Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT39 | APT39 has used malware to decrypt encrypted CAB files. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1140 Deobfuscate/Decode Files or Information |
GroupHigaisa | Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTropic Trooper | Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKe3chang | Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLeviathan | Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWinter Vivern | Winter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTurla | Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTA505 | TA505 has decrypted packed DLLs with an XOR key. |
| T1140 Deobfuscate/Decode Files or Information |
GroupCinnamon Tempest | Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBRONZE BUTLER | BRONZE BUTLER downloads encoded payloads and decodes them on the victim. |
| T1140 Deobfuscate/Decode Files or Information |
GroupDarkhotel | Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAgrius | Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT28 | An APT28 macro uses the command |
| T1140 Deobfuscate/Decode Files or Information |
GroupMalteiro | Malteiro has the ability to deobfuscate downloaded files prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLazarus Group | Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
GroupEarth Lusca | Earth Lusca has used certutil to decode a string into a cabinet file. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMolerats | Molerats decompresses ZIP files once on the victim machine. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWIRTE | WIRTE has used Base64 to decode malicious VBS script. |
| T1140 Deobfuscate/Decode Files or Information |
GroupThreat Group-3390 | During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression. |
| T1140 Deobfuscate/Decode Files or Information |
GroupFIN13 | FIN13 has utilized `certutil` to decode base64 encoded versions of custom malware. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT19 | An APT19 HTTP malware variant decrypts strings using single-byte XOR keys. |
| T1176.001 Browser Extensions |
GroupKimsuky | Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies. |
| T1176.002 IDE Extensions |
GroupMustang Panda | Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads. |
| T1176.002 IDE Extensions |
GroupTeamPCP | TeamPCP has compromised VS Code and Open VSX IDE extensions. |
| T1185 Browser Session Hijacking |
GroupKimsuky | Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. |
| T1187 Forced Authentication |
GroupDragonfly | Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems. |
| T1187 Forced Authentication |
GroupDarkHydrus | DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials. |
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1189 Drive-by Compromise |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1189 Drive-by Compromise |
GroupPatchwork | Patchwork has used watering holes to deliver files with exploits to initial victims. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1189 Drive-by Compromise |
GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| T1189 Drive-by Compromise |
GroupLeafminer | Leafminer has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupMachete | Machete has distributed Machete through a fake blog website. |
| T1189 Drive-by Compromise |
GroupAndariel | Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range. |
| T1189 Drive-by Compromise |
GroupCURIUM | CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. |
| T1189 Drive-by Compromise |
GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| T1189 Drive-by Compromise |
GroupWindigo | Windigo has distributed Windows malware via drive-by downloads. |
| T1189 Drive-by Compromise |
GroupLeviathan | Leviathan has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupWinter Vivern | Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software. |
| T1189 Drive-by Compromise |
GroupTurla | Turla has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupDark Caracal | Dark Caracal leveraged a watering hole to serve up malicious code. |
| T1189 Drive-by Compromise |
GroupBRONZE BUTLER | BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks. |
| T1189 Drive-by Compromise |
GroupDarkhotel | Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1189 Drive-by Compromise |
GroupAxiom | Axiom has used watering hole attacks to gain access. |
| T1189 Drive-by Compromise |
GroupWindshift | Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1189 Drive-by Compromise |
GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.