Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1210 Exploitation of Remote Services |
MalwareInvisiMole | InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively. |
| T1218.002 Control Panel |
MalwareInvisiMole | InvisiMole can register itself for execution and persistence via the Control Panel. |
| T1218.011 Rundll32 |
MalwareInvisiMole | InvisiMole has used rundll32.exe for execution. |
| T1480.001 Environmental Keying |
MalwareInvisiMole | InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer. |
| T1490 Inhibit System Recovery |
MalwareInvisiMole | InvisiMole can can remove all system restore points. |
| T1497.001 System Checks |
MalwareInvisiMole | InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected. |
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1518.001 Security Software Discovery |
MalwareInvisiMole | InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall. |
| T1543.003 Windows Service |
MalwareInvisiMole | InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisiMole | InvisiMole can place a lnk file in the Startup Folder to achieve persistence. |
| T1547.009 Shortcut Modification |
MalwareInvisiMole | InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareInvisiMole | InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges. |
| T1559.001 Component Object Model |
MalwareInvisiMole | InvisiMole can use the |
| T1560.001 Archive via Utility |
MalwareInvisiMole | InvisiMole uses WinRAR to compress data that is intended to be exfiltrated. |
| T1560.002 Archive via Library |
MalwareInvisiMole | InvisiMole can use zlib to compress and decompress data. |
| T1560.003 Archive via Custom Method |
MalwareInvisiMole | InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareInvisiMole | InvisiMole can create hidden system directories. |
| T1564.003 Hidden Window |
MalwareInvisiMole | InvisiMole has executed legitimate tools in hidden windows. |
| T1569.002 Service Execution |
MalwareInvisiMole | InvisiMole has used Windows services as a way to execute its malicious payload. |
| T1573.001 Symmetric Cryptography |
MalwareInvisiMole | InvisiMole uses variations of a simple XOR encryption routine for C&C communications. |
| T1574.001 DLL |
MalwareInvisiMole | InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library. |
| T1680 Local Storage Discovery |
MalwareInvisiMole | InvisiMole can gather information on the mapped drives and system volume serial number. |
| T1686 Disable or Modify System Firewall |
MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.