ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
ToolIronNetInjector

IronNetInjector has the ability to decrypt embedded .NET and PE payloads.

T1140
Deobfuscate/Decode Files or Information
ToolExpand

Expand can be used to decompress a local or remote CAB file into an executable.

T1140
Deobfuscate/Decode Files or Information
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to decrypt obfuscated payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareCanisterWorm

CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload.

T1140
Deobfuscate/Decode Files or Information
MalwareBADFLICK

BADFLICK can decode shellcode using a custom rotating XOR cipher.

T1176.001
Browser Extensions
GroupKimsuky

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.

T1176.001
Browser Extensions
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data.

T1176.001
Browser Extensions
MalwareMispadu

Mispadu utilizes malicious Google Chrome browser extensions to steal financial data.

T1176.001
Browser Extensions
MalwareLumma Stealer

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

T1176.001
Browser Extensions
MalwareBundlore

Bundlore can install malicious browser extensions that are used to hijack user searches.

T1176.001
Browser Extensions
MalwareGrandoreiro

Grandoreiro can use malicious browser extensions to steal cookies and other user information.

T1176.001
Browser Extensions
MalwareOSX/Shlayer

OSX/Shlayer can install malicious Safari browser extensions to serve ads.

T1176.002
IDE Extensions
GroupMustang Panda

Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads.

T1176.002
IDE Extensions
GroupTeamPCP

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1185
Browser Session Hijacking
GroupKimsuky

Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms.

T1185
Browser Session Hijacking
MalwareTrickBot

TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page.

T1185
Browser Session Hijacking
MalwareUrsnif

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).

T1185
Browser Session Hijacking
MalwareTRANSLATEXT

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1185
Browser Session Hijacking
MalwareChaes

Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1185
Browser Session Hijacking
MalwareXLoader

XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1185
Browser Session Hijacking
MalwareMelcoz

Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background.

T1185
Browser Session Hijacking
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareQakBot

QakBot can use advanced web injects to steal web banking credentials.

T1185
Browser Session Hijacking
MalwareDridex

Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies.

T1185
Browser Session Hijacking
Toolevilginx2

evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions.

T1185
Browser Session Hijacking
MalwareKali365

Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.

T1187
Forced Authentication
GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

T1187
Forced Authentication
GroupDarkHydrus

DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials.

T1187
Forced Authentication
MalwareEnvyScout

EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure.

T1189
Drive-by Compromise
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322.

T1189
Drive-by Compromise
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package.

T1189
Drive-by Compromise
CampaignC0010

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.

T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1189
Drive-by Compromise
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.

T1189
Drive-by Compromise
GroupMustard Tempest

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1189
Drive-by Compromise
GroupPatchwork

Patchwork has used watering holes to deliver files with exploits to initial victims.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1189
Drive-by Compromise
GroupAPT32

APT32 has infected victims by tricking them into visiting compromised watering hole websites.

T1189
Drive-by Compromise
GroupLeafminer

Leafminer has infected victims using watering holes.

T1189
Drive-by Compromise
GroupMachete

Machete has distributed Machete through a fake blog website.

T1189
Drive-by Compromise
GroupAndariel

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

T1189
Drive-by Compromise
GroupCURIUM

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1189
Drive-by Compromise
GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

T1189
Drive-by Compromise
GroupWindigo

Windigo has distributed Windows malware via drive-by downloads.

T1189
Drive-by Compromise
GroupLeviathan

Leviathan has infected victims using watering holes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.