ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareXORIndex Loader

XORIndex Loader has collected the username from the victim host.

T1033
System Owner/User Discovery
MalwareSmall Sieve

Small Sieve can obtain the id of a logged in user.

T1033
System Owner/User Discovery
ToolBloodHound

BloodHound can collect information on user sessions.

T1033
System Owner/User Discovery
ToolSILENTTRINITY

SILENTTRINITY can gather a list of logged on users.

T1033
System Owner/User Discovery
ToolEmpire

Empire can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolAsyncRAT

AsyncRAT can check if the current user of a compromised system is an administrator.

T1033
System Owner/User Discovery
ToolRemcos

Remcos can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolNBTscan

NBTscan can list active users on the system.

T1033
System Owner/User Discovery
ToolKoadic

Koadic can identify logged in users across the domain and views user sessions.

T1033
System Owner/User Discovery
ToolPupy

Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts.

T1033
System Owner/User Discovery
ToolQuasarRAT

QuasarRAT can enumerate the username and account type.

T1033
System Owner/User Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user.

T1033
System Owner/User Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner.

T1033
System Owner/User Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

T1036
Masquerading
MalwareTrickBot

The TrickBot downloader has used an icon to appear as a Microsoft Word document.

T1036
Masquerading
MalwareRCSession

RCSession has used a file named English.rtf to appear benign on victim hosts.

T1036
Masquerading
MalwareWindTail

WindTail has used icons mimicking MS Office files to mask payloads.

T1036
Masquerading
MalwarePony

Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy.

T1036
Masquerading
MalwareUPSTYLE

UPSTYLE has masqueraded filenames using examples such as `update.py`.

T1036
Masquerading
MalwareAppleSeed

AppleSeed can disguise JavaScript files as PDFs.

T1036
Masquerading
MalwareEnvyScout

EnvyScout has used folder icons for malicious files to lure victims into opening them.

T1036
Masquerading
MalwareDynoWiper

DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe.

T1036
Masquerading
MalwareDacls

The Dacls Mach-O binary has been disguised as a .nib file.

T1036
Masquerading
MalwareSombRAT

SombRAT can use a legitimate process name to hide itself.

T1036
Masquerading
MalwareWhisperGate

WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file.

T1036
Masquerading
MalwareRaindrop

Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code.

T1036
Masquerading
MalwareNotPetya

NotPetya drops PsExec with the filename dllhost.dat.

T1036
Masquerading
MalwareFlagpro

Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution.

T1036
Masquerading
MalwareDarkTortilla

DarkTortilla's payload has been renamed `PowerShellInfo.exe`.

T1036
Masquerading
MalwareBeaverTail

BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes.

T1036
Masquerading
MalwareDarkWatchman

DarkWatchman has used an icon mimicking a text file to mask a malicious executable.

T1036
Masquerading
MalwareBisonal

Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script.

T1036
Masquerading
MalwareDarkGate

DarkGate can masquerade as pirated media content for initial delivery to victims.

T1036
Masquerading
MalwareFoggyWeb

FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file.

T1036
Masquerading
MalwareSaint Bot

Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection.

T1036
Masquerading
MalwareGlassWorm

GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects.

T1036
Masquerading
MalwareRedLine Stealer

RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains.

T1036
Masquerading
MalwareRTM

RTM has been delivered as archived Windows executable files masquerading as PDF documents.

T1036
Masquerading
MalwareStrelaStealer

StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`.

T1036
Masquerading
MalwareRyuk

Ryuk can create .dll files that actually contain a Rich Text File format document.

T1036
Masquerading
MalwareMilan

Milan has used an executable named `companycatalogue` to appear benign.

T1036
Masquerading
MalwareNativeZone

NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system.

T1036
Masquerading
MalwareRamsay

Ramsay has masqueraded as a JPG image file.

T1036
Masquerading
MalwareTrailBlazer

TrailBlazer has used filenames that match the name of the compromised system in attempt to avoid detection.

T1036
Masquerading
MalwarePowGoop

PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat).

T1036
Masquerading
MalwareBoomBox

BoomBox has the ability to mask malicious data strings as PDF files.

T1036
Masquerading
MalwareXCSSET

XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata.

T1036.001
Invalid Code Signature
MalwareWindTail

WindTail has been incompletely signed with revoked certificates.

T1036.001
Invalid Code Signature
MalwareNETWIRE

The NETWIRE client has been signed by fake and invalid digital certificates.

T1036.001
Invalid Code Signature
MalwareRegin

Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.