Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.016 Junk Code Insertion |
MalwareStrelaStealer | StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1027.016 Junk Code Insertion |
MalwareFinFisher | FinFisher contains junk code in its functions in an effort to confuse disassembly programs. |
| T1027.016 Junk Code Insertion |
MalwareANELLDR | ANELLDR can use junk code for payload obfuscation. |
| T1027.016 Junk Code Insertion |
MalwareMaze | Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1027.016 Junk Code Insertion |
MalwarePOWERSTATS | POWERSTATS has used useless code blocks to counter analysis. |
| T1027.016 Junk Code Insertion |
MalwareGoopy | Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1027.016 Junk Code Insertion |
MalwareGelsemium | Gelsemium can use junk code to hide functions and evade detection. |
| T1027.018 Invisible Unicode |
MalwareGlassWorm | GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors. |
| T1029 Scheduled Transfer |
GroupHigaisa | Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes. |
| T1029 Scheduled Transfer |
MalwareNinja | Ninja can configure its agent to work only in specific time frames. |
| T1029 Scheduled Transfer |
MalwareTinyTurla | TinyTurla contacts its C2 based on a scheduled timing set in its configuration. |
| T1029 Scheduled Transfer |
MalwareMachete | Machete sends stolen data to the C2 server every 10 minutes. |
| T1029 Scheduled Transfer |
MalwareKazuar | Kazuar can sleep for a specific time and be set to communicate at specific intervals. |
| T1029 Scheduled Transfer |
MalwareShimRat | ShimRat can sleep when instructed to do so by the C2. |
| T1029 Scheduled Transfer |
MalwareChrommme | Chrommme can set itself to sleep before requesting a new command from C2. |
| T1029 Scheduled Transfer |
MalwareFlagpro | Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2. |
| T1029 Scheduled Transfer |
MalwareLightNeuron | LightNeuron can be configured to exfiltrate data during nighttime or working hours. |
| T1029 Scheduled Transfer |
MalwareShark | Shark can pause C2 communications for a specified time. |
| T1029 Scheduled Transfer |
MalwareCobalt Strike | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval. |
| T1029 Scheduled Transfer |
MalwareComRAT | ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday). |
| T1029 Scheduled Transfer |
MalwareDipsind | Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic. |
| T1029 Scheduled Transfer |
MalwarePOWERSTATS | POWERSTATS can sleep for a given number of seconds. |
| T1029 Scheduled Transfer |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure. |
| T1029 Scheduled Transfer |
MalwareShadowPad | ShadowPad has sent data back to C2 every 8 hours. |
| T1029 Scheduled Transfer |
MalwarejRAT | jRAT can be configured to reconnect at certain intervals. |
| T1029 Scheduled Transfer |
MalwareADVSTORESHELL | ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
| T1030 Data Transfer Size Limits |
CampaignC0015 | During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration. |
| T1030 Data Transfer Size Limits |
CampaignC0026 | During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration. |
| T1030 Data Transfer Size Limits |
GroupAPT41 | APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection. |
| T1030 Data Transfer Size Limits |
GroupLuminousMoth | LuminousMoth has split archived files into multiple parts to bypass a 5MB limit. |
| T1030 Data Transfer Size Limits |
GroupAPT28 | APT28 has split archived exfiltration files into chunks smaller than 1MB. |
| T1030 Data Transfer Size Limits |
GroupPlay | Play has split victims' files into chunks for exfiltration. |
| T1030 Data Transfer Size Limits |
GroupThreat Group-3390 | Threat Group-3390 actors have split RAR files for exfiltration into parts. |
| T1030 Data Transfer Size Limits |
MalwareAppleSeed | AppleSeed has divided files if the size is 0x1000000 bytes or more. |
| T1030 Data Transfer Size Limits |
MalwareRDAT | RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions. |
| T1030 Data Transfer Size Limits |
MalwareObliqueRAT | ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration. |
| T1030 Data Transfer Size Limits |
MalwarePOSHSPY | POSHSPY uploads data in 2048-byte chunks. |
| T1030 Data Transfer Size Limits |
MalwareCarbanak | Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes . |
| T1030 Data Transfer Size Limits |
MalwareOopsIE | OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks. |
| T1030 Data Transfer Size Limits |
MalwareCobalt Strike | Cobalt Strike will break large data sets into smaller chunks for exfiltration. |
| T1030 Data Transfer Size Limits |
MalwareKessel | Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries. |
| T1030 Data Transfer Size Limits |
MalwareStealBit | StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms. |
| T1030 Data Transfer Size Limits |
MalwareLunarWeb | LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB. |
| T1030 Data Transfer Size Limits |
MalwareKevin | Kevin can exfiltrate data to the C2 server in 27-character chunks. |
| T1030 Data Transfer Size Limits |
MalwareHelminth | Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server. |
| T1030 Data Transfer Size Limits |
ToolRclone | The Rclone "chunker" overlay supports splitting large files in smaller chunks during upload to circumvent size limits. |
| T1030 Data Transfer Size Limits |
ToolMythic | Mythic supports custom chunk sizes used to upload/download files. |
| T1033 System Owner/User Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels. |
| T1033 System Owner/User Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information. |
| T1033 System Owner/User Discovery |
CampaignC0018 | During C0018, the threat actors collected `whoami` information via PowerShell scripts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.