ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1120
Peripheral Device Discovery
MalwareBADNEWS

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.

T1120
Peripheral Device Discovery
MalwareQakBot

QakBot can identify peripheral devices on targeted systems.

T1120
Peripheral Device Discovery
MalwarejRAT

jRAT can map UPnP ports.

T1120
Peripheral Device Discovery
MalwareINC Ransomware

INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.

T1120
Peripheral Device Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list connected devices.

T1123
Audio Capture
GroupAPT37

APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input.

T1123
Audio Capture
GroupVOID MANTICORE

VOID MANTICORE has gathered audio during a Zoom session.

T1123
Audio Capture
MalwareDOGCALL

DOGCALL can capture microphone data from the victim's machine.

T1123
Audio Capture
MalwareJanicab

Janicab captured audio and sent it out to a C2 server.

T1123
Audio Capture
MalwareEvilGrab

EvilGrab has the capability to capture audio from a victim machine.

T1123
Audio Capture
MalwareCrimson

Crimson can perform audio surveillance using microphones.

T1123
Audio Capture
MalwareMachete

Machete captures audio from the computer’s microphone.

T1123
Audio Capture
MalwareInvisiMole

InvisiMole can record sound using input audio devices.

T1123
Audio Capture
MalwareVERMIN

VERMIN can perform audio capture.

T1123
Audio Capture
MalwareDarkComet

DarkComet can listen in to victims' conversations through the system’s microphone.

T1123
Audio Capture
MalwareLightSpy

LightSpy uses Apple's built-in AVFoundation Framework library to capture and manage audio recordings then transform them to JSON blobs for exfiltration.

T1123
Audio Capture
MalwareROKRAT

ROKRAT has an audio capture and eavesdropping module.

T1123
Audio Capture
MalwareBandook

Bandook has modules that are capable of capturing audio.

T1123
Audio Capture
MalwareT9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.

T1123
Audio Capture
MalwareMicropsia

Micropsia can perform microphone recording.

T1123
Audio Capture
MalwareAttor

Attor's has a plugin that is capable of recording audio using available input sound devices.

T1123
Audio Capture
MalwareNightClub

NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio.

T1123
Audio Capture
MalwareDerusbi

Derusbi is capable of performing audio captures.

T1123
Audio Capture
MalwareMgBot

MgBot can capture input and output audio streams from infected devices.

T1123
Audio Capture
MalwareCadelspy

Cadelspy has the ability to record audio from the compromised host.

T1123
Audio Capture
MalwareCobian RAT

Cobian RAT has a feature to perform voice recording on the victim’s machine.

T1123
Audio Capture
MalwareNanoCore

NanoCore can capture audio feeds from the system.

T1123
Audio Capture
MalwareTajMahal

TajMahal has the ability to capture VoiceIP application audio on an infected host.

T1123
Audio Capture
MalwareRevenge RAT

Revenge RAT has a plugin for microphone interception.

T1123
Audio Capture
MalwareMacMa

MacMa has the ability to record audio.

T1123
Audio Capture
MalwarejRAT

jRAT can capture microphone recordings.

T1123
Audio Capture
MalwareMacSpy

MacSpy can record the sounds from microphones on a computer.

T1123
Audio Capture
ToolPowerSploit

PowerSploit's Get-MicrophoneAudio Exfiltration module can record system microphone audio.

T1123
Audio Capture
ToolRemcos

Remcos can capture data from the system’s microphone.

T1123
Audio Capture
ToolImminent Monitor

Imminent Monitor has a remote microphone monitoring capability.

T1123
Audio Capture
ToolPupy

Pupy can record sound with the microphone.

T1123
Audio Capture
MalwareFlame

Flame can record audio using any existing hardware recording devices.

T1124
System Time Discovery
CampaignC0015

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.

T1124
System Time Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance.

T1124
System Time Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system.

T1124
System Time Discovery
GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

T1124
System Time Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system timezone.

T1124
System Time Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

T1124
System Time Discovery
GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1124
System Time Discovery
GroupSidewinder

Sidewinder has used tools to obtain the current system time.

T1124
System Time Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

T1124
System Time Discovery
GroupUNC3886

UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts.

T1124
System Time Discovery
GroupHigaisa

Higaisa used a function to gather the current time.

T1124
System Time Discovery
GroupThe White Company

The White Company has checked the current date on the victim system.

T1124
System Time Discovery
GroupTurla

Turla surveys a system upon check-in to discover the system time by using the net time command.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.