Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.005 Cloud Instance Metadata API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API. |
| T1552.006 Group Policy Preferences |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy. |
| T1552.006 Group Policy Preferences |
GroupAPT33 | APT33 has used a variety of publicly available tools like Gpppassword to gather credentials. |
| T1552.006 Group Policy Preferences |
MalwareMirrorStealer | MirrorStealer can target Group Policy Preferences for credentials. |
| T1552.006 Group Policy Preferences |
ToolSILENTTRINITY | SILENTTRINITY has a module that can extract cached GPP passwords. |
| T1552.006 Group Policy Preferences |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences. |
| T1552.007 Container API |
ToolPeirates | Peirates can query the Kubernetes API for secrets. |
| T1552.007 Container API |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can query the Kubernetes API for credentials. |
| T1552.007 Container API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators. |
| T1552.008 Chat Messages |
GroupLAPSUS$ | LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement. |
| T1553 Subvert Trust Controls |
GroupAxiom | Axiom has used digital certificates to deliver malware. |
| T1553 Subvert Trust Controls |
MalwareShai-Hulud | Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0. |
| T1553.001 Gatekeeper Bypass |
MalwareCuckoo Stealer | Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute. |
| T1553.001 Gatekeeper Bypass |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses the command |
| T1553.001 Gatekeeper Bypass |
MalwareMacMa | MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`. |
| T1553.001 Gatekeeper Bypass |
MalwareCoinTicker | CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag. |
| T1553.001 Gatekeeper Bypass |
MalwareXCSSET | XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13). |
| T1553.001 Gatekeeper Bypass |
MalwareOSX/Shlayer | If running with elevated privileges, OSX/Shlayer has used the |
| T1553.002 Code Signing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection. |
| T1553.002 Code Signing |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations. |
| T1553.002 Code Signing |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature. |
| T1553.002 Code Signing |
Campaign3CX Supply Chain Attack | Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate. |
| T1553.002 Code Signing |
CampaignC0015 | For C0015, the threat actors used DLL files that had invalid certificates. |
| T1553.002 Code Signing |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle. |
| T1553.002 Code Signing |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT. |
| T1553.002 Code Signing |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| T1553.002 Code Signing |
GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| T1553.002 Code Signing |
GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1553.002 Code Signing |
GroupPatchwork | Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies. |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1553.002 Code Signing |
GroupmenuPass | menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures. |
| T1553.002 Code Signing |
GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| T1553.002 Code Signing |
GroupFIN7 | FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
GroupScattered Spider | Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC. |
| T1553.002 Code Signing |
GroupMoses Staff | Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection. |
| T1553.002 Code Signing |
GroupOilRig | OilRig has signed its malware with stolen certificates. |
| T1553.002 Code Signing |
GroupSuckfly | Suckfly has used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupSaint Bear | Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1553.002 Code Signing |
GroupMirrorFace | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed. |
| T1553.002 Code Signing |
GroupMedusa Group | Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| T1553.002 Code Signing |
GroupLuminousMoth | LuminousMoth has signed their malware with a valid digital signature. |
| T1553.002 Code Signing |
GroupWinnti Group | Winnti Group used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupLazarus Group | Lazarus Group has digitally signed malware and utilities to evade detection. |
| T1553.002 Code Signing |
GroupSilence | Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot). |
| T1553.002 Code Signing |
GroupCopyKittens | CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| T1553.002 Code Signing |
GroupWizard Spider | Wizard Spider has used Digicert code-signing certificates for some of its malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.