Real-world descriptions of how a group, tool or campaign used a technique.
45 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareNETWIRE | NETWIRE can discover and close windows on controlled systems. |
| T1016 System Network Configuration Discovery |
MalwareNETWIRE | NETWIRE can collect the IP address of a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareNETWIRE | NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1027.002 Software Packing |
MalwareNETWIRE | NETWIRE has used .NET packer tools to evade detection. |
| T1027.011 Fileless Storage |
MalwareNETWIRE | NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1036.001 Invalid Code Signature |
MalwareNETWIRE | The NETWIRE client has been signed by fake and invalid digital certificates. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNETWIRE | NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder. |
| T1049 System Network Connections Discovery |
MalwareNETWIRE | NETWIRE can capture session logon details from a compromised host. |
| T1053.003 Cron |
MalwareNETWIRE | NETWIRE can use crontabs to establish persistence. |
| T1053.005 Scheduled Task |
MalwareNETWIRE | NETWIRE can create a scheduled task to establish persistence. |
| T1055 Process Injection |
MalwareNETWIRE | NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1057 Process Discovery |
MalwareNETWIRE | NETWIRE can discover processes on compromised hosts. |
| T1059.001 PowerShell |
MalwareNETWIRE | The NETWIRE binary has been executed via PowerShell script. |
| T1059.003 Windows Command Shell |
MalwareNETWIRE | NETWIRE can issue commands using cmd.exe. |
| T1059.004 Unix Shell |
MalwareNETWIRE | NETWIRE has the ability to use |
| T1059.005 Visual Basic |
MalwareNETWIRE | NETWIRE has been executed through use of VBScripts. |
| T1071.001 Web Protocols |
MalwareNETWIRE | NETWIRE has the ability to communicate over HTTP. |
| T1074.001 Local Data Staging |
MalwareNETWIRE | NETWIRE has the ability to write collected data to a file created in the |
| T1082 System Information Discovery |
MalwareNETWIRE | NETWIRE can discover and collect victim system information. |
| T1083 File and Directory Discovery |
MalwareNETWIRE | NETWIRE has the ability to search for files on the compromised host. |
| T1090 Proxy |
MalwareNETWIRE | NETWIRE can implement use of proxies to pivot traffic. |
| T1095 Non-Application Layer Protocol |
MalwareNETWIRE | NETWIRE can use TCP in C2 communications. |
| T1102 Web Service |
MalwareNETWIRE | NETWIRE has used web services including Paste.ee to host payloads. |
| T1105 Ingress Tool Transfer |
MalwareNETWIRE | NETWIRE can downloaded payloads from C2 to the compromised host. |
| T1106 Native API |
MalwareNETWIRE | NETWIRE can use Native API including |
| T1112 Modify Registry |
MalwareNETWIRE | NETWIRE can modify the Registry to store its configuration information. |
| T1113 Screen Capture |
MalwareNETWIRE | NETWIRE can capture the victim's screen. |
| T1119 Automated Collection |
MalwareNETWIRE | NETWIRE can automatically archive collected data. |
| T1204.001 Malicious Link |
MalwareNETWIRE | NETWIRE has been executed through convincing victims into clicking malicious links. |
| T1204.002 Malicious File |
MalwareNETWIRE | NETWIRE has been executed through luring victims into opening malicious documents. |
| T1543.001 Launch Agent |
MalwareNETWIRE | NETWIRE can use launch agents for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETWIRE | NETWIRE creates a Registry start-up entry to establish persistence. |
| T1547.013 XDG Autostart Entries |
MalwareNETWIRE | NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems. |
| T1547.015 Login Items |
MalwareNETWIRE | NETWIRE can persist via startup options for Login items. |
| T1555 Credentials from Password Stores |
MalwareNETWIRE | NETWIRE can retrieve passwords from messaging and mail client applications. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1560 Archive Collected Data |
MalwareNETWIRE | NETWIRE has the ability to compress archived screenshots. |
| T1560.003 Archive via Custom Method |
MalwareNETWIRE | NETWIRE has used a custom encryption algorithm to encrypt collected data. |
| T1564.001 Hidden Files and Directories |
MalwareNETWIRE | NETWIRE can copy itself to and launch itself from hidden folders. |
| T1566.001 Spearphishing Attachment |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious links. |
| T1573 Encrypted Channel |
MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNETWIRE | NETWIRE can use AES encryption for C2 data transferred. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.