Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.001 Credentials In Files |
GroupTA505 | TA505 has used malware to gather credentials from FTP clients and Outlook. |
| T1552.001 Credentials In Files |
GroupRedCurl | |
| T1552.001 Credentials In Files |
GroupEmber Bear | Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials. |
| T1552.001 Credentials In Files |
GroupFox Kitten | Fox Kitten has accessed files to gain valid credentials. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.001 Credentials In Files |
GroupFIN13 | FIN13 has obtained administrative credentials by browsing through local files on a compromised machine. |
| T1552.001 Credentials In Files |
GroupShinyHunters | ShinyHunters has gathered PII from database infrastructure. |
| T1552.002 Credentials in Registry |
GroupAPT32 | APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry. |
| T1552.002 Credentials in Registry |
GroupRedCurl | |
| T1552.002 Credentials in Registry |
GroupVOID MANTICORE | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM. |
| T1552.004 Private Keys |
GroupKimsuky | Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`. |
| T1552.004 Private Keys |
GroupVolt Typhoon | Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser. |
| T1552.004 Private Keys |
GroupTeamTNT | TeamTNT has searched for unsecured SSH keys. |
| T1552.004 Private Keys |
GroupRocke | Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network. |
| T1552.004 Private Keys |
GroupScattered Spider | Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host. |
| T1552.004 Private Keys |
GroupStorm-0501 | Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation. |
| T1552.004 Private Keys |
GroupTeamPCP | TeamPCP has used malware to extract SSH and GPG keys from victim environments. |
| T1552.005 Cloud Instance Metadata API |
GroupTeamTNT | TeamTNT has queried the AWS instance metadata service for credentials. |
| T1552.006 Group Policy Preferences |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy. |
| T1552.006 Group Policy Preferences |
GroupAPT33 | APT33 has used a variety of publicly available tools like Gpppassword to gather credentials. |
| T1552.008 Chat Messages |
GroupLAPSUS$ | LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement. |
| T1553 Subvert Trust Controls |
GroupAxiom | Axiom has used digital certificates to deliver malware. |
| T1553.002 Code Signing |
GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| T1553.002 Code Signing |
GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1553.002 Code Signing |
GroupPatchwork | Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies. |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1553.002 Code Signing |
GroupmenuPass | menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures. |
| T1553.002 Code Signing |
GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| T1553.002 Code Signing |
GroupFIN7 | FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
GroupScattered Spider | Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC. |
| T1553.002 Code Signing |
GroupMoses Staff | Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection. |
| T1553.002 Code Signing |
GroupOilRig | OilRig has signed its malware with stolen certificates. |
| T1553.002 Code Signing |
GroupSuckfly | Suckfly has used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupSaint Bear | Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1553.002 Code Signing |
GroupMirrorFace | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed. |
| T1553.002 Code Signing |
GroupMedusa Group | Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| T1553.002 Code Signing |
GroupLuminousMoth | LuminousMoth has signed their malware with a valid digital signature. |
| T1553.002 Code Signing |
GroupWinnti Group | Winnti Group used stolen certificates to sign its malware. |
| T1553.002 Code Signing |
GroupLazarus Group | Lazarus Group has digitally signed malware and utilities to evade detection. |
| T1553.002 Code Signing |
GroupSilence | Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot). |
| T1553.002 Code Signing |
GroupCopyKittens | CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| T1553.002 Code Signing |
GroupWizard Spider | Wizard Spider has used Digicert code-signing certificates for some of its malware. |
| T1553.002 Code Signing |
GroupMolerats | Molerats has used forged Microsoft code-signing certificates on malware. |
| T1553.002 Code Signing |
GroupPROMETHIUM | PROMETHIUM has signed code with self-signed certificates. |
| T1553.002 Code Signing |
GroupDaggerfly | Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| T1553.002 Code Signing |
GroupTeamPCP | TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.