ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1125
Video Capture
MalwareT9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.

T1125
Video Capture
MalwareSDBbot

SDBbot has the ability to record video on a compromised host.

T1125
Video Capture
MalwareDerusbi

Derusbi is capable of capturing video.

T1125
Video Capture
MalwareCobian RAT

Cobian RAT has a feature to access the webcam on the victim’s machine.

T1125
Video Capture
MalwareNanoCore

NanoCore can access the victim's webcam and capture data.

T1125
Video Capture
MalwareTajMahal

TajMahal has the ability to capture webcam video.

T1125
Video Capture
MalwareRevenge RAT

Revenge RAT has the ability to access the webcam.

T1125
Video Capture
MalwarePoetRAT

PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts.

T1125
Video Capture
MalwareZxShell

ZxShell has a command to perform video device spying.

T1125
Video Capture
MalwarenjRAT

njRAT can access the victim's webcam.

T1125
Video Capture
MalwareAgent Tesla

Agent Tesla can access the victim’s webcam and record video.

T1125
Video Capture
MalwarejRAT

jRAT has the capability to capture video from a webcam.

T1125
Video Capture
MalwareWarzoneRAT

WarzoneRAT can access the webcam on a victim's machine.

T1125
Video Capture
ToolEmpire

Empire can capture webcam data on Windows and macOS systems.

T1125
Video Capture
ToolPcShare

PcShare can capture camera video as part of its collection process.

T1125
Video Capture
ToolAsyncRAT

AsyncRAT can record screen content on targeted systems.

T1125
Video Capture
ToolRemcos

Remcos can access a system’s webcam and take pictures.

T1125
Video Capture
ToolConnectWise

ConnectWise can record video on remote hosts.

T1125
Video Capture
ToolImminent Monitor

Imminent Monitor has a remote webcam monitoring capability.

T1125
Video Capture
ToolPupy

Pupy can access a connected webcam and capture pictures.

T1125
Video Capture
ToolQuasarRAT

QuasarRAT can perform webcam viewing.

T1125
Video Capture
ToolQuick Assist

Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity.

T1127.001
MSBuild
CampaignFrankenstein

During Frankenstein, the threat actors used MSbuild to execute an actor-created file.

T1127.001
MSBuild
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool.

T1127.001
MSBuild
MalwarePlugX

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.

T1127.001
MSBuild
MalwareNOOPLDR

NOOPLDR can be executed via MSBuild.

T1127.001
MSBuild
ToolEmpire

Empire can use built-in modules to abuse trusted utilities like MSBuild.exe.

T1129
Shared Modules
GroupMustang Panda

Mustang Panda has leveraged `LoadLibrary` to load DLLs.

T1129
Shared Modules
MalwareBLINDINGCAN

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

T1129
Shared Modules
MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

T1129
Shared Modules
MalwareStuxnet

Stuxnet calls LoadLibrary then executes exports from a DLL.

T1129
Shared Modules
MalwareRotaJakiro

RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`.

T1129
Shared Modules
MalwareVersaMem

VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory.

T1129
Shared Modules
MalwareBOOSTWRITE

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

T1129
Shared Modules
MalwareLightSpy

LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class.

T1129
Shared Modules
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1129
Shared Modules
MalwareDarkWatchman

DarkWatchman can load DLLs.

T1129
Shared Modules
MalwareFoggyWeb

FoggyWeb's loader can call the load() function to load the FoggyWeb dll into an Application Domain on a compromised AD FS server.

T1129
Shared Modules
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1129
Shared Modules
MalwareMetamorfo

Metamorfo had used AutoIt to load and execute the DLL payload.

T1129
Shared Modules
MalwarePipeMon

PipeMon has used call to LoadLibrary to load its installer. PipeMon loads its modules using reflective loading or custom shellcode.

T1129
Shared Modules
Malwaregh0st RAT

gh0st RAT can load DLLs into memory.

T1129
Shared Modules
MalwareAttor

Attor's dispatcher can execute additional plugins by loading the respective DLLs.

T1129
Shared Modules
MalwareOSX_OCEANLOTUS.D

For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`.

T1129
Shared Modules
MalwareTajMahal

TajMahal has the ability to inject the LoadLibrary call template DLL into running processes.

T1129
Shared Modules
MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1129
Shared Modules
MalwareKillDisk

KillDisk loads and executes functions from a DLL.

T1129
Shared Modules
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

T1129
Shared Modules
MalwareDtrack

Dtrack contains a function that calls LoadLibrary and GetProcAddress.

T1132
Data Encoding
GroupVelvet Ant

Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.