Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareCHOPSTICK | CHOPSTICK can switch to a new C2 channel if the current one is broken. |
| T1012 Query Registry |
MalwareCHOPSTICK | CHOPSTICK provides access to the Windows Registry, which can be used to gather information. |
| T1027.011 Fileless Storage |
MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1071.001 Web Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over HTTP. |
| T1071.003 Mail Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3. |
| T1083 File and Directory Discovery |
MalwareCHOPSTICK | An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o. |
| T1090.001 Internal Proxy |
MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1105 Ingress Tool Transfer |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote file transmission. |
| T1112 Modify Registry |
MalwareCHOPSTICK | CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information. |
| T1113 Screen Capture |
MalwareCHOPSTICK | CHOPSTICK has the capability to capture screenshots. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCHOPSTICK | CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
| T1518.001 Security Software Discovery |
MalwareCHOPSTICK | CHOPSTICK checks for antivirus and forensics software. |
| T1568.002 Domain Generation Algorithms |
MalwareCHOPSTICK | CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists. |
| T1573.001 Symmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with RC4. |
| T1573.002 Asymmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with TLS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.