Real-world descriptions of how a group, tool or campaign used a technique.
58 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.007 Path Interception by PATH Environment Variable |
MalwareDarkGate | DarkGate overrides the |
| T1583.001 Domains |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1622 Debugger Evasion |
MalwareDarkGate | DarkGate checks the |
| T1657 Financial Theft |
MalwareDarkGate | DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets. |
| T1665 Hide Infrastructure |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1680 Local Storage Discovery |
MalwareDarkGate | DarkGate uses the Delphi methods |
| T1685 Disable or Modify Tools |
MalwareDarkGate | DarkGate will terminate processes associated with several security software products if identified during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.