ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1115
Clipboard Data
MalwareKONNI

KONNI had a feature to steal data from the clipboard.

T1115
Clipboard Data
MalwareJHUHUGIT

A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.

T1115
Clipboard Data
MalwareCatchamas

Catchamas steals data stored in the clipboard.

T1115
Clipboard Data
MalwareAttor

Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs.

T1115
Clipboard Data
MalwareRTM

RTM collects data from the clipboard.

T1115
Clipboard Data
MalwareGrandoreiro

Grandoreiro can capture clipboard data from a compromised host.

T1115
Clipboard Data
MalwareXLoader

XLoader can collect data stored in the victim's clipboard.

T1115
Clipboard Data
MalwareMgBot

MgBot can capture clipboard data.

T1115
Clipboard Data
MalwareCadelspy

Cadelspy has the ability to steal data from the clipboard.

T1115
Clipboard Data
MalwareTajMahal

TajMahal has the ability to steal data from the clipboard of an infected host.

T1115
Clipboard Data
MalwareTinyZBot

TinyZBot contains functionality to collect information from the clipboard.

T1115
Clipboard Data
MalwareMelcoz

Melcoz can monitor content saved to the clipboard.

T1115
Clipboard Data
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

T1115
Clipboard Data
MalwareRemexi

Remexi collects text from the clipboard.

T1115
Clipboard Data
MalwareAstaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries.

T1115
Clipboard Data
MalwarejRAT

jRAT can capture clipboard data.

T1115
Clipboard Data
MalwareHelminth

The executable version of Helminth has a module to log clipboard contents.

T1115
Clipboard Data
MalwareMacSpy

MacSpy can steal clipboard contents.

T1115
Clipboard Data
ToolSILENTTRINITY

SILENTTRINITY can monitor Clipboard text and can use `System.Windows.Forms.Clipboard.GetText()` to collect data from the clipboard.

T1115
Clipboard Data
ToolEmpire

Empire can harvest clipboard data on both Windows and macOS systems.

T1115
Clipboard Data
ToolRemcos

Remcos steals and modifies data from the clipboard.

T1115
Clipboard Data
ToolKoadic

Koadic can retrieve the current content of the user clipboard.

T1119
Automated Collection
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings.

T1119
Automated Collection
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information.

T1119
Automated Collection
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction.

T1119
Automated Collection
CampaignArcaneDoor

ArcaneDoor included collection of packet capture and system configuration information.

T1119
Automated Collection
CampaignAPT41 DUST

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

T1119
Automated Collection
CampaignOperation Wocao

During Operation Wocao, threat actors used a script to collect information about the infected system.

T1119
Automated Collection
GroupPatchwork

Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server.

T1119
Automated Collection
GroupmenuPass

menuPass has used the Csvde tool to collect Active Directory files and data.

T1119
Automated Collection
GroupHAFNIUM

HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint.

T1119
Automated Collection
GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

T1119
Automated Collection
GroupGamaredon Group

Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents.

T1119
Automated Collection
GroupSidewinder

Sidewinder has used tools to automatically collect system and network configuration information.

T1119
Automated Collection
GroupMustang Panda

Mustang Panda used custom batch scripts to collect files automatically from a targeted system.

T1119
Automated Collection
GroupOilRig

OilRig has used automated collection.

T1119
Automated Collection
GroupTropic Trooper

Tropic Trooper has collected information automatically using the adversary's USBferry attack.

T1119
Automated Collection
GroupKe3chang

Ke3chang has performed frequent and scheduled data collection from victim networks.

T1119
Automated Collection
GroupAPT1

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

T1119
Automated Collection
GroupConfucius

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

T1119
Automated Collection
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1119
Automated Collection
GroupRedCurl

RedCurl has used batch scripts to collect data.

T1119
Automated Collection
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1119
Automated Collection
GroupChimera

Chimera has used custom DLLs for continuous retrieval of data from memory.

T1119
Automated Collection
GroupEmber Bear

Ember Bear engages in mass collection from compromised systems during intrusions.

T1119
Automated Collection
GroupAgrius

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

T1119
Automated Collection
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1119
Automated Collection
GroupVOID MANTICORE

VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.

T1119
Automated Collection
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1119
Automated Collection
MalwareProxysvc

Proxysvc automatically collects data about the victim and sends it to the control server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.