Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1528 Steal Application Access Token |
ToolAADInternals | AADInternals can steal users’ access tokens via phishing emails containing malicious links. |
| T1528 Steal Application Access Token |
ToolTruffleHog | TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories. |
| T1528 Steal Application Access Token |
ToolPeirates | Peirates gathers Kubernetes service account tokens using a variety of techniques. |
| T1528 Steal Application Access Token |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens. |
| T1528 Steal Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD. |
| T1528 Steal Application Access Token |
MalwareCanisterWorm | CanisterWorm has gathered cloud access tokens. |
| T1528 Steal Application Access Token |
MalwareKali365 | Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure. |
| T1529 System Shutdown/Reboot |
MalwareAcidRain | AcidRain reboots the target system once the various wiping processes are complete. |
| T1529 System Shutdown/Reboot |
MalwareAvosLocker | AvosLocker’s Linux variant has terminated ESXi virtual machines. |
| T1529 System Shutdown/Reboot |
MalwareOlympic Destroyer | Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings. |
| T1529 System Shutdown/Reboot |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system. |
| T1529 System Shutdown/Reboot |
MalwareShrinkLocker | ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users. |
| T1529 System Shutdown/Reboot |
MalwareApostle | Apostle reboots the victim machine following wiping and related activity. |
| T1529 System Shutdown/Reboot |
MalwareWhisperGate | WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag. |
| T1529 System Shutdown/Reboot |
MalwareAcidPour | AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain. |
| T1529 System Shutdown/Reboot |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| T1529 System Shutdown/Reboot |
MalwareDCSrv | DCSrv has a function to sleep for two hours before rebooting the system. |
| T1529 System Shutdown/Reboot |
MalwareNotPetya | NotPetya will reboot the system one hour after infection. |
| T1529 System Shutdown/Reboot |
MalwareLockerGoga | LockerGoga has been observed shutting down infected systems. |
| T1529 System Shutdown/Reboot |
MalwareMultiLayer Wiper | MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery. |
| T1529 System Shutdown/Reboot |
MalwareDarkGate | DarkGate has used the `shutdown`command to shut down and/or restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareLatrodectus | Latrodectus has the ability to restart compromised hosts. |
| T1529 System Shutdown/Reboot |
MalwareShamoon | Shamoon will reboot the infected system once the wiping functionality has been completed. |
| T1529 System Shutdown/Reboot |
MalwareBlack Basta | Black Basta has used `ShellExecuteA` to shut down and restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareXLoader | XLoader can initiate a system reboot or shutdown. |
| T1529 System Shutdown/Reboot |
MalwareHermeticWiper | HermeticWiper can initiate a system shutdown. |
| T1529 System Shutdown/Reboot |
MalwareLookBack | LookBack can shutdown and reboot the victim machine. |
| T1529 System Shutdown/Reboot |
MalwareBFG Agonizer | BFG Agonizer uses elevated privileges to call |
| T1529 System Shutdown/Reboot |
MalwareMaze | Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM. |
| T1529 System Shutdown/Reboot |
MalwareKillDisk | KillDisk attempts to reboot the machine by terminating specific processes. |
| T1529 System Shutdown/Reboot |
MalwareQilin | Qilin can initiate a reboot of the backup server to hinder recovery. |
| T1529 System Shutdown/Reboot |
ToolRemcos | Remcos can shutdown and restart remote devices. |
| T1529 System Shutdown/Reboot |
MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
| T1530 Data from Cloud Storage |
ToolPacu | Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets. |
| T1530 Data from Cloud Storage |
ToolAADInternals | AADInternals can collect files from a user’s OneDrive. |
| T1530 Data from Cloud Storage |
ToolTruffleHog | TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage. |
| T1530 Data from Cloud Storage |
ToolPeirates | Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3. |
| T1531 Account Access Removal |
MalwareLockerGoga | LockerGoga has been observed changing account passwords and logging off current users. |
| T1531 Account Access Removal |
MalwareMegaCortex | MegaCortex has changed user account passwords and logged users off the system. |
| T1531 Account Access Removal |
MalwareMeteor | Meteor has the ability to change the password of local users on compromised hosts and can log off users. |
| T1531 Account Access Removal |
MalwareDEADWOOD | DEADWOOD changes the password for local and domain users via |
| T1534 Internal Spearphishing |
MalwareSameCoin | SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization. |
| T1539 Steal Web Session Cookie |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1539 Steal Web Session Cookie |
MalwareDarkGate | DarkGate attempts to steal Opera cookies, if present, after terminating the related process. |
| T1539 Steal Web Session Cookie |
MalwareChaes | Chaes has used a script that extracts the web session cookie and sends it to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareLODEINFO | LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies. |
| T1539 Steal Web Session Cookie |
MalwareEVILNUM | EVILNUM can harvest cookies and upload them to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareGlassWorm | GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers. |
| T1539 Steal Web Session Cookie |
MalwareSpica | Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.