Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| T1113 Screen Capture |
MalwarePOWERSTATS | POWERSTATS can retrieve screenshots from compromised hosts. |
| T1113 Screen Capture |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can capture screenshots and store them locally. |
| T1113 Screen Capture |
MalwareBADNEWS | BADNEWS has a command to take a screenshot and send it to the C2 server. |
| T1113 Screen Capture |
MalwareRemexi | Remexi takes screenshots of windows of interest. |
| T1113 Screen Capture |
MalwarejRAT | jRAT has the capability to take screenshots of the victim’s machine. |
| T1113 Screen Capture |
MalwareMacSpy | MacSpy can capture screenshots of the desktop over multiple monitors. |
| T1113 Screen Capture |
MalwareLizar | Lizar can take JPEG screenshots of an infected system. Lizar has also used a plugin to take a screenshot of the infected system. |
| T1113 Screen Capture |
MalwareAzorult | Azorult can capture screenshots of the victim’s machines. |
| T1113 Screen Capture |
MalwareUPPERCUT | UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server. |
| T1113 Screen Capture |
MalwareStrifeWater | StrifeWater has the ability to take screen captures. |
| T1113 Screen Capture |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has taken a screenshot of a victim's desktop, named it "Filter3.jpg", and stored it in the local directory. |
| T1113 Screen Capture |
ToolRemoteUtilities | RemoteUtilities can take screenshots on a compromised host. |
| T1113 Screen Capture |
ToolSliver | Sliver can take screenshots of the victim’s active display. |
| T1113 Screen Capture |
ToolSILENTTRINITY | SILENTTRINITY can take a screenshot of the current desktop. |
| T1113 Screen Capture |
ToolPowerSploit | PowerSploit's |
| T1113 Screen Capture |
ToolEmpire | Empire is capable of capturing screenshots on Windows and macOS systems. |
| T1113 Screen Capture |
ToolPcShare | PcShare can take screen shots of a compromised machine. |
| T1113 Screen Capture |
ToolAsyncRAT | AsyncRAT has the ability to view the screen on compromised hosts. |
| T1113 Screen Capture |
ToolBrute Ratel C4 | Brute Ratel C4 can take screenshots on compromised hosts. |
| T1113 Screen Capture |
ToolRemcos | Remcos takes automated screenshots of the infected machine. |
| T1113 Screen Capture |
ToolConnectWise | ConnectWise can take screenshots on remote hosts. |
| T1113 Screen Capture |
ToolPupy | Pupy can drop a mouse-logger that will take small screenshots around at each click and then send back to the server. |
| T1113 Screen Capture |
ToolQuick Assist | Quick Assist allows for the remote administrator to take screenshots of the running system. |
| T1113 Screen Capture |
MalwareFlame | Flame can take regular screenshots when certain applications are open that are sent to the command and control server. |
| T1114 Email Collection |
GroupScattered Spider | Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response. |
| T1114 Email Collection |
GroupSilent Librarian | Silent Librarian has exfiltrated entire mailboxes from compromised accounts. |
| T1114 Email Collection |
GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| T1114 Email Collection |
GroupMagic Hound | Magic Hound has compromised email credentials in order to steal sensitive data. |
| T1114 Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1114 Email Collection |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated collected email addresses to the C2 server. |
| T1114.001 Local Email Collection |
CampaignNight Dragon | During Night Dragon, threat actors used RAT malware to exfiltrate email archives. |
| T1114.001 Local Email Collection |
GroupSea Turtle | Sea Turtle collected email archives from victim environments. |
| T1114.001 Local Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| T1114.001 Local Email Collection |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers. |
| T1114.001 Local Email Collection |
GroupRedCurl | RedCurl has collected emails to use in future phishing campaigns. |
| T1114.001 Local Email Collection |
GroupChimera | Chimera has harvested data from victim's e-mail including through execution of |
| T1114.001 Local Email Collection |
GroupMirrorFace | MirrorFace has exfiltrated stored emails from compromised hosts. |
| T1114.001 Local Email Collection |
GroupWIRTE | WIRTE has collected documents from victims' email accounts. |
| T1114.001 Local Email Collection |
GroupMagic Hound | Magic Hound has collected .PST archives. |
| T1114.001 Local Email Collection |
MalwareSmoke Loader | Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.). |
| T1114.001 Local Email Collection |
MalwareCosmicDuke | CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration. |
| T1114.001 Local Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that scrapes email data from Outlook. |
| T1114.001 Local Email Collection |
MalwareCrimson | Crimson contains a command to collect and exfiltrate emails from Outlook. |
| T1114.001 Local Email Collection |
MalwareCarbanak | Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server. |
| T1114.001 Local Email Collection |
MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| T1114.001 Local Email Collection |
MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| T1114.001 Local Email Collection |
MalwareQakBot | QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns. |
| T1114.001 Local Email Collection |
ToolEmpire | Empire has the ability to collect emails on a target system. |
| T1114.001 Local Email Collection |
ToolOut1 | Out1 can parse e-mails on a target machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.