Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1115 Clipboard Data |
MalwareKONNI | KONNI had a feature to steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareJHUHUGIT | A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image. |
| T1115 Clipboard Data |
MalwareCatchamas | Catchamas steals data stored in the clipboard. |
| T1115 Clipboard Data |
MalwareAttor | Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs. |
| T1115 Clipboard Data |
MalwareRTM | RTM collects data from the clipboard. |
| T1115 Clipboard Data |
MalwareGrandoreiro | Grandoreiro can capture clipboard data from a compromised host. |
| T1115 Clipboard Data |
MalwareXLoader | XLoader can collect data stored in the victim's clipboard. |
| T1115 Clipboard Data |
MalwareMgBot | MgBot can capture clipboard data. |
| T1115 Clipboard Data |
MalwareCadelspy | Cadelspy has the ability to steal data from the clipboard. |
| T1115 Clipboard Data |
MalwareTajMahal | TajMahal has the ability to steal data from the clipboard of an infected host. |
| T1115 Clipboard Data |
MalwareTinyZBot | TinyZBot contains functionality to collect information from the clipboard. |
| T1115 Clipboard Data |
MalwareMelcoz | Melcoz can monitor content saved to the clipboard. |
| T1115 Clipboard Data |
MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| T1115 Clipboard Data |
MalwareRemexi | Remexi collects text from the clipboard. |
| T1115 Clipboard Data |
MalwareAstaroth | Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. |
| T1115 Clipboard Data |
MalwarejRAT | jRAT can capture clipboard data. |
| T1115 Clipboard Data |
MalwareHelminth | The executable version of Helminth has a module to log clipboard contents. |
| T1115 Clipboard Data |
MalwareMacSpy | MacSpy can steal clipboard contents. |
| T1115 Clipboard Data |
ToolSILENTTRINITY | SILENTTRINITY can monitor Clipboard text and can use `System.Windows.Forms.Clipboard.GetText()` to collect data from the clipboard. |
| T1115 Clipboard Data |
ToolEmpire | Empire can harvest clipboard data on both Windows and macOS systems. |
| T1115 Clipboard Data |
ToolRemcos | Remcos steals and modifies data from the clipboard. |
| T1115 Clipboard Data |
ToolKoadic | Koadic can retrieve the current content of the user clipboard. |
| T1119 Automated Collection |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings. |
| T1119 Automated Collection |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information. |
| T1119 Automated Collection |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction. |
| T1119 Automated Collection |
CampaignArcaneDoor | ArcaneDoor included collection of packet capture and system configuration information. |
| T1119 Automated Collection |
CampaignAPT41 DUST | APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| T1119 Automated Collection |
CampaignOperation Wocao | During Operation Wocao, threat actors used a script to collect information about the infected system. |
| T1119 Automated Collection |
GroupPatchwork | Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server. |
| T1119 Automated Collection |
GroupmenuPass | menuPass has used the Csvde tool to collect Active Directory files and data. |
| T1119 Automated Collection |
GroupHAFNIUM | HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1119 Automated Collection |
GroupGamaredon Group | Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents. |
| T1119 Automated Collection |
GroupSidewinder | Sidewinder has used tools to automatically collect system and network configuration information. |
| T1119 Automated Collection |
GroupMustang Panda | Mustang Panda used custom batch scripts to collect files automatically from a targeted system. |
| T1119 Automated Collection |
GroupOilRig | OilRig has used automated collection. |
| T1119 Automated Collection |
GroupTropic Trooper | Tropic Trooper has collected information automatically using the adversary's USBferry attack. |
| T1119 Automated Collection |
GroupKe3chang | Ke3chang has performed frequent and scheduled data collection from victim networks. |
| T1119 Automated Collection |
GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1119 Automated Collection |
GroupConfucius | Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
| T1119 Automated Collection |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1119 Automated Collection |
GroupRedCurl | RedCurl has used batch scripts to collect data. |
| T1119 Automated Collection |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1119 Automated Collection |
GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| T1119 Automated Collection |
GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| T1119 Automated Collection |
GroupAgrius | Agrius used a custom tool, |
| T1119 Automated Collection |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1119 Automated Collection |
GroupVOID MANTICORE | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems. |
| T1119 Automated Collection |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1119 Automated Collection |
MalwareProxysvc | Proxysvc automatically collects data about the victim and sends it to the control server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.