Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
ToolRemcos | Remcos has full control of the Registry, including the ability to modify it. |
| T1112 Modify Registry |
ToolCrackMapExec | CrackMapExec can create a registry key using wdigest. |
| T1112 Modify Registry |
ToolReg | Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface. |
| T1112 Modify Registry |
ToolQuasarRAT | QuasarRAT has a command to edit the Registry on the victim’s machine. |
| T1113 Screen Capture |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using |
| T1113 Screen Capture |
GroupKimsuky | Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware. |
| T1113 Screen Capture |
GroupVolt Typhoon | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1113 Screen Capture |
GroupMuddyWater | MuddyWater has used malware that can capture screenshots of the victim’s machine. |
| T1113 Screen Capture |
GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| T1113 Screen Capture |
GroupFIN7 | FIN7 captured screenshots and desktop video recordings. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1113 Screen Capture |
GroupOilRig | OilRig has a tool called CANDYKING to capture a screenshot of user's desktop. |
| T1113 Screen Capture |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to take screenshots on targeted systems. |
| T1113 Screen Capture |
GroupGroup5 | Malware used by Group5 is capable of watching the victim's screen. |
| T1113 Screen Capture |
GroupWinter Vivern | Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines. |
| T1113 Screen Capture |
GroupDark Caracal | Dark Caracal took screenshots using their Windows malware. |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1113 Screen Capture |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
| T1113 Screen Capture |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines. |
| T1113 Screen Capture |
GroupSilence | Silence can capture victim screen activity. |
| T1113 Screen Capture |
GroupVOID MANTICORE | VOID MANTICORE has captured screen content during an active Zoom session. |
| T1113 Screen Capture |
GroupMagic Hound | Magic Hound malware can take a screenshot and upload the file to its C2 server. |
| T1113 Screen Capture |
MalwareRCSession | RCSession can capture screenshots from a compromised host. |
| T1113 Screen Capture |
MalwareQuietSieve | QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`. |
| T1113 Screen Capture |
MalwareGRIFFON | GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system. |
| T1113 Screen Capture |
Malwareyty | yty collects screenshots of the victim machine. |
| T1113 Screen Capture |
MalwareDOGCALL | DOGCALL is capable of capturing screenshots of the victim's machine. |
| T1113 Screen Capture |
MalwarePOWRUNER | POWRUNER can capture a screenshot from a victim. |
| T1113 Screen Capture |
MalwareSharpStage | SharpStage has the ability to capture the victim's screen. |
| T1113 Screen Capture |
MalwareHALFBAKED | HALFBAKED can obtain screenshots from the victim. |
| T1113 Screen Capture |
MalwareKEYMARBLE | KEYMARBLE can capture screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareUrsnif | Ursnif has used hooked APIs to take screenshots. |
| T1113 Screen Capture |
MalwareZLib | ZLib has the ability to obtain screenshots of the compromised system. |
| T1113 Screen Capture |
MalwareRedLeaves | RedLeaves can capture screenshots. |
| T1113 Screen Capture |
MalwareZeus Panda | Zeus Panda can take screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
| T1113 Screen Capture |
MalwareMatryoshka | Matryoshka is capable of performing screen captures. |
| T1113 Screen Capture |
MalwareJanicab | Janicab captured screenshots and sent them out to a C2 server. |
| T1113 Screen Capture |
MalwareTONESHELL | TONESHELL has conducted screen capturing. |
| T1113 Screen Capture |
MalwareKasidet | Kasidet has the ability to initiate keylogging and screen captures. |
| T1113 Screen Capture |
MalwareRainyDay | RainyDay has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| T1113 Screen Capture |
MalwareNETWIRE | NETWIRE can capture the victim's screen. |
| T1113 Screen Capture |
MalwareCosmicDuke | CosmicDuke takes periodic screenshots and exfiltrates them. |
| T1113 Screen Capture |
MalwareEvilGrab | EvilGrab has the capability to capture screenshots. |
| T1113 Screen Capture |
MalwareAria-body | Aria-body has the ability to capture screenshots on compromised hosts. |
| T1113 Screen Capture |
MalwareCrimson | Crimson contains a command to perform screen captures. |
| T1113 Screen Capture |
MalwareDUSTTRAP | DUSTTRAP can capture screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.