ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
MalwareTurian

Turian has the ability to take screenshots.

T1113
Screen Capture
MalwareBADHATCH

BADHATCH can take screenshots and send them to an actor-controlled C2 server.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1113
Screen Capture
MalwarePrikormka

Prikormka contains a module that captures screenshots of the victim's desktop.

T1113
Screen Capture
MalwareWoody RAT

Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+.

T1113
Screen Capture
MalwareMafalda

Mafalda can take a screenshot of the target machine and save it to a file.

T1113
Screen Capture
MalwareSHUTTERSPEED

SHUTTERSPEED can capture screenshots.

T1113
Screen Capture
MalwareFlawedAmmyy

FlawedAmmyy can capture screenshots.

T1113
Screen Capture
MalwareCuckoo Stealer

Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts.

T1113
Screen Capture
MalwareInvisiMole

InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping.

T1113
Screen Capture
MalwareFruitFly

FruitFly takes screenshots of the user's desktop.

T1113
Screen Capture
MalwareRDAT

RDAT can take a screenshot on the infected system.

T1113
Screen Capture
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag.

T1113
Screen Capture
MalwareMispadu

Mispadu has the ability to capture screenshots on compromised hosts.

T1113
Screen Capture
MalwareVERMIN

VERMIN can perform screen captures of the victim’s machine.

T1113
Screen Capture
MalwareHTTPTroy

HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server.

T1113
Screen Capture
MalwareMarkiRAT

MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’.

T1113
Screen Capture
MalwareKazuar

Kazuar captures screenshots of the victim’s screen.

T1113
Screen Capture
MalwarePOORAIM

POORAIM can perform screen capturing.

T1113
Screen Capture
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk.

T1113
Screen Capture
MalwareBlackEnergy

BlackEnergy is capable of taking screenshots.

T1113
Screen Capture
MalwareChrommme

Chrommme has the ability to capture screenshots.

T1113
Screen Capture
MalwareObliqueRAT

ObliqueRAT can capture a screenshot of the current screen.

T1113
Screen Capture
MalwareXAgentOSX

XAgentOSX contains the takeScreenShot (along with startTakeScreenShot and stopTakeScreenShot) functions to take screenshots using the CGGetActiveDisplayList, CGDisplayCreateImage, and NSImage:initWithCGImage methods.

T1113
Screen Capture
MalwareLightSpy

LightSpy uses Apple's built-in AVFoundation Framework library to access the user's camera and screen. It uses the `AVCaptureStillImage` to take a picture using the user's camera and the `AVCaptureScreen` to take a screenshot or record the user's screen for a specified period of time.

T1113
Screen Capture
MalwareKeyBoy

KeyBoy has a command to perform screen grabbing.

T1113
Screen Capture
MalwareHyperBro

HyperBro has the ability to take screenshots.

T1113
Screen Capture
MalwarePteranodon

Pteranodon can capture screenshots at a configurable interval.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

T1113
Screen Capture
MalwarePlugX

PlugX allows the operator to capture screenshots.

T1113
Screen Capture
MalwareLumma Stealer

Lumma Stealer has taken screenshots of victim machines.

T1113
Screen Capture
MalwareDustySky

DustySky captures PNG screenshots of the main screen.

T1113
Screen Capture
MalwareRover

Rover takes screenshots of the compromised system's desktop and saves them to C:\system\screenshot.bmp for exfiltration every 60 minutes.

T1113
Screen Capture
MalwarePeppy

Peppy can take screenshots on targeted systems.

T1113
Screen Capture
MalwareClambling

Clambling has the ability to capture screenshots.

T1113
Screen Capture
MalwareSVCReady

SVCReady can take a screenshot from an infected host.

T1113
Screen Capture
MalwareCarbanak

Carbanak performs desktop video recording and captures screenshots of the desktop and sends it to the C2 server.

T1113
Screen Capture
MalwareHydraq

Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host.

T1113
Screen Capture
MalwareChaes

Chaes can capture screenshots of the infected machine.

T1113
Screen Capture
MalwareLODEINFO

LODEINFO has the ability to take screenshots.

T1113
Screen Capture
MalwareCharmPower

CharmPower has the ability to capture screenshots.

T1113
Screen Capture
MalwareSMOKEDHAM

SMOKEDHAM can capture screenshots of the victim’s desktop.

T1113
Screen Capture
MalwareMetamorfo

Metamorfo can collect screenshots of the victim’s machine.

T1113
Screen Capture
MalwareTrojan.Karagany

Trojan.Karagany can take a desktop screenshot and save the file into \ProgramData\Mail\MailAg\shot.png.

T1113
Screen Capture
MalwareBandook

Bandook is capable of taking an image of and uploading the current desktop.

T1113
Screen Capture
MalwareKONNI

KONNI can take screenshots of the victim’s machine.

T1113
Screen Capture
MalwareT9000

T9000 can take screenshots of the desktop and target application windows, saving them to user directories as one byte XOR encrypted .dat files.

T1113
Screen Capture
Malwaregh0st RAT

gh0st RAT can capture the victim’s screen remotely.

T1113
Screen Capture
MalwareJHUHUGIT

A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image.

T1113
Screen Capture
MalwareBLUELIGHT

BLUELIGHT has captured a screenshot of the display every 30 seconds for the first 5 minutes after initiating a C2 loop, and then once every five minutes thereafter.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.