Real-world descriptions of how a group, tool or campaign used a technique.
196 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareT9000 | T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM. |
| T1033 System Owner/User Discovery |
MalwareDnsSystem | DnsSystem can use the Windows user name to create a unique identification for infected users and systems. |
| T1033 System Owner/User Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareIxeshe | Ixeshe collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareMicropsia | Micropsia collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareRedLine Stealer | RedLine Stealer has obtained the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareRogueRobin | RogueRobin collects the victim’s username and whether that user is an admin. |
| T1033 System Owner/User Discovery |
MalwareLitePower | LitePower can determine if the current user has admin privileges. |
| T1033 System Owner/User Discovery |
MalwareSDBbot | SDBbot has the ability to identify the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMosquito | Mosquito runs |
| T1033 System Owner/User Discovery |
MalwareRTM | RTM can obtain the victim username and permissions. |
| T1033 System Owner/User Discovery |
MalwareDerusbi | A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareSodaMaster | SodaMaster can identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareGrandoreiro | Grandoreiro can collect the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareWellMail | WellMail can identify the current username on the victim system. |
| T1033 System Owner/User Discovery |
MalwareLiteDuke | LiteDuke can enumerate the account name on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareZxxZ | ZxxZ can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim user name. |
| T1033 System Owner/User Discovery |
MalwareBazar | Bazar can identify the username of the infected user. |
| T1033 System Owner/User Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1033 System Owner/User Discovery |
MalwareXLoader | XLoader can identify the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareMoonWind | MoonWind obtains the victim username. |
| T1033 System Owner/User Discovery |
MalwareHiddenFace | HiddenFace can collect the username associated with the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCryptoistic | Cryptoistic can gather data on the user of a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMgBot | MgBot includes modules for identifying local users and administrators on victim machines. |
| T1033 System Owner/User Discovery |
MalwareZebrocy | Zebrocy gets the username from the system. |
| T1033 System Owner/User Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareHotCroissant | HotCroissant has the ability to collect the username on the infected host. |
| T1033 System Owner/User Discovery |
MalwareServHelper | ServHelper will attempt to enumerate the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim usernames. |
| T1033 System Owner/User Discovery |
MalwareValak | Valak can gather information regarding the user. |
| T1033 System Owner/User Discovery |
MalwareMilan | Milan can identify users registered to a targeted machine. |
| T1033 System Owner/User Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's username which is then used as part of a unique identifier. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1033 System Owner/User Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareBISCUIT | BISCUIT has a command to gather the username from the system. |
| T1033 System Owner/User Discovery |
MalwareGold Dragon | Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server. |
| T1033 System Owner/User Discovery |
MalwareRGDoor | RGDoor executes the |
| T1033 System Owner/User Discovery |
MalwareRevenge RAT | Revenge RAT gathers the username from the system. |
| T1033 System Owner/User Discovery |
MalwareMacMa | MacMa can collect the username from the compromised machine. |
| T1033 System Owner/User Discovery |
MalwareFunnyDream | FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1033 System Owner/User Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSysUpdate | SysUpdate can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKwampirs | Kwampirs collects registered owner details by using the commands |
| T1033 System Owner/User Discovery |
MalwareBoomBox | BoomBox can enumerate the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareLAMEHUG | LAMEHUG can use `whoami` to enumerate the system user. |
| T1033 System Owner/User Discovery |
MalwareMango | Mango can collect the user name from a compromised system which is used to create a unique victim identifier. |
| T1033 System Owner/User Discovery |
MalwareGrimAgent | GrimAgent can identify the user id on a target machine. |
| T1033 System Owner/User Discovery |
MalwareLokibot | Lokibot has the ability to discover the username on the infected host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.