Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1614.001 System Language Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so. |
| T1614.001 System Language Discovery |
MalwareREvil | REvil can check the system language using |
| T1614.001 System Language Discovery |
MalwareGrimAgent | GrimAgent has used |
| T1614.001 System Language Discovery |
MalwareClop | Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the |
| T1614.001 System Language Discovery |
MalwareStealBit | StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries. |
| T1614.001 System Language Discovery |
MalwareMaze | Maze has checked the language of the machine with function |
| T1614.001 System Language Discovery |
MalwareXCSSET | XCSSET uses AppleScript to check the host's language and location with the command |
| T1614.001 System Language Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language. |
| T1614.001 System Language Discovery |
MalwareCanisterWorm | CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component. |
| T1615 Group Policy Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed extensive Active Directory enumeration of victim environments during Leviathan Australian Intrusions. |
| T1615 Group Policy Discovery |
GroupTurla | Turla surveys a system upon check-in to discover Group Policy details using the |
| T1615 Group Policy Discovery |
MalwareEmissary | Emissary has the capability to execute |
| T1615 Group Policy Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify victim environment Group Policy information. |
| T1615 Group Policy Discovery |
MalwareLunarWeb | LunarWeb can capture information on group policy settings |
| T1615 Group Policy Discovery |
ToolBloodHound | BloodHound has the ability to collect local admin information via GPO. |
| T1615 Group Policy Discovery |
ToolEmpire | Empire includes various modules for enumerating Group Policy. |
| T1619 Cloud Storage Object Discovery |
ToolPacu | Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes. |
| T1619 Cloud Storage Object Discovery |
ToolTruffleHog | TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets. |
| T1619 Cloud Storage Object Discovery |
ToolPeirates | Peirates can list AWS S3 buckets. |
| T1619 Cloud Storage Object Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects. |
| T1620 Reflective Code Loading |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
| T1620 Reflective Code Loading |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory. |
| T1620 Reflective Code Loading |
GroupKimsuky | Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`. |
| T1620 Reflective Code Loading |
GroupGamaredon Group | Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2. |
| T1620 Reflective Code Loading |
GroupFIN7 | FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`. |
| T1620 Reflective Code Loading |
GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
| T1620 Reflective Code Loading |
MalwarePikabot | Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine. |
| T1620 Reflective Code Loading |
MalwareSardonic | Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions. |
| T1620 Reflective Code Loading |
MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
| T1620 Reflective Code Loading |
MalwareBADHATCH | BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`. |
| T1620 Reflective Code Loading |
MalwareSystemBC | SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call. |
| T1620 Reflective Code Loading |
MalwareWhisperGate | WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly. |
| T1620 Reflective Code Loading |
MalwareLunarLoader | LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
| T1620 Reflective Code Loading |
MalwareLumma Stealer | Lumma Stealer has used reflective loading techniques to load content into memory during execution. |
| T1620 Reflective Code Loading |
MalwareCuba | Cuba loaded the payload into memory using PowerShell. |
| T1620 Reflective Code Loading |
MalwareThiefQuest | ThiefQuest uses various API functions such as |
| T1620 Reflective Code Loading |
MalwareFoggyWeb | FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory. |
| T1620 Reflective Code Loading |
MalwareMuddyViper | MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread. |
| T1620 Reflective Code Loading |
MalwareFooder | Fooder has reflectively loaded a payload into memory. |
| T1620 Reflective Code Loading |
MalwareUroburos | Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command. |
| T1620 Reflective Code Loading |
MalwareCobalt Strike | Cobalt Strike's |
| T1620 Reflective Code Loading |
MalwareLokibot | Lokibot has reflectively loaded the decoded DLL into memory. |
| T1620 Reflective Code Loading |
MalwareIceApple | IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers. |
| T1620 Reflective Code Loading |
MalwaremetaMain | metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file. |
| T1620 Reflective Code Loading |
MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| T1620 Reflective Code Loading |
MalwareGelsemium | Gelsemium can use custom shellcode to map embedded DLLs into memory. |
| T1620 Reflective Code Loading |
MalwareLizar | Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory. |
| T1620 Reflective Code Loading |
ToolSILENTTRINITY | SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR. |
| T1620 Reflective Code Loading |
ToolPowerSploit | PowerSploit reflectively loads a Windows PE file into a process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.