Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
MalwareMicropsia | Micropsia takes screenshots every 90 seconds by calling the Gdi32.BitBlt API. |
| T1113 Screen Capture |
MalwareRedLine Stealer | RedLine Stealer can capture screenshots on a compromised host. |
| T1113 Screen Capture |
MalwareCatchamas | Catchamas captures screenshots based on specific keywords in the window’s title. |
| T1113 Screen Capture |
MalwareStoneDrill | StoneDrill can take screenshots. |
| T1113 Screen Capture |
MalwareRogueRobin | RogueRobin has a command named |
| T1113 Screen Capture |
MalwareAttor | Attor's has a plugin that captures screenshots of the target applications. |
| T1113 Screen Capture |
MalwareLitePower | LitePower can take system screenshots and save them to `%AppData%`. |
| T1113 Screen Capture |
MalwareNightClub | NightClub can load a module to call `CreateCompatibleDC` and `GdipSaveImageToStream` for screen capture. |
| T1113 Screen Capture |
MalwareRTM | RTM can capture screenshots. |
| T1113 Screen Capture |
MalwareDerusbi | Derusbi is capable of performing screen captures. |
| T1113 Screen Capture |
MalwareBadPatch | BadPatch captures screenshots in .jpg format and then exfiltrates them. |
| T1113 Screen Capture |
MalwareXLoader | XLoader can capture screenshots on compromised hosts. |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1113 Screen Capture |
MalwareFinFisher | FinFisher takes a screenshot of the screen and displays it on top of all other windows for few seconds in an apparent attempt to hide some messages showed by the system during the setup process. |
| T1113 Screen Capture |
MalwareLunarMail | LunarMail can capture screenshots from compromised hosts. |
| T1113 Screen Capture |
MalwareCrossRAT | CrossRAT is capable of taking screen captures. |
| T1113 Screen Capture |
MalwareCadelspy | Cadelspy has the ability to capture screenshots and webcam photos. |
| T1113 Screen Capture |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of capturing screenshots. |
| T1113 Screen Capture |
MalwareCobian RAT | Cobian RAT has a feature to perform screen capture. |
| T1113 Screen Capture |
MalwareHotCroissant | HotCroissant has the ability to do real time screen viewing on an infected host. |
| T1113 Screen Capture |
MalwareValak | Valak has the ability to take screenshots on a compromised host. |
| T1113 Screen Capture |
MalwareKivars | Kivars has the ability to capture screenshots on the infected host. |
| T1113 Screen Capture |
MalwareTajMahal | TajMahal has the ability to take screenshots on an infected host including capturing content from windows of instant messaging applications. |
| T1113 Screen Capture |
MalwareRaccoon Stealer | Raccoon Stealer can capture screenshots from victim systems. |
| T1113 Screen Capture |
MalwareDaserf | Daserf can take screenshots. |
| T1113 Screen Capture |
MalwareCardinal RAT | Cardinal RAT can capture screenshots. |
| T1113 Screen Capture |
MalwareBISCUIT | BISCUIT has a command to periodically take screenshots of the system. |
| T1113 Screen Capture |
MalwareRamsay | Ramsay can take screenshots every 30 seconds as well as when an external removable storage device is connected. |
| T1113 Screen Capture |
MalwareAshTag | The AshTag AshenOrchestrator component has the ability to take screenshots. |
| T1113 Screen Capture |
MalwareCarberp | Carberp can capture display screenshots with the screens_dll.dll plugin. |
| T1113 Screen Capture |
MalwareNKAbuse | NKAbuse can take screenshots of the victim machine. |
| T1113 Screen Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for screen capture. |
| T1113 Screen Capture |
MalwareMacMa | MacMa has used Apple’s Core Graphic APIs, such as `CGWindowListCreateImageFromArray`, to capture the user's screen and open windows. |
| T1113 Screen Capture |
MalwareFunnyDream | The FunnyDream ScreenCap component can take screenshots on a compromised host. |
| T1113 Screen Capture |
MalwareSysUpdate | SysUpdate has the ability to capture screenshots. |
| T1113 Screen Capture |
MalwareTinyZBot | TinyZBot contains screen capture functionality. |
| T1113 Screen Capture |
MalwareProton | Proton captures the content of the desktop with the screencapture binary. |
| T1113 Screen Capture |
MalwareLookBack | LookBack can take desktop screenshots. |
| T1113 Screen Capture |
MalwarePoetRAT | PoetRAT has the ability to take screen captures. |
| T1113 Screen Capture |
MalwareCHOPSTICK | CHOPSTICK has the capability to capture screenshots. |
| T1113 Screen Capture |
MalwareZxShell | ZxShell can capture screenshots. |
| T1113 Screen Capture |
MalwareCannon | Cannon can take a screenshot of the desktop. |
| T1113 Screen Capture |
MalwareTroll Stealer | Troll Stealer can capture screenshots from victim machines. |
| T1113 Screen Capture |
MalwarenjRAT | njRAT can capture screenshots of the victim’s machines. |
| T1113 Screen Capture |
MalwareTURNEDUP | TURNEDUP is capable of taking screenshots. |
| T1113 Screen Capture |
MalwareManjusaka | Manjusaka can take screenshots of the victim desktop. |
| T1113 Screen Capture |
MalwaremetaMain | metaMain can take and save screenshots. |
| T1113 Screen Capture |
MalwareXCSSET | XCSSET saves a screen capture of the victim's system with a numbered filename and |
| T1113 Screen Capture |
MalwareOctopus | Octopus can capture screenshots of the victims’ machine. |
| T1113 Screen Capture |
MalwareSocksbot | Socksbot can take screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.