ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
MalwareRover

Rover copies files from removable drives to C:\system.

T1074.001
Local Data Staging
MalwareLightNeuron

LightNeuron can store email data in files and directories specified in its configuration, such as C:\Windows\ServiceProfiles\NetworkService\appdata\Local\Temp\.

T1074.001
Local Data Staging
MalwareElise

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.

T1074.001
Local Data Staging
MalwareLODEINFO

LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder.

T1074.001
Local Data Staging
MalwareSagerunex

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1074.001
Local Data Staging
MalwareLP-Notes

LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`.

T1074.001
Local Data Staging
MalwareGlassWorm

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1074.001
Local Data Staging
MalwareTrojan.Karagany

Trojan.Karagany can create directories to store plugin output and stage data for exfiltration.

T1074.001
Local Data Staging
MalwareSPACESHIP

SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.

T1074.001
Local Data Staging
MalwareKGH_SPY

KGH_SPY can save collected system information to a file named "info" before exfiltration.

T1074.001
Local Data Staging
MalwareCatchamas

Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations.

T1074.001
Local Data Staging
MalwareOopsIE

OopsIE stages the output from command execution and collected files in specific folders before exfiltration.

T1074.001
Local Data Staging
MalwareAttor

Attor has staged collected data in a central upload directory prior to exfiltration.

T1074.001
Local Data Staging
MalwareBoxCaon

BoxCaon has created a working folder for collected files that it sends to the C2 server.

T1074.001
Local Data Staging
MalwareNightClub

NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts.

T1074.001
Local Data Staging
MalwareCrutch

Crutch has staged stolen files in the C:\AMD\Temp directory.

T1074.001
Local Data Staging
MalwareRawPOS

Data captured by RawPOS is placed in a temporary file under a directory named "memdump".

T1074.001
Local Data Staging
MalwareBadPatch

BadPatch stores collected data in log files before exfiltration.

T1074.001
Local Data Staging
MalwareMESSAGETAP

MESSAGETAP stored targeted SMS messages that matched its target list in CSV files on the compromised system.

T1074.001
Local Data Staging
MalwareSUGARDUMP

SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`.

T1074.001
Local Data Staging
MalwareMoonWind

MoonWind saves information from its keylogging routine as a .zip file in the present working directory.

T1074.001
Local Data Staging
MalwareCorKLOG

CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key.

T1074.001
Local Data Staging
Malwareccf32

ccf32 can temporarily store files in a hidden directory on the local host.

T1074.001
Local Data Staging
MalwareZebrocy

Zebrocy stores all collected information in a single file before exfiltration.

T1074.001
Local Data Staging
MalwareLunarMail

LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration.

T1074.001
Local Data Staging
MalwareSampleCheck5000

SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration.

T1074.001
Local Data Staging
MalwareMilan

Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`.

T1074.001
Local Data Staging
MalwareUSBStealer

USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration.

T1074.001
Local Data Staging
MalwareOilBooster

OilBooster can stage files in the `tempFiles` directory for exfiltration.

T1074.001
Local Data Staging
MalwarePoisonIvy

PoisonIvy stages collected data in a text file.

T1074.001
Local Data Staging
MalwareCarbon

Carbon creates a base directory that contains the files and folders that are collected.

T1074.001
Local Data Staging
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1074.001
Local Data Staging
MalwareGold Dragon

Gold Dragon stores information gathered from the endpoint in a file named 1.hwp.

T1074.001
Local Data Staging
MalwareRamsay

Ramsay can stage data prior to exfiltration in %APPDATA%\Microsoft\UserSetting and %APPDATA%\Microsoft\UserSetting\MediaCache.

T1074.001
Local Data Staging
MalwareMacMa

MacMa has stored collected files locally before exfiltration.

T1074.001
Local Data Staging
MalwareFunnyDream

FunnyDream can stage collected information including screen captures and logged keystrokes locally.

T1074.001
Local Data Staging
MalwarePUNCHTRACK

PUNCHTRACK aggregates collected data in a tmp file.

T1074.001
Local Data Staging
MalwareLAMEHUG

LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration.

T1074.001
Local Data Staging
MalwareRIFLESPINE

RIFLESPINE can stage the output from executed C2 commands to a temporary file.

T1074.001
Local Data Staging
MalwareSLIGHTPULSE

SLIGHTPULSE has piped the output from executed commands to `/tmp/1`.

T1074.001
Local Data Staging
MalwareTroll Stealer

Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure.

T1074.001
Local Data Staging
MalwaremetaMain

metaMain has stored the collected system files in a working directory.

T1074.001
Local Data Staging
MalwareMis-Type

Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`.

T1074.001
Local Data Staging
MalwareOctopus

Octopus has stored collected information in the Application Data directory on a compromised host.

T1074.001
Local Data Staging
MalwareSTARWHALE

STARWHALE has stored collected data in a file called `stari.txt`.

T1074.001
Local Data Staging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has stored keystrokes and screenshots within the %temp%\GoogleChrome, %temp%\Downloads, and %temp%\TrendMicroUpdate directories.

T1074.001
Local Data Staging
MalwareBADNEWS

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.

T1074.001
Local Data Staging
MalwareDRYHOOK

DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`.

T1074.001
Local Data Staging
MalwareAstaroth

Astaroth collects data in a plaintext file named r1.log before exfiltration.

T1074.001
Local Data Staging
MalwareQakBot

QakBot has stored stolen emails and other data into new folders prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.