Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1589.002 Email Addresses |
ToolAADInternals | AADInternals can check for the existence of user email addresses using public Microsoft APIs. |
| T1590.001 Domain Properties |
ToolAADInternals | AADInternals can gather information about a tenant’s domains using public Microsoft APIs. |
| T1593.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string. |
| T1598.003 Spearphishing Link |
MalwareSMOKEDHAM | SMOKEDHAM has been delivered via malicious links in phishing emails. |
| T1598.003 Spearphishing Link |
Toolevilginx2 | evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing. |
| T1598.003 Spearphishing Link |
ToolAADInternals | AADInternals can send phishing emails containing malicious links designed to collect users’ credentials. |
| T1601 Modify System Image |
MalwareDRYHOOK | DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code. |
| T1601.001 Patch System Image |
MalwareSYNful Knock | SYNful Knock is malware that is inserted into a network device by patching the operating system image. |
| T1602.002 Network Device Configuration Dump |
MalwareGlassWorm | GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`. |
| T1606.002 SAML Tokens |
ToolAADInternals | AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate. |
| T1608.001 Upload Malware |
MalwareShai-Hulud | Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts. |
| T1609 Container Administration Command |
MalwareHildegard | Hildegard was executed through the kubelet API run command and by executing commands on running containers. |
| T1609 Container Administration Command |
MalwareSiloscape | Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster. |
| T1609 Container Administration Command |
MalwareKinsing | Kinsing was executed with an Ubuntu container entry point that runs shell scripts. |
| T1609 Container Administration Command |
ToolPeirates | Peirates can use `kubectl` or the Kubernetes API to run commands. |
| T1609 Container Administration Command |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes. |
| T1609 Container Administration Command |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`. |
| T1609 Container Administration Command |
MalwareCanisterWorm | CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl. |
| T1610 Deploy Container |
MalwareKinsing | Kinsing was run through a deployed Ubuntu container. |
| T1610 Deploy Container |
ToolPeirates | Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node. |
| T1610 Deploy Container |
MalwareDoki | Doki was run through a deployed container. |
| T1611 Escape to Host |
MalwareHildegard | Hildegard has used the BOtB tool that can break out of containers. |
| T1611 Escape to Host |
MalwareDoki | Doki’s container was configured to bind the host root directory. |
| T1611 Escape to Host |
MalwareSiloscape | Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of |
| T1611 Escape to Host |
ToolPeirates | Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath. |
| T1613 Container and Resource Discovery |
MalwareHildegard | Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers. |
| T1613 Container and Resource Discovery |
ToolPeirates | Peirates can enumerate Kubernetes pods in a given namespace. |
| T1613 Container and Resource Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials. |
| T1613 Container and Resource Discovery |
MalwareCanisterWorm | CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `. |
| T1614 System Location Discovery |
MalwareAmadey | Amadey does not run any tasks or install additional malware if the victim machine is based in Russia. |
| T1614 System Location Discovery |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine. |
| T1614 System Location Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”. |
| T1614 System Location Discovery |
MalwareCrimson | Crimson can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
MalwareGootloader | Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea. |
| T1614 System Location Discovery |
MalwareHexEval Loader | HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions. |
| T1614 System Location Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can determine the geographical location of a victim host by checking the language. |
| T1614 System Location Discovery |
MalwareSameCoin | SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location. |
| T1614 System Location Discovery |
MalwareRagnar Locker | Before executing malicious code, Ragnar Locker checks the Windows API |
| T1614 System Location Discovery |
MalwareSocGholish | SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations. |
| T1614 System Location Discovery |
MalwareDarkWatchman | DarkWatchman can identity the OS locale of a compromised host. |
| T1614 System Location Discovery |
MalwarePlugX | PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`. |
| T1614 System Location Discovery |
MalwarePureCrypter | PureCrypter can use `kernel32!GetGeoInfo` to determine system location. |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1614 System Location Discovery |
MalwareSaint Bot | Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova. |
| T1614 System Location Discovery |
MalwareGlassWorm | GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute. |
| T1614 System Location Discovery |
MalwareRedLine Stealer | RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service. |
| T1614 System Location Discovery |
MalwareSDBbot | SDBbot can collected the country code of a compromised machine. |
| T1614 System Location Discovery |
MalwareRaccoon Stealer | Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present. |
| T1614 System Location Discovery |
MalwareAshTag | AshTag can check geolocation on targeted systems. |
| T1614 System Location Discovery |
MalwareGrimAgent | GrimAgent can identify the country code on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.