Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareRover | Rover copies files from removable drives to |
| T1074.001 Local Data Staging |
MalwareLightNeuron | LightNeuron can store email data in files and directories specified in its configuration, such as |
| T1074.001 Local Data Staging |
MalwareElise | Elise creates a file in |
| T1074.001 Local Data Staging |
MalwareLODEINFO | LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder. |
| T1074.001 Local Data Staging |
MalwareSagerunex | Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1074.001 Local Data Staging |
MalwareLP-Notes | LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`. |
| T1074.001 Local Data Staging |
MalwareGlassWorm | GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`. |
| T1074.001 Local Data Staging |
MalwareTrojan.Karagany | Trojan.Karagany can create directories to store plugin output and stage data for exfiltration. |
| T1074.001 Local Data Staging |
MalwareSPACESHIP | SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile. |
| T1074.001 Local Data Staging |
MalwareKGH_SPY | KGH_SPY can save collected system information to a file named "info" before exfiltration. |
| T1074.001 Local Data Staging |
MalwareCatchamas | Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations. |
| T1074.001 Local Data Staging |
MalwareOopsIE | OopsIE stages the output from command execution and collected files in specific folders before exfiltration. |
| T1074.001 Local Data Staging |
MalwareAttor | Attor has staged collected data in a central upload directory prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareBoxCaon | BoxCaon has created a working folder for collected files that it sends to the C2 server. |
| T1074.001 Local Data Staging |
MalwareNightClub | NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts. |
| T1074.001 Local Data Staging |
MalwareCrutch | Crutch has staged stolen files in the |
| T1074.001 Local Data Staging |
MalwareRawPOS | Data captured by RawPOS is placed in a temporary file under a directory named "memdump". |
| T1074.001 Local Data Staging |
MalwareBadPatch | BadPatch stores collected data in log files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareMESSAGETAP | MESSAGETAP stored targeted SMS messages that matched its target list in CSV files on the compromised system. |
| T1074.001 Local Data Staging |
MalwareSUGARDUMP | SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`. |
| T1074.001 Local Data Staging |
MalwareMoonWind | MoonWind saves information from its keylogging routine as a .zip file in the present working directory. |
| T1074.001 Local Data Staging |
MalwareCorKLOG | CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key. |
| T1074.001 Local Data Staging |
Malwareccf32 | ccf32 can temporarily store files in a hidden directory on the local host. |
| T1074.001 Local Data Staging |
MalwareZebrocy | Zebrocy stores all collected information in a single file before exfiltration. |
| T1074.001 Local Data Staging |
MalwareLunarMail | LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration. |
| T1074.001 Local Data Staging |
MalwareSampleCheck5000 | SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMilan | Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`. |
| T1074.001 Local Data Staging |
MalwareUSBStealer | USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration. |
| T1074.001 Local Data Staging |
MalwareOilBooster | OilBooster can stage files in the `tempFiles` directory for exfiltration. |
| T1074.001 Local Data Staging |
MalwarePoisonIvy | PoisonIvy stages collected data in a text file. |
| T1074.001 Local Data Staging |
MalwareCarbon | Carbon creates a base directory that contains the files and folders that are collected. |
| T1074.001 Local Data Staging |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1074.001 Local Data Staging |
MalwareGold Dragon | Gold Dragon stores information gathered from the endpoint in a file named 1.hwp. |
| T1074.001 Local Data Staging |
MalwareRamsay | Ramsay can stage data prior to exfiltration in |
| T1074.001 Local Data Staging |
MalwareMacMa | MacMa has stored collected files locally before exfiltration. |
| T1074.001 Local Data Staging |
MalwareFunnyDream | FunnyDream can stage collected information including screen captures and logged keystrokes locally. |
| T1074.001 Local Data Staging |
MalwarePUNCHTRACK | PUNCHTRACK aggregates collected data in a tmp file. |
| T1074.001 Local Data Staging |
MalwareLAMEHUG | LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration. |
| T1074.001 Local Data Staging |
MalwareRIFLESPINE | RIFLESPINE can stage the output from executed C2 commands to a temporary file. |
| T1074.001 Local Data Staging |
MalwareSLIGHTPULSE | SLIGHTPULSE has piped the output from executed commands to `/tmp/1`. |
| T1074.001 Local Data Staging |
MalwareTroll Stealer | Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure. |
| T1074.001 Local Data Staging |
MalwaremetaMain | metaMain has stored the collected system files in a working directory. |
| T1074.001 Local Data Staging |
MalwareMis-Type | Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`. |
| T1074.001 Local Data Staging |
MalwareOctopus | Octopus has stored collected information in the Application Data directory on a compromised host. |
| T1074.001 Local Data Staging |
MalwareSTARWHALE | STARWHALE has stored collected data in a file called `stari.txt`. |
| T1074.001 Local Data Staging |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON has stored keystrokes and screenshots within the |
| T1074.001 Local Data Staging |
MalwareBADNEWS | BADNEWS copies documents under 15MB found on the victim system to is the user's |
| T1074.001 Local Data Staging |
MalwareDRYHOOK | DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`. |
| T1074.001 Local Data Staging |
MalwareAstaroth | Astaroth collects data in a plaintext file named r1.log before exfiltration. |
| T1074.001 Local Data Staging |
MalwareQakBot | QakBot has stored stolen emails and other data into new folders prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.