Real-world descriptions of how a group, tool or campaign used a technique.
95 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareOopsIE | OopsIE stages the output from command execution and collected files in specific folders before exfiltration. |
| T1074.001 Local Data Staging |
MalwareAttor | Attor has staged collected data in a central upload directory prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareBoxCaon | BoxCaon has created a working folder for collected files that it sends to the C2 server. |
| T1074.001 Local Data Staging |
MalwareNightClub | NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts. |
| T1074.001 Local Data Staging |
MalwareCrutch | Crutch has staged stolen files in the |
| T1074.001 Local Data Staging |
MalwareRawPOS | Data captured by RawPOS is placed in a temporary file under a directory named "memdump". |
| T1074.001 Local Data Staging |
MalwareBadPatch | BadPatch stores collected data in log files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareMESSAGETAP | MESSAGETAP stored targeted SMS messages that matched its target list in CSV files on the compromised system. |
| T1074.001 Local Data Staging |
MalwareSUGARDUMP | SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`. |
| T1074.001 Local Data Staging |
MalwareMoonWind | MoonWind saves information from its keylogging routine as a .zip file in the present working directory. |
| T1074.001 Local Data Staging |
MalwareCorKLOG | CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key. |
| T1074.001 Local Data Staging |
Malwareccf32 | ccf32 can temporarily store files in a hidden directory on the local host. |
| T1074.001 Local Data Staging |
MalwareZebrocy | Zebrocy stores all collected information in a single file before exfiltration. |
| T1074.001 Local Data Staging |
MalwareLunarMail | LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration. |
| T1074.001 Local Data Staging |
MalwareSampleCheck5000 | SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMilan | Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`. |
| T1074.001 Local Data Staging |
MalwareUSBStealer | USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration. |
| T1074.001 Local Data Staging |
MalwareOilBooster | OilBooster can stage files in the `tempFiles` directory for exfiltration. |
| T1074.001 Local Data Staging |
MalwarePoisonIvy | PoisonIvy stages collected data in a text file. |
| T1074.001 Local Data Staging |
MalwareCarbon | Carbon creates a base directory that contains the files and folders that are collected. |
| T1074.001 Local Data Staging |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1074.001 Local Data Staging |
MalwareGold Dragon | Gold Dragon stores information gathered from the endpoint in a file named 1.hwp. |
| T1074.001 Local Data Staging |
MalwareRamsay | Ramsay can stage data prior to exfiltration in |
| T1074.001 Local Data Staging |
MalwareMacMa | MacMa has stored collected files locally before exfiltration. |
| T1074.001 Local Data Staging |
MalwareFunnyDream | FunnyDream can stage collected information including screen captures and logged keystrokes locally. |
| T1074.001 Local Data Staging |
MalwarePUNCHTRACK | PUNCHTRACK aggregates collected data in a tmp file. |
| T1074.001 Local Data Staging |
MalwareLAMEHUG | LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration. |
| T1074.001 Local Data Staging |
MalwareRIFLESPINE | RIFLESPINE can stage the output from executed C2 commands to a temporary file. |
| T1074.001 Local Data Staging |
MalwareSLIGHTPULSE | SLIGHTPULSE has piped the output from executed commands to `/tmp/1`. |
| T1074.001 Local Data Staging |
MalwareTroll Stealer | Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure. |
| T1074.001 Local Data Staging |
MalwaremetaMain | metaMain has stored the collected system files in a working directory. |
| T1074.001 Local Data Staging |
MalwareMis-Type | Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`. |
| T1074.001 Local Data Staging |
MalwareOctopus | Octopus has stored collected information in the Application Data directory on a compromised host. |
| T1074.001 Local Data Staging |
MalwareSTARWHALE | STARWHALE has stored collected data in a file called `stari.txt`. |
| T1074.001 Local Data Staging |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON has stored keystrokes and screenshots within the |
| T1074.001 Local Data Staging |
MalwareBADNEWS | BADNEWS copies documents under 15MB found on the victim system to is the user's |
| T1074.001 Local Data Staging |
MalwareDRYHOOK | DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`. |
| T1074.001 Local Data Staging |
MalwareAstaroth | Astaroth collects data in a plaintext file named r1.log before exfiltration. |
| T1074.001 Local Data Staging |
MalwareQakBot | QakBot has stored stolen emails and other data into new folders prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareHelminth | Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server. |
| T1074.001 Local Data Staging |
MalwareDtrack | Dtrack can save collected data to disk, different file formats, and network shares. |
| T1074.001 Local Data Staging |
MalwareSLOWPULSE | SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`. |
| T1074.001 Local Data Staging |
MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data. |
| T1074.001 Local Data Staging |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.