ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1033×

196 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareBonadan

Bonadan has discovered the username of the user running the backdoor.

T1033
System Owner/User Discovery
MalwareNeoichor

Neoichor can collect the user name from a victim's machine.

T1033
System Owner/User Discovery
MalwareRaspberry Robin

Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges.

T1033
System Owner/User Discovery
MalwareDiavol

Diavol can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s username.

T1033
System Owner/User Discovery
MalwareBlackCat

BlackCat can utilize `net use` commands to discover the user name on a compromised host.

T1033
System Owner/User Discovery
MalwareVERMIN

VERMIN gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareNightdoor

Nightdoor gathers information on victim system users and usernames.

T1033
System Owner/User Discovery
MalwareMarkiRAT

MarkiRAT can retrieve the victim’s username.

T1033
System Owner/User Discovery
MalwarePowerShower

PowerShower has the ability to identify the current user on the infected host.

T1033
System Owner/User Discovery
MalwareKazuar

Kazuar gathers information on users.

T1033
System Owner/User Discovery
MalwareDarkComet

DarkComet gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1033
System Owner/User Discovery
MalwareLucifer

Lucifer has the ability to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwarezwShell

zwShell can obtain the name of the logged-in user on the victim.

T1033
System Owner/User Discovery
MalwareDRATzarus

DRATzarus can obtain a list of users from an infected machine.

T1033
System Owner/User Discovery
MalwareRising Sun

Rising Sun can detect the username of the infected host.

T1033
System Owner/User Discovery
MalwareChrommme

Chrommme can retrieve the username from a targeted system.

T1033
System Owner/User Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted usernames on infected endpoints.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1033
System Owner/User Discovery
MalwareFlagpro

Flagpro has been used to run the whoami command on the system.

T1033
System Owner/User Discovery
MalwareXAgentOSX

XAgentOSX contains the getInfoOSX function to return the OS X version as well as the current user.

T1033
System Owner/User Discovery
MalwareROKRAT

ROKRAT can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareDarkWatchman

DarkWatchman has collected the username from a victim machine.

T1033
System Owner/User Discovery
MalwareDyre

Dyre has the ability to identify the users on a compromised host.

T1033
System Owner/User Discovery
MalwarePlugX

PlugX has the ability to gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareReaver

Reaver collects the victim's username.

T1033
System Owner/User Discovery
MalwareS-Type

S-Type has run tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareRemsec

Remsec can obtain information about the current user.

T1033
System Owner/User Discovery
MalwareExplosive

Explosive has collected the username from the infected host.

T1033
System Owner/User Discovery
MalwareEpic

Epic collects the user name from the victim’s machine.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwarePureCrypter

PureCrypter can retrieve the username from targeted machines.

T1033
System Owner/User Discovery
MalwareNanHaiShu

NanHaiShu collects the username from the victim.

T1033
System Owner/User Discovery
MalwareSVCReady

SVCReady can collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareNGLite

NGLite will run the whoami command to gather system information and return this to the command and control server.

T1033
System Owner/User Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of user accounts from a victim's machine.

T1033
System Owner/User Discovery
MalwareGazer

Gazer obtains the current user's security identifier.

T1033
System Owner/User Discovery
MalwareLatrodectus

Latrodectus can discover the username of an infected host.

T1033
System Owner/User Discovery
MalwareSaint Bot

Saint Bot can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareChaes

Chaes has collected the username and UID from the infected machine.

T1033
System Owner/User Discovery
MalwareLODEINFO

LODEINFO can identify the associated username on targeted machines.

T1033
System Owner/User Discovery
MalwareEVILNUM

EVILNUM can obtain the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used whoami commands to identify system owners.

T1033
System Owner/User Discovery
MalwareQUADAGENT

QUADAGENT gathers the victim username.

T1033
System Owner/User Discovery
MalwareSys10

Sys10 collects the account name of the logged-in user and sends it to the C2.

T1033
System Owner/User Discovery
MalwareMetamorfo

Metamorfo has collected the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information about the user on a compromised host.

T1033
System Owner/User Discovery
MalwareKONNI

KONNI can collect the username from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.