Real-world descriptions of how a group, tool or campaign used a technique.
169 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFatDuke | FatDuke can copy files and directories from a compromised host. |
| T1005 Data from Local System |
MalwareDRATzarus | DRATzarus can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareRising Sun | Rising Sun has collected data and files from a compromised host. |
| T1005 Data from Local System |
MalwareShimRat | ShimRat has the capability to upload collected files to a C2. |
| T1005 Data from Local System |
MalwareChrommme | Chrommme can collect data from a local system. |
| T1005 Data from Local System |
MalwareFlagpro | Flagpro can collect data from a compromised host, including Windows authentication information. |
| T1005 Data from Local System |
MalwareSpicyOmelette | SpicyOmelette has collected data and other information from a compromised host. |
| T1005 Data from Local System |
MalwareGreen Lambert | Green Lambert can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareChina Chopper | China Chopper's server component can upload local files. |
| T1005 Data from Local System |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from local systems. |
| T1005 Data from Local System |
MalwareROKRAT | ROKRAT can collect host data and specific file types. |
| T1005 Data from Local System |
MalwareDarkWatchman | DarkWatchman can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareBlackMould | BlackMould can copy files on a compromised host. |
| T1005 Data from Local System |
MalwareBisonal | Bisonal has collected information from a compromised host. |
| T1005 Data from Local System |
MalwareRover | Rover searches for files on local drives based on a predefined list of file extensions. |
| T1005 Data from Local System |
MalwareLightNeuron | LightNeuron can collect files from a local system. |
| T1005 Data from Local System |
MalwareClambling | Clambling can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareDarkGate | DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present. |
| T1005 Data from Local System |
MalwareMongall | Mongall has the ability to upload files from victim's machines. |
| T1005 Data from Local System |
MalwareSVCReady | SVCReady can collect data from an infected host. |
| T1005 Data from Local System |
MalwareFoggyWeb | FoggyWeb can retrieve configuration data from a compromised AD FS server. |
| T1005 Data from Local System |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can read data from files. |
| T1005 Data from Local System |
MalwareCreepyDrive | CreepyDrive can upload files to C2 from victim machines. |
| T1005 Data from Local System |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to collect information from the local database. |
| T1005 Data from Local System |
MalwareUSBferry | USBferry can collect information from an air-gapped host machine. |
| T1005 Data from Local System |
MalwareLatrodectus | Latrodectus can collect data from a compromised host using a stealer module. |
| T1005 Data from Local System |
MalwareSaint Bot | Saint Bot can collect files and information from a compromised host. |
| T1005 Data from Local System |
MalwareLODEINFO | LODEINFO can upload files from infected hosts to the C2. |
| T1005 Data from Local System |
MalwareCharmPower | CharmPower can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareGlassWorm | GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads. |
| T1005 Data from Local System |
MalwareUroburos | Uroburos can use its `Get` command to exfiltrate specified files from the compromised system. |
| T1005 Data from Local System |
MalwareBandook | Bandook can collect local files from the system . |
| T1005 Data from Local System |
MalwareKONNI | KONNI has stored collected information and discovered processes in a tmp file. |
| T1005 Data from Local System |
MalwareRAPIDPULSE | RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell. |
| T1005 Data from Local System |
MalwareDnsSystem | DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string. |
| T1005 Data from Local System |
MalwareKGH_SPY | KGH_SPY can send a file containing victim system information to C2. |
| T1005 Data from Local System |
MalwareIxeshe | Ixeshe can collect data from a local system. |
| T1005 Data from Local System |
MalwareRedLine Stealer | RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram. |
| T1005 Data from Local System |
MalwareBoxCaon | BoxCaon can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareNightClub | NightClub can use a file monitor to steal specific files from targeted systems. |
| T1005 Data from Local System |
MalwareCrutch | Crutch can exfiltrate files from compromised systems. |
| T1005 Data from Local System |
MalwareSDBbot | SDBbot has the ability to access the file system on a compromised host. |
| T1005 Data from Local System |
MalwareHikit | Hikit can upload files from compromised machines. |
| T1005 Data from Local System |
MalwareWellMail | WellMail can exfiltrate files from the victim machine. |
| T1005 Data from Local System |
MalwareRawPOS | RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data. |
| T1005 Data from Local System |
MalwareZxxZ | ZxxZ can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareDrovorub | Drovorub can transfer files from the victim machine. |
| T1005 Data from Local System |
MalwareShark | Shark can upload files to its C2. |
| T1005 Data from Local System |
MalwareBazar | Bazar can retrieve information from the infected machine. |
| T1005 Data from Local System |
MalwareBadPatch | BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.