ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1217
Browser Information Discovery
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1217
Browser Information Discovery
MalwareLightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareDarkWatchman

DarkWatchman can retrieve browser history.

T1217
Browser Information Discovery
MalwareLumma Stealer

Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers.

T1217
Browser Information Discovery
MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information from browsers and browser extensions.

T1217
Browser Information Discovery
MalwareSUGARDUMP

SUGARDUMP has collected browser bookmark and history information.

T1217
Browser Information Discovery
MalwareCalisto

Calisto collects information on bookmarks from Google Chrome.

T1217
Browser Information Discovery
MalwareTroll Stealer

Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions.

T1217
Browser Information Discovery
MalwareLizar

Lizar can retrieve browser history and database files.

T1217
Browser Information Discovery
MalwareDtrack

Dtrack can retrieve browser history.

T1217
Browser Information Discovery
ToolEmpire

Empire has the ability to gather browser data such as bookmarks and visited sites.

T1218
System Binary Proxy Execution
GroupVolt Typhoon

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.

T1218
System Binary Proxy Execution
GroupLazarus Group

Lazarus Group lnk files used for persistence have abused the Windows Update Client (wuauclt.exe) to execute a malicious DLL.

T1218.001
Compiled HTML File
GroupAPT38

APT38 has used CHM files to move concealed payloads.

T1218.001
Compiled HTML File
GroupAPT41

APT41 used compiled HTML (.chm) files for targeting.

T1218.001
Compiled HTML File
GroupOilRig

OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim.

T1218.001
Compiled HTML File
GroupDark Caracal

Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1218.001
Compiled HTML File
MalwareAstaroth

Astaroth uses ActiveX objects for file execution and manipulation.

T1218.002
Control Panel
MalwareInvisiMole

InvisiMole can register itself for execution and persistence via the Control Panel.

T1218.002
Control Panel
MalwareReaver

Reaver drops and executes a malicious CPL file as its payload.

T1218.003
CMSTP
GroupMuddyWater

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.

T1218.003
CMSTP
GroupCobalt Group

Cobalt Group has used the command cmstp.exe /s /ns C:\Users\ADMINI~W\AppData\Local\Temp\XKNqbpzl.txt to bypass AppLocker and launch a malicious script.

T1218.003
CMSTP
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile.

T1218.003
CMSTP
MalwareLockBit 3.0

LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges.

T1218.004
InstallUtil
GroupmenuPass

menuPass has used InstallUtil.exe to execute malicious software.

T1218.004
InstallUtil
GroupMustang Panda

Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager.

T1218.004
InstallUtil
MalwareWhisperGate

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.

T1218.004
InstallUtil
MalwareSaint Bot

Saint Bot had used `InstallUtil.exe` to download and deploy executables.

T1218.004
InstallUtil
MalwareChaes

Chaes has used Installutill to download content.

T1218.004
InstallUtil
ToolCovenant

Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners.

T1218.005
Mshta
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`.

T1218.005
Mshta
CampaignC0015

During C0015, the threat actors used `mshta` to execute DLLs.

T1218.005
Mshta
GroupAPT38

APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files.

T1218.005
Mshta
GroupSideCopy

SideCopy has utilized `mshta.exe` to execute a malicious hta file.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.005
Mshta
GroupAPT32

APT32 has used mshta.exe for code execution.

T1218.005
Mshta
GroupMuddyWater

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.

T1218.005
Mshta
GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

T1218.005
Mshta
GroupFIN7

FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.

T1218.005
Mshta
GroupSidewinder

Sidewinder has used mshta.exe to execute malicious payloads.

T1218.005
Mshta
GroupMustang Panda

Mustang Panda has used mshta.exe to launch collection scripts.

T1218.005
Mshta
GroupTA2541

TA2541 has used `mshta` to execute scripts including VBS.

T1218.005
Mshta
GroupConfucius

Confucius has used mshta.exe to execute malicious VBScript.

T1218.005
Mshta
GroupAPT29

APT29 has use `mshta` to execute malicious scripts on a compromised host.

T1218.005
Mshta
GroupTA551

TA551 has used mshta.exe to execute malicious payloads.

T1218.005
Mshta
GroupLazyScripter

LazyScripter has used `mshta.exe` to execute Koadic stagers.

T1218.005
Mshta
GroupLazarus Group

Lazarus Group has used mshta.exe to execute HTML pages downloaded by initial access documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.