Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1539 Steal Web Session Cookie |
MalwareBLUELIGHT | BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1539 Steal Web Session Cookie |
MalwareGrandoreiro | Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device. |
| T1539 Steal Web Session Cookie |
MalwareXLoader | XLoader can capture web session cookies and session information from victim browsers. |
| T1539 Steal Web Session Cookie |
MalwareMgBot | MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers. |
| T1539 Steal Web Session Cookie |
MalwareTajMahal | TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications. |
| T1539 Steal Web Session Cookie |
MalwareRaccoon Stealer | Raccoon Stealer attempts to steal cookies and related information in browser history. |
| T1539 Steal Web Session Cookie |
MalwareXCSSET | XCSSET uses |
| T1539 Steal Web Session Cookie |
MalwareQakBot | QakBot has the ability to capture web session cookies. |
| T1539 Steal Web Session Cookie |
MalwareCookieMiner | CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine. |
| T1539 Steal Web Session Cookie |
Toolevilginx2 | evilginx2 can collect information on each session with a victim including the session cookie. |
| T1539 Steal Web Session Cookie |
MalwareKali365 | Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services. |
| T1542.001 System Firmware |
MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| T1542.001 System Firmware |
MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| T1542.001 System Firmware |
MalwareTrojan.Mebromi | Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal. |
| T1542.002 Component Firmware |
MalwareCyclops Blink | Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices. |
| T1542.003 Bootkit |
MalwareTrickBot | TrickBot can implant malicious code into a compromised device's firmware. |
| T1542.003 Bootkit |
MalwareWhisperGate | WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots. |
| T1542.003 Bootkit |
MalwareFinFisher | Some FinFisher variants incorporate an MBR rootkit. |
| T1542.003 Bootkit |
MalwareCarberp | Carberp has installed a bootkit on the system to maintain persistence. |
| T1542.003 Bootkit |
MalwareROCKBOOT | ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence. |
| T1542.003 Bootkit |
MalwareBOOTRASH | BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence. |
| T1543 Create or Modify System Process |
MalwareBRICKSTORM | BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state. |
| T1543 Create or Modify System Process |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root. |
| T1543 Create or Modify System Process |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background. |
| T1543 Create or Modify System Process |
MalwareIMAPLoader | IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification. |
| T1543 Create or Modify System Process |
MalwareBOLDMOVE | BOLDMOVE can free all resources and terminate itself on victim machines. |
| T1543 Create or Modify System Process |
MalwareAkira _v2 | Akira _v2 can create a child process for encryption. |
| T1543 Create or Modify System Process |
MalwareLunarMail | LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory. |
| T1543 Create or Modify System Process |
MalwareCanisterWorm | CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens. |
| T1543.001 Launch Agent |
MalwareInvisibleFerret | InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”. |
| T1543.001 Launch Agent |
MalwaremacOS.OSAMiner | macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder. |
| T1543.001 Launch Agent |
MalwareNETWIRE | NETWIRE can use launch agents for persistence. |
| T1543.001 Launch Agent |
MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| T1543.001 Launch Agent |
MalwareFruitFly | FruitFly persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareKeydnap | Keydnap uses a Launch Agent to persist. |
| T1543.001 Launch Agent |
MalwareGreen Lambert | Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to |
| T1543.001 Launch Agent |
MalwareThiefQuest | ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the |
| T1543.001 Launch Agent |
MalwareBundlore | Bundlore can persist via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareGlassWorm | GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`. |
| T1543.001 Launch Agent |
MalwareCrossRAT | CrossRAT creates a Launch Agent on macOS. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1543.001 Launch Agent |
MalwareCalisto | Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| T1543.001 Launch Agent |
MalwareMacMa | MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user. |
| T1543.001 Launch Agent |
MalwareProton | Proton persists via Launch Agent. |
| T1543.001 Launch Agent |
MalwareCoinTicker | CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| T1543.001 Launch Agent |
MalwareCookieMiner | CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software. |
| T1543.001 Launch Agent |
MalwareKomplex | The Komplex trojan creates a persistent launch agent called with |
| T1543.001 Launch Agent |
MalwareDok | Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.