ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1033×

196 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareT9000

T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM.

T1033
System Owner/User Discovery
MalwareDnsSystem

DnsSystem can use the Windows user name to create a unique identification for infected users and systems.

T1033
System Owner/User Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the username on a compromised host.

T1033
System Owner/User Discovery
MalwareIxeshe

Ixeshe collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareMicropsia

Micropsia collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareRedLine Stealer

RedLine Stealer has obtained the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareRogueRobin

RogueRobin collects the victim’s username and whether that user is an admin.

T1033
System Owner/User Discovery
MalwareLitePower

LitePower can determine if the current user has admin privileges.

T1033
System Owner/User Discovery
MalwareSDBbot

SDBbot has the ability to identify the user on a compromised host.

T1033
System Owner/User Discovery
MalwareMosquito

Mosquito runs whoami on the victim’s machine.

T1033
System Owner/User Discovery
MalwareRTM

RTM can obtain the victim username and permissions.

T1033
System Owner/User Discovery
MalwareDerusbi

A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim.

T1033
System Owner/User Discovery
MalwareSodaMaster

SodaMaster can identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareGrandoreiro

Grandoreiro can collect the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareWellMail

WellMail can identify the current username on the victim system.

T1033
System Owner/User Discovery
MalwareLiteDuke

LiteDuke can enumerate the account name on a targeted system.

T1033
System Owner/User Discovery
MalwareZxxZ

ZxxZ can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareWINDSHIELD

WINDSHIELD can gather the victim user name.

T1033
System Owner/User Discovery
MalwareBazar

Bazar can identify the username of the infected user.

T1033
System Owner/User Discovery
MalwareRATANKBA

RATANKBA runs the whoami and query user commands.

T1033
System Owner/User Discovery
MalwareXLoader

XLoader can identify the username from a victim machine.

T1033
System Owner/User Discovery
MalwareMoonWind

MoonWind obtains the victim username.

T1033
System Owner/User Discovery
MalwareHiddenFace

HiddenFace can collect the username associated with the compromised host.

T1033
System Owner/User Discovery
MalwareCryptoistic

Cryptoistic can gather data on the user of a compromised host.

T1033
System Owner/User Discovery
MalwareMgBot

MgBot includes modules for identifying local users and administrators on victim machines.

T1033
System Owner/User Discovery
MalwareZebrocy

Zebrocy gets the username from the system.

T1033
System Owner/User Discovery
MalwareSpeakUp

SpeakUp uses the whoami command.

T1033
System Owner/User Discovery
MalwareSUNBURST

SUNBURST collected the username from a compromised host.

T1033
System Owner/User Discovery
MalwareHotCroissant

HotCroissant has the ability to collect the username on the infected host.

T1033
System Owner/User Discovery
MalwareServHelper

ServHelper will attempt to enumerate the username of the victim.

T1033
System Owner/User Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim usernames.

T1033
System Owner/User Discovery
MalwareValak

Valak can gather information regarding the user.

T1033
System Owner/User Discovery
MalwareMilan

Milan can identify users registered to a targeted machine.

T1033
System Owner/User Discovery
MalwareOilBooster

OilBooster can identify the compromised system's username which is then used as part of a unique identifier.

T1033
System Owner/User Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on the infected system owner and user.

T1033
System Owner/User Discovery
MalwareCardinal RAT

Cardinal RAT can collect the username from a victim machine.

T1033
System Owner/User Discovery
MalwareBISCUIT

BISCUIT has a command to gather the username from the system.

T1033
System Owner/User Discovery
MalwareGold Dragon

Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server.

T1033
System Owner/User Discovery
MalwareRGDoor

RGDoor executes the whoami on the victim’s machine.

T1033
System Owner/User Discovery
MalwareRevenge RAT

Revenge RAT gathers the username from the system.

T1033
System Owner/User Discovery
MalwareMacMa

MacMa can collect the username from the compromised machine.

T1033
System Owner/User Discovery
MalwareFunnyDream

FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`.

T1033
System Owner/User Discovery
MalwareMore_eggs

More_eggs has the capability to gather the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareSysUpdate

SysUpdate can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareKwampirs

Kwampirs collects registered owner details by using the commands systeminfo and net config workstation.

T1033
System Owner/User Discovery
MalwareBoomBox

BoomBox can enumerate the username on a compromised host.

T1033
System Owner/User Discovery
MalwareLAMEHUG

LAMEHUG can use `whoami` to enumerate the system user.

T1033
System Owner/User Discovery
MalwareMango

Mango can collect the user name from a compromised system which is used to create a unique victim identifier.

T1033
System Owner/User Discovery
MalwareGrimAgent

GrimAgent can identify the user id on a target machine.

T1033
System Owner/User Discovery
MalwareLokibot

Lokibot has the ability to discover the username on the infected host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.