ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

169 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFatDuke

FatDuke can copy files and directories from a compromised host.

T1005
Data from Local System
MalwareDRATzarus

DRATzarus can collect information from a compromised host.

T1005
Data from Local System
MalwareRising Sun

Rising Sun has collected data and files from a compromised host.

T1005
Data from Local System
MalwareShimRat

ShimRat has the capability to upload collected files to a C2.

T1005
Data from Local System
MalwareChrommme

Chrommme can collect data from a local system.

T1005
Data from Local System
MalwareFlagpro

Flagpro can collect data from a compromised host, including Windows authentication information.

T1005
Data from Local System
MalwareSpicyOmelette

SpicyOmelette has collected data and other information from a compromised host.

T1005
Data from Local System
MalwareGreen Lambert

Green Lambert can collect data from a compromised host.

T1005
Data from Local System
MalwareChina Chopper

China Chopper's server component can upload local files.

T1005
Data from Local System
MalwareBeaverTail

BeaverTail has exfiltrated data collected from local systems.

T1005
Data from Local System
MalwareROKRAT

ROKRAT can collect host data and specific file types.

T1005
Data from Local System
MalwareDarkWatchman

DarkWatchman can collect files from a compromised host.

T1005
Data from Local System
MalwareBlackMould

BlackMould can copy files on a compromised host.

T1005
Data from Local System
MalwareBisonal

Bisonal has collected information from a compromised host.

T1005
Data from Local System
MalwareRover

Rover searches for files on local drives based on a predefined list of file extensions.

T1005
Data from Local System
MalwareLightNeuron

LightNeuron can collect files from a local system.

T1005
Data from Local System
MalwareClambling

Clambling can collect information from a compromised host.

T1005
Data from Local System
MalwareDarkGate

DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1005
Data from Local System
MalwareMongall

Mongall has the ability to upload files from victim's machines.

T1005
Data from Local System
MalwareSVCReady

SVCReady can collect data from an infected host.

T1005
Data from Local System
MalwareFoggyWeb

FoggyWeb can retrieve configuration data from a compromised AD FS server.

T1005
Data from Local System
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can read data from files.

T1005
Data from Local System
MalwareCreepyDrive

CreepyDrive can upload files to C2 from victim machines.

T1005
Data from Local System
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to collect information from the local database.

T1005
Data from Local System
MalwareUSBferry

USBferry can collect information from an air-gapped host machine.

T1005
Data from Local System
MalwareLatrodectus

Latrodectus can collect data from a compromised host using a stealer module.

T1005
Data from Local System
MalwareSaint Bot

Saint Bot can collect files and information from a compromised host.

T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1005
Data from Local System
MalwareCharmPower

CharmPower can collect data and files from a compromised host.

T1005
Data from Local System
MalwareGlassWorm

GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads.

T1005
Data from Local System
MalwareUroburos

Uroburos can use its `Get` command to exfiltrate specified files from the compromised system.

T1005
Data from Local System
MalwareBandook

Bandook can collect local files from the system .

T1005
Data from Local System
MalwareKONNI

KONNI has stored collected information and discovered processes in a tmp file.

T1005
Data from Local System
MalwareRAPIDPULSE

RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell.

T1005
Data from Local System
MalwareDnsSystem

DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string.

T1005
Data from Local System
MalwareKGH_SPY

KGH_SPY can send a file containing victim system information to C2.

T1005
Data from Local System
MalwareIxeshe

Ixeshe can collect data from a local system.

T1005
Data from Local System
MalwareRedLine Stealer

RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram.

T1005
Data from Local System
MalwareBoxCaon

BoxCaon can upload files from a compromised host.

T1005
Data from Local System
MalwareNightClub

NightClub can use a file monitor to steal specific files from targeted systems.

T1005
Data from Local System
MalwareCrutch

Crutch can exfiltrate files from compromised systems.

T1005
Data from Local System
MalwareSDBbot

SDBbot has the ability to access the file system on a compromised host.

T1005
Data from Local System
MalwareHikit

Hikit can upload files from compromised machines.

T1005
Data from Local System
MalwareWellMail

WellMail can exfiltrate files from the victim machine.

T1005
Data from Local System
MalwareRawPOS

RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.

T1005
Data from Local System
MalwareZxxZ

ZxxZ can collect data from a compromised host.

T1005
Data from Local System
MalwareDrovorub

Drovorub can transfer files from the victim machine.

T1005
Data from Local System
MalwareShark

Shark can upload files to its C2.

T1005
Data from Local System
MalwareBazar

Bazar can retrieve information from the infected machine.

T1005
Data from Local System
MalwareBadPatch

BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.