Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
MalwareTurian | Turian has the ability to take screenshots. |
| T1113 Screen Capture |
MalwareBADHATCH | BADHATCH can take screenshots and send them to an actor-controlled C2 server. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1113 Screen Capture |
MalwarePrikormka | Prikormka contains a module that captures screenshots of the victim's desktop. |
| T1113 Screen Capture |
MalwareWoody RAT | Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+. |
| T1113 Screen Capture |
MalwareMafalda | Mafalda can take a screenshot of the target machine and save it to a file. |
| T1113 Screen Capture |
MalwareSHUTTERSPEED | SHUTTERSPEED can capture screenshots. |
| T1113 Screen Capture |
MalwareFlawedAmmyy | FlawedAmmyy can capture screenshots. |
| T1113 Screen Capture |
MalwareCuckoo Stealer | Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts. |
| T1113 Screen Capture |
MalwareInvisiMole | InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping. |
| T1113 Screen Capture |
MalwareFruitFly | FruitFly takes screenshots of the user's desktop. |
| T1113 Screen Capture |
MalwareRDAT | RDAT can take a screenshot on the infected system. |
| T1113 Screen Capture |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag. |
| T1113 Screen Capture |
MalwareMispadu | Mispadu has the ability to capture screenshots on compromised hosts. |
| T1113 Screen Capture |
MalwareVERMIN | VERMIN can perform screen captures of the victim’s machine. |
| T1113 Screen Capture |
MalwareHTTPTroy | HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server. |
| T1113 Screen Capture |
MalwareMarkiRAT | MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’. |
| T1113 Screen Capture |
MalwareKazuar | Kazuar captures screenshots of the victim’s screen. |
| T1113 Screen Capture |
MalwarePOORAIM | POORAIM can perform screen capturing. |
| T1113 Screen Capture |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk. |
| T1113 Screen Capture |
MalwareBlackEnergy | BlackEnergy is capable of taking screenshots. |
| T1113 Screen Capture |
MalwareChrommme | Chrommme has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareObliqueRAT | ObliqueRAT can capture a screenshot of the current screen. |
| T1113 Screen Capture |
MalwareXAgentOSX | XAgentOSX contains the takeScreenShot (along with startTakeScreenShot and stopTakeScreenShot) functions to take screenshots using the CGGetActiveDisplayList, CGDisplayCreateImage, and NSImage:initWithCGImage methods. |
| T1113 Screen Capture |
MalwareLightSpy | LightSpy uses Apple's built-in AVFoundation Framework library to access the user's camera and screen. It uses the `AVCaptureStillImage` to take a picture using the user's camera and the `AVCaptureScreen` to take a screenshot or record the user's screen for a specified period of time. |
| T1113 Screen Capture |
MalwareKeyBoy | KeyBoy has a command to perform screen grabbing. |
| T1113 Screen Capture |
MalwareHyperBro | HyperBro has the ability to take screenshots. |
| T1113 Screen Capture |
MalwarePteranodon | Pteranodon can capture screenshots at a configurable interval. |
| T1113 Screen Capture |
MalwareROKRAT | ROKRAT can capture screenshots of the infected system using the `gdi32` library. |
| T1113 Screen Capture |
MalwarePlugX | PlugX allows the operator to capture screenshots. |
| T1113 Screen Capture |
MalwareLumma Stealer | Lumma Stealer has taken screenshots of victim machines. |
| T1113 Screen Capture |
MalwareDustySky | DustySky captures PNG screenshots of the main screen. |
| T1113 Screen Capture |
MalwareRover | Rover takes screenshots of the compromised system's desktop and saves them to |
| T1113 Screen Capture |
MalwarePeppy | Peppy can take screenshots on targeted systems. |
| T1113 Screen Capture |
MalwareClambling | Clambling has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareSVCReady | SVCReady can take a screenshot from an infected host. |
| T1113 Screen Capture |
MalwareCarbanak | Carbanak performs desktop video recording and captures screenshots of the desktop and sends it to the C2 server. |
| T1113 Screen Capture |
MalwareHydraq | Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host. |
| T1113 Screen Capture |
MalwareChaes | Chaes can capture screenshots of the infected machine. |
| T1113 Screen Capture |
MalwareLODEINFO | LODEINFO has the ability to take screenshots. |
| T1113 Screen Capture |
MalwareCharmPower | CharmPower has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareSMOKEDHAM | SMOKEDHAM can capture screenshots of the victim’s desktop. |
| T1113 Screen Capture |
MalwareMetamorfo | Metamorfo can collect screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareTrojan.Karagany | Trojan.Karagany can take a desktop screenshot and save the file into |
| T1113 Screen Capture |
MalwareBandook | Bandook is capable of taking an image of and uploading the current desktop. |
| T1113 Screen Capture |
MalwareKONNI | KONNI can take screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareT9000 | T9000 can take screenshots of the desktop and target application windows, saving them to user directories as one byte XOR encrypted .dat files. |
| T1113 Screen Capture |
Malwaregh0st RAT | gh0st RAT can capture the victim’s screen remotely. |
| T1113 Screen Capture |
MalwareJHUHUGIT | A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image. |
| T1113 Screen Capture |
MalwareBLUELIGHT | BLUELIGHT has captured a screenshot of the display every 30 seconds for the first 5 minutes after initiating a C2 loop, and then once every five minutes thereafter. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.