Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.004 Install Root Certificate |
Toolcertutil | certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: |
| T1553.004 Install Root Certificate |
Toolevilginx2 | evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareAmadey | Amadey has modified the `:Zone.Identifier` in the ADS area to zero. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareQakBot | QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures. |
| T1553.006 Code Signing Policy Modification |
MalwareBlackEnergy | BlackEnergy has enabled the |
| T1553.006 Code Signing Policy Modification |
MalwareHikit | Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component. |
| T1553.006 Code Signing Policy Modification |
MalwarePandora | Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1554 Compromise Host Software Binary |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset. |
| T1554 Compromise Host Software Binary |
MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareBOLDMOVE | BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| T1554 Compromise Host Software Binary |
MalwareBonadan | Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwareLIGHTWIRE | LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution. |
| T1554 Compromise Host Software Binary |
MalwareThiefQuest | ThiefQuest searches through the |
| T1554 Compromise Host Software Binary |
MalwareGlassWorm | GlassWorm can modify hardware wallet applications. |
| T1554 Compromise Host Software Binary |
MalwareKobalos | Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems. |
| T1554 Compromise Host Software Binary |
MalwareWARPWIRE | WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareFRAMESTING | FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.` |
| T1554 Compromise Host Software Binary |
MalwareWIREFIRE | WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1554 Compromise Host Software Binary |
MalwareKessel | Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwarePHASEJAM | PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided. |
| T1554 Compromise Host Software Binary |
MalwareBFG Agonizer | BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| T1554 Compromise Host Software Binary |
MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1554 Compromise Host Software Binary |
MalwareXCSSET | XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules. |
| T1554 Compromise Host Software Binary |
MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| T1554 Compromise Host Software Binary |
MalwareSLOWPULSE | SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files. |
| T1554 Compromise Host Software Binary |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers. |
| T1555 Credentials from Password Stores |
MalwareMatryoshka | Matryoshka is capable of stealing Outlook passwords. |
| T1555 Credentials from Password Stores |
MalwareNETWIRE | NETWIRE can retrieve passwords from messaging and mail client applications. |
| T1555 Credentials from Password Stores |
MalwareOLDBAIT | OLDBAIT collects credentials from several email clients. |
| T1555 Credentials from Password Stores |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys. |
| T1555 Credentials from Password Stores |
MalwareMirrorStealer | MirrorStealer has the ability to steal credentials from email clients. |
| T1555 Credentials from Password Stores |
MalwarePrikormka | A module in Prikormka collects passwords stored in applications installed on the victim. |
| T1555 Credentials from Password Stores |
MalwareMispadu | Mispadu has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555 Credentials from Password Stores |
MalwareBeaverTail | BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`. |
| T1555 Credentials from Password Stores |
MalwareDarkGate | DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions. |
| T1555 Credentials from Password Stores |
MalwareKGH_SPY | KGH_SPY can collect credentials from WINSCP. |
| T1555 Credentials from Password Stores |
MalwareRedLine Stealer | RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients. |
| T1555 Credentials from Password Stores |
MalwareXLoader | XLoader can collect credentials stored in email clients. |
| T1555 Credentials from Password Stores |
MalwareMgBot | MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software. |
| T1555 Credentials from Password Stores |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook. |
| T1555 Credentials from Password Stores |
MalwarePLEAD | PLEAD has the ability to steal saved passwords from Microsoft Outlook. |
| T1555 Credentials from Password Stores |
MalwareCarberp | Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients. |
| T1555 Credentials from Password Stores |
MalwareLokibot | Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients. |
| T1555 Credentials from Password Stores |
MalwareManjusaka | Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types. |
| T1555 Credentials from Password Stores |
MalwareAgent Tesla | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles. |
| T1555 Credentials from Password Stores |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1555 Credentials from Password Stores |
ToolPoshC2 | PoshC2 can decrypt passwords stored in the RDCMan configuration file. |
| T1555 Credentials from Password Stores |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI. |
| T1555 Credentials from Password Stores |
ToolLaZagne | LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms. |
| T1555 Credentials from Password Stores |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.