Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1039 Data from Network Shared Drive |
CampaignC0015 | During C0015, the threat actors collected files from network shared drives prior to network encryption. |
| T1039 Data from Network Shared Drive |
GroupmenuPass | menuPass has collected data from remote systems by mounting network shares with |
| T1039 Data from Network Shared Drive |
GroupGamaredon Group | Gamaredon Group malware has collected Microsoft Office documents from mapped network drives. |
| T1039 Data from Network Shared Drive |
GroupRedCurl | RedCurl has collected data about network drives. |
| T1039 Data from Network Shared Drive |
GroupChimera | Chimera has collected data of interest from network shares. |
| T1039 Data from Network Shared Drive |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from file shares. |
| T1039 Data from Network Shared Drive |
GroupAPT28 | APT28 has collected files from network shared drives. |
| T1039 Data from Network Shared Drive |
GroupFox Kitten | Fox Kitten has searched network shares to access sensitive documents. |
| T1039 Data from Network Shared Drive |
GroupSowbug | Sowbug extracted Word documents from a file server on a victim network. |
| T1039 Data from Network Shared Drive |
MalwareCosmicDuke | CosmicDuke steals user files from network shared drives with file extensions and keywords that match a predefined list. |
| T1039 Data from Network Shared Drive |
MalwareRamsay | Ramsay can collect data from network drives and stage it for exfiltration. |
| T1039 Data from Network Shared Drive |
MalwareEgregor | Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel. |
| T1039 Data from Network Shared Drive |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1040 Network Sniffing |
CampaignRedPenguin | During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer. |
| T1040 Network Sniffing |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network between the local LAN and the power grid’s industrial control systems. |
| T1040 Network Sniffing |
CampaignArcaneDoor | ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1040 Network Sniffing |
GroupKimsuky | Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols. |
| T1040 Network Sniffing |
GroupSalt Typhoon | Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces. |
| T1040 Network Sniffing |
GroupSandworm Team | Sandworm Team has used intercepter-NG to sniff passwords in network traffic. |
| T1040 Network Sniffing |
GroupUNC3886 | UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets. |
| T1040 Network Sniffing |
GroupDarkVishnya | DarkVishnya used network sniffing to obtain login data. |
| T1040 Network Sniffing |
GroupAPT28 | APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials. |
| T1040 Network Sniffing |
GroupVelvet Ant | Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices. |
| T1040 Network Sniffing |
GroupAPT33 | APT33 has used SniffPass to collect credentials by sniffing network traffic. |
| T1040 Network Sniffing |
Malwarecd00r | cd00r can use the libpcap library to monitor captured packets for specifc sequences. |
| T1040 Network Sniffing |
MalwareJumbledPath | JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts. |
| T1040 Network Sniffing |
MalwareVersaMem | VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules. |
| T1040 Network Sniffing |
MalwareCASTLETAP | CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic. |
| T1040 Network Sniffing |
MalwareJ-magic | J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports. |
| T1040 Network Sniffing |
MalwareEmotet | Emotet has been observed to hook network APIs to monitor network traffic. |
| T1040 Network Sniffing |
MalwareRegin | Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB. |
| T1040 Network Sniffing |
MalwareLine Dancer | Line Dancer can create and exfiltrate packet captures from compromised environments. |
| T1040 Network Sniffing |
MalwareFoggyWeb | FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor. |
| T1040 Network Sniffing |
MalwareMESSAGETAP | MESSAGETAP uses the libpcap library to listen to all traffic and parses network protocols starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP, and TCAP and finally extracts SMS message data and routing metadata. |
| T1040 Network Sniffing |
MalwarePenquin | Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1040 Network Sniffing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1040 Network Sniffing |
ToolImpacket | Impacket can be used to sniff network traffic via an interface or raw socket. |
| T1040 Network Sniffing |
ToolEmpire | Empire can be used to conduct packet captures on target hosts. |
| T1040 Network Sniffing |
ToolPoshC2 | PoshC2 contains a module for taking packet captures on compromised hosts. |
| T1040 Network Sniffing |
ToolResponder | Responder captures hashes and credentials that are sent to the system after the name services have been poisoned. |
| T1040 Network Sniffing |
ToolNBTscan | NBTscan can dump and print whole packet content. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2. |
| T1041 Exfiltration Over C2 Channel |
CampaignRedPenguin | During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Wocao | During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
CampaignLeviathan Australian Intrusions | Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.