Real-world descriptions of how a group, tool or campaign used a technique.
169 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHiddenFace | HiddenFace can upload files from the victim machine to C2 nodes. |
| T1005 Data from Local System |
MalwareCryptoistic | Cryptoistic can retrieve files from the local file system. |
| T1005 Data from Local System |
MalwareMgBot | MgBot includes modules for collecting files from local systems based on a given set of properties and filenames. |
| T1005 Data from Local System |
Malwareccf32 | ccf32 can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareCobalt Strike | Cobalt Strike can collect data from a local system. |
| T1005 Data from Local System |
MalwareSUNBURST | SUNBURST collected information from a compromised host. |
| T1005 Data from Local System |
MalwareSamurai | Samurai can leverage an exfiltration module to download arbitrary files from compromised machines. |
| T1005 Data from Local System |
MalwarePinchDuke | PinchDuke collects user files from the compromised host based on predefined file extensions. |
| T1005 Data from Local System |
MalwareMilan | Milan can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has the ability to upload files from a compromised host. |
| T1005 Data from Local System |
MalwareTaidoor | Taidoor can upload data and files from a victim's machine. |
| T1005 Data from Local System |
MalwareCyclops Blink | Cyclops Blink can upload files from a compromised host. |
| T1005 Data from Local System |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can steal system information. |
| T1005 Data from Local System |
MalwareTajMahal | TajMahal has the ability to steal documents from the local system including the print spooler queue. |
| T1005 Data from Local System |
MalwareRaccoon Stealer | Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes. |
| T1005 Data from Local System |
MalwareIPsec Helper | IPsec Helper can identify specific files and folders for follow-on exfiltration. |
| T1005 Data from Local System |
MalwareDanBot | DanBot can upload files from compromised hosts. |
| T1005 Data from Local System |
MalwareCalisto | Calisto can collect data from user directories. |
| T1005 Data from Local System |
MalwareRamsay | Ramsay can collect Microsoft Word documents from the target's file system, as well as |
| T1005 Data from Local System |
MalwarePillowmint | Pillowmint has collected credit card data using native API functions. |
| T1005 Data from Local System |
MalwareMacMa | MacMa can collect then exfiltrate files from the compromised system. |
| T1005 Data from Local System |
MalwareFunnyDream | FunnyDream can upload files from victims' machines. |
| T1005 Data from Local System |
MalwareSysUpdate | SysUpdate can collect information and files from a compromised host. |
| T1005 Data from Local System |
MalwareOutSteel | OutSteel can collect information from a compromised host. |
| T1005 Data from Local System |
MalwarePUNCHTRACK | PUNCHTRACK scrapes memory for properly formatted payment card data. |
| T1005 Data from Local System |
MalwareLAMEHUG | LAMEHUG has the ability to collect system information and files of interest from compromised systems. |
| T1005 Data from Local System |
MalwareGrimAgent | GrimAgent can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareStealBit | StealBit can upload data and files to the LockBit victim-shaming site. |
| T1005 Data from Local System |
MalwareZxShell | ZxShell can transfer files from a compromised host. |
| T1005 Data from Local System |
MalwareSLIGHTPULSE | SLIGHTPULSE can read files specified on the local system. |
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1005 Data from Local System |
MalwareTroll Stealer | Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note. |
| T1005 Data from Local System |
MalwarenjRAT | njRAT can collect data from a local system. |
| T1005 Data from Local System |
MalwareIceApple | IceApple can collect files, passwords, and other data from a compromised host. |
| T1005 Data from Local System |
MalwaremetaMain | metaMain can collect files and system information from a compromised host. |
| T1005 Data from Local System |
MalwareSideTwist | SideTwist has the ability to upload files from a compromised host. |
| T1005 Data from Local System |
MalwareMis-Type | Mis-Type has collected files and data from a compromised host. |
| T1005 Data from Local System |
MalwareXCSSET | XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders. |
| T1005 Data from Local System |
MalwareOctopus | Octopus can exfiltrate files from the system using a documents collector tool. |
| T1005 Data from Local System |
MalwareSTARWHALE | STARWHALE can collect data from an infected local host. |
| T1005 Data from Local System |
MalwarePcexter | Pcexter can upload files from targeted systems. |
| T1005 Data from Local System |
MalwareKevin | Kevin can upload logs and other data from a compromised host. |
| T1005 Data from Local System |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve files. |
| T1005 Data from Local System |
MalwarePOWERSTATS | POWERSTATS can upload files from compromised hosts. |
| T1005 Data from Local System |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1005 Data from Local System |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can obtain data from local systems. |
| T1005 Data from Local System |
MalwareGoopy | Goopy has the ability to exfiltrate documents from infected systems. |
| T1005 Data from Local System |
MalwareQakBot | QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated. |
| T1005 Data from Local System |
MalwareCookieMiner | CookieMiner has retrieved iPhone text messages from iTunes phone backup files. |
| T1005 Data from Local System |
MalwareGelsemium | Gelsemium can collect data from a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.