Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
Malwaregh0st RAT | gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system. |
| T1055 Process Injection |
Malwaregh0st RAT | gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function. |
| T1056.001 Keylogging |
Malwaregh0st RAT | gh0st RAT has a keylogger. |
| T1057 Process Discovery |
Malwaregh0st RAT | gh0st RAT has the capability to list processes. |
| T1059 Command and Scripting Interpreter |
Malwaregh0st RAT | gh0st RAT is able to open a remote shell to execute commands. |
| T1070.004 File Deletion |
Malwaregh0st RAT | gh0st RAT has the capability to to delete files. |
| T1082 System Information Discovery |
Malwaregh0st RAT | gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information. |
| T1095 Non-Application Layer Protocol |
Malwaregh0st RAT | gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2. |
| T1105 Ingress Tool Transfer |
Malwaregh0st RAT | gh0st RAT can download files to the victim’s machine. |
| T1106 Native API |
Malwaregh0st RAT | gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions. |
| T1112 Modify Registry |
Malwaregh0st RAT | gh0st RAT has altered the InstallTime subkey. |
| T1113 Screen Capture |
Malwaregh0st RAT | gh0st RAT can capture the victim’s screen remotely. |
| T1129 Shared Modules |
Malwaregh0st RAT | gh0st RAT can load DLLs into memory. |
| T1132.001 Standard Encoding |
Malwaregh0st RAT | gh0st RAT has used Zlib to compress C2 communications data before encrypting it. |
| T1140 Deobfuscate/Decode Files or Information |
Malwaregh0st RAT | gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched. |
| T1218.011 Rundll32 |
Malwaregh0st RAT | A gh0st RAT variant has used rundll32 for execution. |
| T1543.003 Windows Service |
Malwaregh0st RAT | gh0st RAT can create a new service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwaregh0st RAT | gh0st RAT has added a Registry Run key to establish persistence. |
| T1568.001 Fast Flux DNS |
Malwaregh0st RAT | gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses. |
| T1569.002 Service Execution |
Malwaregh0st RAT | gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service. |
| T1573 Encrypted Channel |
Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| T1573.001 Symmetric Cryptography |
Malwaregh0st RAT | gh0st RAT uses RC4 and XOR to encrypt C2 traffic. |
| T1574.001 DLL |
Malwaregh0st RAT | A gh0st RAT variant has used DLL side-loading. |
| T1685.005 Clear Windows Event Logs |
Malwaregh0st RAT | gh0st RAT is able to wipe event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.