Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1125 Video Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1125 Video Capture |
MalwareSDBbot | SDBbot has the ability to record video on a compromised host. |
| T1125 Video Capture |
MalwareDerusbi | Derusbi is capable of capturing video. |
| T1125 Video Capture |
MalwareCobian RAT | Cobian RAT has a feature to access the webcam on the victim’s machine. |
| T1125 Video Capture |
MalwareNanoCore | NanoCore can access the victim's webcam and capture data. |
| T1125 Video Capture |
MalwareTajMahal | TajMahal has the ability to capture webcam video. |
| T1125 Video Capture |
MalwareRevenge RAT | Revenge RAT has the ability to access the webcam. |
| T1125 Video Capture |
MalwarePoetRAT | PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts. |
| T1125 Video Capture |
MalwareZxShell | ZxShell has a command to perform video device spying. |
| T1125 Video Capture |
MalwarenjRAT | njRAT can access the victim's webcam. |
| T1125 Video Capture |
MalwareAgent Tesla | Agent Tesla can access the victim’s webcam and record video. |
| T1125 Video Capture |
MalwarejRAT | jRAT has the capability to capture video from a webcam. |
| T1125 Video Capture |
MalwareWarzoneRAT | WarzoneRAT can access the webcam on a victim's machine. |
| T1125 Video Capture |
ToolEmpire | Empire can capture webcam data on Windows and macOS systems. |
| T1125 Video Capture |
ToolPcShare | PcShare can capture camera video as part of its collection process. |
| T1125 Video Capture |
ToolAsyncRAT | AsyncRAT can record screen content on targeted systems. |
| T1125 Video Capture |
ToolRemcos | Remcos can access a system’s webcam and take pictures. |
| T1125 Video Capture |
ToolConnectWise | ConnectWise can record video on remote hosts. |
| T1125 Video Capture |
ToolImminent Monitor | Imminent Monitor has a remote webcam monitoring capability. |
| T1125 Video Capture |
ToolPupy | Pupy can access a connected webcam and capture pictures. |
| T1125 Video Capture |
ToolQuasarRAT | QuasarRAT can perform webcam viewing. |
| T1125 Video Capture |
ToolQuick Assist | Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity. |
| T1127.001 MSBuild |
CampaignFrankenstein | During Frankenstein, the threat actors used MSbuild to execute an actor-created file. |
| T1127.001 MSBuild |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool. |
| T1127.001 MSBuild |
MalwarePlugX | A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques. |
| T1127.001 MSBuild |
MalwareNOOPLDR | NOOPLDR can be executed via MSBuild. |
| T1127.001 MSBuild |
ToolEmpire | Empire can use built-in modules to abuse trusted utilities like MSBuild.exe. |
| T1129 Shared Modules |
GroupMustang Panda | Mustang Panda has leveraged `LoadLibrary` to load DLLs. |
| T1129 Shared Modules |
MalwareBLINDINGCAN | BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine. |
| T1129 Shared Modules |
MalwareBumblebee | Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll. |
| T1129 Shared Modules |
MalwareStuxnet | Stuxnet calls LoadLibrary then executes exports from a DLL. |
| T1129 Shared Modules |
MalwareRotaJakiro | RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`. |
| T1129 Shared Modules |
MalwareVersaMem | VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory. |
| T1129 Shared Modules |
MalwareBOOSTWRITE | BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules. |
| T1129 Shared Modules |
MalwareLightSpy | LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class. |
| T1129 Shared Modules |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using the LoadLibrary API. |
| T1129 Shared Modules |
MalwareDarkWatchman | DarkWatchman can load DLLs. |
| T1129 Shared Modules |
MalwareFoggyWeb | FoggyWeb's loader can call the |
| T1129 Shared Modules |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can load and call DLL functions. |
| T1129 Shared Modules |
MalwareMetamorfo | Metamorfo had used AutoIt to load and execute the DLL payload. |
| T1129 Shared Modules |
MalwarePipeMon | PipeMon has used call to |
| T1129 Shared Modules |
Malwaregh0st RAT | gh0st RAT can load DLLs into memory. |
| T1129 Shared Modules |
MalwareAttor | Attor's dispatcher can execute additional plugins by loading the respective DLLs. |
| T1129 Shared Modules |
MalwareOSX_OCEANLOTUS.D | For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`. |
| T1129 Shared Modules |
MalwareTajMahal | TajMahal has the ability to inject the |
| T1129 Shared Modules |
MalwareEbury | Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`. |
| T1129 Shared Modules |
MalwareKillDisk | KillDisk loads and executes functions from a DLL. |
| T1129 Shared Modules |
MalwareAstaroth | Astaroth uses the LoadLibraryExW() function to load additional modules. |
| T1129 Shared Modules |
MalwareDtrack | Dtrack contains a function that calls |
| T1132 Data Encoding |
GroupVelvet Ant | Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.