 Browser Extensions |
MalwareMispadu | Mispadu utilizes malicious Google Chrome browser extensions to steal financial data. |
| T1176.001 Browser Extensions |
MalwareLumma Stealer | Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data. |
| T1176.001 Browser Extensions |
MalwareBundlore | Bundlore can install malicious browser extensions that are used to hijack user searches. |
| T1176.001 Browser Extensions |
MalwareGrandoreiro | Grandoreiro can use malicious browser extensions to steal cookies and other user information. |
| T1176.001 Browser Extensions |
MalwareOSX/Shlayer | OSX/Shlayer can install malicious Safari browser extensions to serve ads. |
| T1185 Browser Session Hijacking |
MalwareTrickBot | TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. |
| T1185 Browser Session Hijacking |
MalwareUrsnif | Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords). |
| T1185 Browser Session Hijacking |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1185 Browser Session Hijacking |
MalwareChaes | Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts. |
| T1185 Browser Session Hijacking |
MalwareGrandoreiro | Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1185 Browser Session Hijacking |
MalwareXLoader | XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1185 Browser Session Hijacking |
MalwareCarberp | Carberp has captured credentials when a user performs login through a SSL session. |
| T1185 Browser Session Hijacking |
MalwareMelcoz | Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background. |
| T1185 Browser Session Hijacking |
MalwareAgent Tesla | Agent Tesla has the ability to use form-grabbing to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1185 Browser Session Hijacking |
MalwareDridex | Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. |
| T1185 Browser Session Hijacking |
Toolevilginx2 | evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions. |
| T1185 Browser Session Hijacking |
MalwareKali365 | Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment. |
| T1187 Forced Authentication |
MalwareEnvyScout | EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure. |
| T1189 Drive-by Compromise |
MalwareBad Rabbit | Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a |
| T1189 Drive-by Compromise |
MalwareKARAE | KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure. |
| T1189 Drive-by Compromise |
MalwareSnip3 | Snip3 has been delivered to targets via downloads from malicious domains. |
| T1189 Drive-by Compromise |
MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| T1189 Drive-by Compromise |
MalwarePOORAIM | POORAIM has been delivered through compromised sites acting as watering holes. |
| T1189 Drive-by Compromise |
MalwareSocGholish | SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1189 Drive-by Compromise |
MalwareBundlore | Bundlore has been spread through malicious advertisements on websites. |
| T1189 Drive-by Compromise |
MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1189 Drive-by Compromise |
MalwareLoudMiner | LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
| T1190 Exploit Public-Facing Application |
MalwareCOATHANGER | COATHANGER is installed following exploitation of a vulnerable FortiGate device. |
| T1190 Exploit Public-Facing Application |
MalwareBOLDMOVE | BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS. |
| T1190 Exploit Public-Facing Application |
MalwareSiloscape | Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability. |
| T1190 Exploit Public-Facing Application |
MalwareZxShell | ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322. |
| T1190 Exploit Public-Facing Application |
MalwareQilin | Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP. |
| T1190 Exploit Public-Facing Application |
MalwareSoreFang | SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries. |
| T1190 Exploit Public-Facing Application |
Toolsqlmap | sqlmap can be used to automate exploitation of SQL injection vulnerabilities. |
| T1190 Exploit Public-Facing Application |
ToolHavij | Havij is used to automate SQL injection. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1195 Supply Chain Compromise |
MalwareRaccoon Stealer | Raccoon Stealer has been distributed through cracked software downloads. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareTsundere Botnet | Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail | BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.