Real-world descriptions of how a group, tool or campaign used a technique.
49 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwarePlugX | PlugX can enumerate and query for information contained within the Windows Registry. |
| T1016 System Network Configuration Discovery |
MalwarePlugX | PlugX has captured victim IP address details of the targeted machine. |
| T1027 Obfuscated Files or Information |
MalwarePlugX | PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027.001 Binary Padding |
MalwarePlugX | PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.007 Dynamic API Resolution |
MalwarePlugX | PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.013 Encrypted/Encoded File |
MalwarePlugX | PlugX has leveraged XOR encryption with the key of 123456789. |
| T1033 System Owner/User Discovery |
MalwarePlugX | PlugX has the ability to gather the username from the victim’s machine. |
| T1036.004 Masquerade Task or Service |
MalwarePlugX | In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility." |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePlugX | PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
| T1041 Exfiltration Over C2 Channel |
MalwarePlugX | PlugX has exfiltrated stolen data and files to its C2 server. |
| T1049 System Network Connections Discovery |
MalwarePlugX | PlugX has a module for enumerating TCP and UDP network connections and associated processes using the |
| T1053.005 Scheduled Task |
MalwarePlugX | PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence. |
| T1056.001 Keylogging |
MalwarePlugX | PlugX has a module for capturing keystrokes per process including window titles. |
| T1057 Process Discovery |
MalwarePlugX | PlugX has a module to list the processes running on a machine. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1070.004 File Deletion |
MalwarePlugX | PlugX has the remove itself and other artifacts. |
| T1070.009 Clear Persistence |
MalwarePlugX | PlugX has deleted registry keys that store data and maintained persistence. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1071.004 DNS |
MalwarePlugX | PlugX can be configured to use DNS for command and control. |
| T1074.001 Local Data Staging |
MalwarePlugX | PlugX has collected and staged the victim’s computer files for exfiltration. |
| T1082 System Information Discovery |
MalwarePlugX | PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1091 Replication Through Removable Media |
MalwarePlugX | PlugX has copied itself to infected removable drives for propagation to other victim devices. |
| T1095 Non-Application Layer Protocol |
MalwarePlugX | PlugX can be configured to use raw TCP or UDP for command and control. |
| T1102.001 Dead Drop Resolver |
MalwarePlugX | PlugX uses Pastebin to store C2 addresses. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
| T1106 Native API |
MalwarePlugX | PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process. |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1113 Screen Capture |
MalwarePlugX | PlugX allows the operator to capture screenshots. |
| T1120 Peripheral Device Discovery |
MalwarePlugX | PlugX can identify removable media attached to compromised hosts. |
| T1124 System Time Discovery |
MalwarePlugX | PlugX has identified system time through its GetSystemInfo command. |
| T1127.001 MSBuild |
MalwarePlugX | A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1204.002 Malicious File |
MalwarePlugX | PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it. |
| T1480.002 Mutual Exclusion |
MalwarePlugX | PlugX has leveraged a mutex in its infection process. |
| T1497.001 System Checks |
MalwarePlugX | PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd". |
| T1543.003 Windows Service |
MalwarePlugX | PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1564.001 Hidden Files and Directories |
MalwarePlugX | PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system. |
| T1564.003 Hidden Window |
MalwarePlugX | PlugX has the ability to execute a command on a hidden desktop. |
| T1571 Non-Standard Port |
MalwarePlugX | PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities. |
| T1573.001 Symmetric Cryptography |
MalwarePlugX | PlugX can use RC4 encryption in C2 communications. |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1614 System Location Discovery |
MalwarePlugX | PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
| T1622 Debugger Evasion |
MalwarePlugX | PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1680 Local Storage Discovery |
MalwarePlugX | PlugX has collected a list of all mapped drives on the infected host. |
| T1686 Disable or Modify System Firewall |
MalwarePlugX | PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.