Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1614 System Location Discovery |
MalwareXORIndex Loader | XORIndex Loader can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
ToolRemcos | Remcos can identify the location of targeted devices. |
| T1614 System Location Discovery |
ToolQuasarRAT | QuasarRAT can determine the country a victim host is located in. |
| T1614 System Location Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings. |
| T1614.001 System Language Discovery |
MalwareSpark | Spark has checked the results of the |
| T1614.001 System Language Discovery |
MalwareSynAck | SynAck lists all the keyboard layouts installed on the victim’s system using |
| T1614.001 System Language Discovery |
MalwareSharpStage | SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed. |
| T1614.001 System Language Discovery |
MalwareMisdat | Misdat has attempted to detect if a compromised host had a Japanese keyboard via the Windows API call `GetKeyboardType`. |
| T1614.001 System Language Discovery |
MalwareZeus Panda | Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN. |
| T1614.001 System Language Discovery |
MalwarePUBLOAD | PUBLOAD has checked supported languages on the compromised system. |
| T1614.001 System Language Discovery |
MalwareGootloader | Gootloader can determine if a victim's computer is running an operating system with specific language preferences. |
| T1614.001 System Language Discovery |
MalwareDropBook | DropBook has checked for the presence of Arabic language in the infected machine's settings. |
| T1614.001 System Language Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`). |
| T1614.001 System Language Discovery |
MalwareNeoichor | Neoichor can identify the system language on a compromised host. |
| T1614.001 System Language Discovery |
MalwareMispadu | Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese. |
| T1614.001 System Language Discovery |
MalwareIcedID | IcedID used the following command to check the country/language of the active console: |
| T1614.001 System Language Discovery |
MalwareMarkiRAT | MarkiRAT can use the |
| T1614.001 System Language Discovery |
MalwareAvaddon | Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities. |
| T1614.001 System Language Discovery |
MalwareFlagpro | Flagpro can check whether the target system is using Japanese, Taiwanese, or English through detection of specific Windows Security and Internet Explorer dialog. |
| T1614.001 System Language Discovery |
MalwareS-Type | S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call. |
| T1614.001 System Language Discovery |
MalwareCuba | Cuba can check if Russian language is installed on the infected machine by using the function |
| T1614.001 System Language Discovery |
MalwareDEATHRANSOM | Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit. |
| T1614.001 System Language Discovery |
MalwareLockBit 3.0 | LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages. |
| T1614.001 System Language Discovery |
MalwareLODEINFO | LODEINFO can looks for the “en_US” locale on the victim’s machine. |
| T1614.001 System Language Discovery |
MalwareGlassWorm | GlassWorm has identified the system language settings by checking for `ru_RU`, `ru-RU`, `ru`, and `Russian` to prevent execution in a Russian associated device. |
| T1614.001 System Language Discovery |
MalwareRedLine Stealer | RedLine Stealer can retrieve system default language and time zone. |
| T1614.001 System Language Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies the language on the victim system. |
| T1614.001 System Language Discovery |
MalwareStrelaStealer | StrelaStealer variants check system language settings via keyboard layout or similar mechanisms. |
| T1614.001 System Language Discovery |
MalwareBazar | Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian. |
| T1614.001 System Language Discovery |
MalwareRyuk | Ryuk has been observed to query the registry key |
| T1614.001 System Language Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so. |
| T1614.001 System Language Discovery |
MalwareREvil | REvil can check the system language using |
| T1614.001 System Language Discovery |
MalwareGrimAgent | GrimAgent has used |
| T1614.001 System Language Discovery |
MalwareClop | Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the |
| T1614.001 System Language Discovery |
MalwareStealBit | StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries. |
| T1614.001 System Language Discovery |
MalwareMaze | Maze has checked the language of the machine with function |
| T1614.001 System Language Discovery |
MalwareXCSSET | XCSSET uses AppleScript to check the host's language and location with the command |
| T1614.001 System Language Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language. |
| T1614.001 System Language Discovery |
MalwareCanisterWorm | CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component. |
| T1615 Group Policy Discovery |
MalwareEmissary | Emissary has the capability to execute |
| T1615 Group Policy Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify victim environment Group Policy information. |
| T1615 Group Policy Discovery |
MalwareLunarWeb | LunarWeb can capture information on group policy settings |
| T1615 Group Policy Discovery |
ToolBloodHound | BloodHound has the ability to collect local admin information via GPO. |
| T1615 Group Policy Discovery |
ToolEmpire | Empire includes various modules for enumerating Group Policy. |
| T1619 Cloud Storage Object Discovery |
ToolPacu | Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes. |
| T1619 Cloud Storage Object Discovery |
ToolTruffleHog | TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets. |
| T1619 Cloud Storage Object Discovery |
ToolPeirates | Peirates can list AWS S3 buckets. |
| T1620 Reflective Code Loading |
MalwarePikabot | Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine. |
| T1620 Reflective Code Loading |
MalwareSardonic | Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions. |
| T1620 Reflective Code Loading |
MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.