Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1539 Steal Web Session Cookie |
MalwareDarkGate | DarkGate attempts to steal Opera cookies, if present, after terminating the related process. |
| T1539 Steal Web Session Cookie |
MalwareChaes | Chaes has used a script that extracts the web session cookie and sends it to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareLODEINFO | LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies. |
| T1539 Steal Web Session Cookie |
MalwareEVILNUM | EVILNUM can harvest cookies and upload them to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareGlassWorm | GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers. |
| T1539 Steal Web Session Cookie |
MalwareSpica | Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers. |
| T1539 Steal Web Session Cookie |
MalwareBLUELIGHT | BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1539 Steal Web Session Cookie |
MalwareGrandoreiro | Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device. |
| T1539 Steal Web Session Cookie |
MalwareXLoader | XLoader can capture web session cookies and session information from victim browsers. |
| T1539 Steal Web Session Cookie |
MalwareMgBot | MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers. |
| T1539 Steal Web Session Cookie |
MalwareTajMahal | TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications. |
| T1539 Steal Web Session Cookie |
MalwareRaccoon Stealer | Raccoon Stealer attempts to steal cookies and related information in browser history. |
| T1539 Steal Web Session Cookie |
MalwareXCSSET | XCSSET uses |
| T1539 Steal Web Session Cookie |
MalwareQakBot | QakBot has the ability to capture web session cookies. |
| T1539 Steal Web Session Cookie |
MalwareCookieMiner | CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine. |
| T1539 Steal Web Session Cookie |
Toolevilginx2 | evilginx2 can collect information on each session with a victim including the session cookie. |
| T1539 Steal Web Session Cookie |
MalwareKali365 | Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services. |
| T1542.001 System Firmware |
MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| T1542.001 System Firmware |
MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| T1542.001 System Firmware |
MalwareTrojan.Mebromi | Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal. |
| T1542.002 Component Firmware |
GroupEquation | Equation is known to have the capability to overwrite the firmware on hard drives from some manufacturers. |
| T1542.002 Component Firmware |
MalwareCyclops Blink | Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices. |
| T1542.003 Bootkit |
GroupAPT41 | APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems. |
| T1542.003 Bootkit |
GroupAPT28 | APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy. |
| T1542.003 Bootkit |
GroupLazarus Group | Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down. |
| T1542.003 Bootkit |
MalwareTrickBot | TrickBot can implant malicious code into a compromised device's firmware. |
| T1542.003 Bootkit |
MalwareWhisperGate | WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots. |
| T1542.003 Bootkit |
MalwareFinFisher | Some FinFisher variants incorporate an MBR rootkit. |
| T1542.003 Bootkit |
MalwareCarberp | Carberp has installed a bootkit on the system to maintain persistence. |
| T1542.003 Bootkit |
MalwareROCKBOOT | ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence. |
| T1542.003 Bootkit |
MalwareBOOTRASH | BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence. |
| T1543 Create or Modify System Process |
MalwareBRICKSTORM | BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state. |
| T1543 Create or Modify System Process |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root. |
| T1543 Create or Modify System Process |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background. |
| T1543 Create or Modify System Process |
MalwareIMAPLoader | IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification. |
| T1543 Create or Modify System Process |
MalwareBOLDMOVE | BOLDMOVE can free all resources and terminate itself on victim machines. |
| T1543 Create or Modify System Process |
MalwareAkira _v2 | Akira _v2 can create a child process for encryption. |
| T1543 Create or Modify System Process |
MalwareLunarMail | LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory. |
| T1543 Create or Modify System Process |
MalwareCanisterWorm | CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens. |
| T1543.001 Launch Agent |
GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist. |
| T1543.001 Launch Agent |
MalwareInvisibleFerret | InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”. |
| T1543.001 Launch Agent |
MalwaremacOS.OSAMiner | macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder. |
| T1543.001 Launch Agent |
MalwareNETWIRE | NETWIRE can use launch agents for persistence. |
| T1543.001 Launch Agent |
MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| T1543.001 Launch Agent |
MalwareFruitFly | FruitFly persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareKeydnap | Keydnap uses a Launch Agent to persist. |
| T1543.001 Launch Agent |
MalwareGreen Lambert | Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.