Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
ToolIronNetInjector | IronNetInjector has the ability to decrypt embedded .NET and PE payloads. |
| T1140 Deobfuscate/Decode Files or Information |
ToolExpand | Expand can be used to decompress a local or remote CAB file into an executable. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to decrypt obfuscated payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCanisterWorm | CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBADFLICK | BADFLICK can decode shellcode using a custom rotating XOR cipher. |
| T1176.001 Browser Extensions |
GroupKimsuky | Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies. |
| T1176.001 Browser Extensions |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to capture credentials, cookies, browser screenshots, etc. and to exfiltrate data. |
| T1176.001 Browser Extensions |
MalwareMispadu | Mispadu utilizes malicious Google Chrome browser extensions to steal financial data. |
| T1176.001 Browser Extensions |
MalwareLumma Stealer | Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data. |
| T1176.001 Browser Extensions |
MalwareBundlore | Bundlore can install malicious browser extensions that are used to hijack user searches. |
| T1176.001 Browser Extensions |
MalwareGrandoreiro | Grandoreiro can use malicious browser extensions to steal cookies and other user information. |
| T1176.001 Browser Extensions |
MalwareOSX/Shlayer | OSX/Shlayer can install malicious Safari browser extensions to serve ads. |
| T1176.002 IDE Extensions |
GroupMustang Panda | Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads. |
| T1176.002 IDE Extensions |
GroupTeamPCP | TeamPCP has compromised VS Code and Open VSX IDE extensions. |
| T1185 Browser Session Hijacking |
GroupKimsuky | Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. |
| T1185 Browser Session Hijacking |
MalwareTrickBot | TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. |
| T1185 Browser Session Hijacking |
MalwareUrsnif | Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords). |
| T1185 Browser Session Hijacking |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1185 Browser Session Hijacking |
MalwareChaes | Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts. |
| T1185 Browser Session Hijacking |
MalwareGrandoreiro | Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1185 Browser Session Hijacking |
MalwareXLoader | XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1185 Browser Session Hijacking |
MalwareCarberp | Carberp has captured credentials when a user performs login through a SSL session. |
| T1185 Browser Session Hijacking |
MalwareMelcoz | Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background. |
| T1185 Browser Session Hijacking |
MalwareAgent Tesla | Agent Tesla has the ability to use form-grabbing to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1185 Browser Session Hijacking |
MalwareDridex | Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. |
| T1185 Browser Session Hijacking |
Toolevilginx2 | evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions. |
| T1185 Browser Session Hijacking |
MalwareKali365 | Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment. |
| T1187 Forced Authentication |
GroupDragonfly | Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems. |
| T1187 Forced Authentication |
GroupDarkHydrus | DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials. |
| T1187 Forced Authentication |
MalwareEnvyScout | EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure. |
| T1189 Drive-by Compromise |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322. |
| T1189 Drive-by Compromise |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package. |
| T1189 Drive-by Compromise |
CampaignC0010 | During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021. |
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1189 Drive-by Compromise |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1189 Drive-by Compromise |
GroupPatchwork | Patchwork has used watering holes to deliver files with exploits to initial victims. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1189 Drive-by Compromise |
GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| T1189 Drive-by Compromise |
GroupLeafminer | Leafminer has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupMachete | Machete has distributed Machete through a fake blog website. |
| T1189 Drive-by Compromise |
GroupAndariel | Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range. |
| T1189 Drive-by Compromise |
GroupCURIUM | CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. |
| T1189 Drive-by Compromise |
GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| T1189 Drive-by Compromise |
GroupWindigo | Windigo has distributed Windows malware via drive-by downloads. |
| T1189 Drive-by Compromise |
GroupLeviathan | Leviathan has infected victims using watering holes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.