Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1217 Browser Information Discovery |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1217 Browser Information Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1217 Browser Information Discovery |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1217 Browser Information Discovery |
MalwareDarkWatchman | DarkWatchman can retrieve browser history. |
| T1217 Browser Information Discovery |
MalwareLumma Stealer | Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers. |
| T1217 Browser Information Discovery |
MalwareGlassWorm | GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets. |
| T1217 Browser Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information from browsers and browser extensions. |
| T1217 Browser Information Discovery |
MalwareSUGARDUMP | SUGARDUMP has collected browser bookmark and history information. |
| T1217 Browser Information Discovery |
MalwareCalisto | Calisto collects information on bookmarks from Google Chrome. |
| T1217 Browser Information Discovery |
MalwareTroll Stealer | Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions. |
| T1217 Browser Information Discovery |
MalwareLizar | Lizar can retrieve browser history and database files. |
| T1217 Browser Information Discovery |
MalwareDtrack | Dtrack can retrieve browser history. |
| T1217 Browser Information Discovery |
ToolEmpire | Empire has the ability to gather browser data such as bookmarks and visited sites. |
| T1218 System Binary Proxy Execution |
GroupVolt Typhoon | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks. |
| T1218 System Binary Proxy Execution |
GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| T1218.001 Compiled HTML File |
GroupAPT38 | APT38 has used CHM files to move concealed payloads. |
| T1218.001 Compiled HTML File |
GroupAPT41 | APT41 used compiled HTML (.chm) files for targeting. |
| T1218.001 Compiled HTML File |
GroupOilRig | OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim. |
| T1218.001 Compiled HTML File |
GroupDark Caracal | Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable. |
| T1218.001 Compiled HTML File |
GroupSilence | Silence has weaponized CHM files in their phishing campaigns. |
| T1218.001 Compiled HTML File |
MalwareAstaroth | Astaroth uses ActiveX objects for file execution and manipulation. |
| T1218.002 Control Panel |
MalwareInvisiMole | InvisiMole can register itself for execution and persistence via the Control Panel. |
| T1218.002 Control Panel |
MalwareReaver | Reaver drops and executes a malicious CPL file as its payload. |
| T1218.003 CMSTP |
GroupMuddyWater | MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload. |
| T1218.003 CMSTP |
GroupCobalt Group | Cobalt Group has used the command |
| T1218.003 CMSTP |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile. |
| T1218.003 CMSTP |
MalwareLockBit 3.0 | LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges. |
| T1218.004 InstallUtil |
GroupmenuPass | menuPass has used |
| T1218.004 InstallUtil |
GroupMustang Panda | Mustang Panda has used |
| T1218.004 InstallUtil |
MalwareWhisperGate | WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender. |
| T1218.004 InstallUtil |
MalwareSaint Bot | Saint Bot had used `InstallUtil.exe` to download and deploy executables. |
| T1218.004 InstallUtil |
MalwareChaes | Chaes has used Installutill to download content. |
| T1218.004 InstallUtil |
ToolCovenant | Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners. |
| T1218.005 Mshta |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`. |
| T1218.005 Mshta |
CampaignC0015 | During C0015, the threat actors used `mshta` to execute DLLs. |
| T1218.005 Mshta |
GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| T1218.005 Mshta |
GroupSideCopy | SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
GroupAPT32 | APT32 has used mshta.exe for code execution. |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1218.005 Mshta |
GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| T1218.005 Mshta |
GroupSidewinder | Sidewinder has used |
| T1218.005 Mshta |
GroupMustang Panda | Mustang Panda has used mshta.exe to launch collection scripts. |
| T1218.005 Mshta |
GroupTA2541 | TA2541 has used `mshta` to execute scripts including VBS. |
| T1218.005 Mshta |
GroupConfucius | Confucius has used mshta.exe to execute malicious VBScript. |
| T1218.005 Mshta |
GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| T1218.005 Mshta |
GroupTA551 | TA551 has used mshta.exe to execute malicious payloads. |
| T1218.005 Mshta |
GroupLazyScripter | LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.