Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareROKRAT | ROKRAT can collect host data and specific file types. |
| T1010 Application Window Discovery |
MalwareROKRAT | ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing. |
| T1012 Query Registry |
MalwareROKRAT | ROKRAT can access the |
| T1027 Obfuscated Files or Information |
MalwareROKRAT | ROKRAT can encrypt data prior to exfiltration by using an RSA public key. |
| T1033 System Owner/User Discovery |
MalwareROKRAT | ROKRAT can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwareROKRAT | ROKRAT can send collected files back over same C2 channel. |
| T1055 Process Injection |
MalwareROKRAT | ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`. |
| T1056.001 Keylogging |
MalwareROKRAT | ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes. |
| T1057 Process Discovery |
MalwareROKRAT | ROKRAT can list the current running processes on the system. |
| T1059.005 Visual Basic |
MalwareROKRAT | ROKRAT has used Visual Basic for execution. |
| T1070.004 File Deletion |
MalwareROKRAT | ROKRAT can request to delete files. |
| T1071.001 Web Protocols |
MalwareROKRAT | ROKRAT can use HTTP and HTTPS for command and control communication. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1102.002 Bidirectional Communication |
MalwareROKRAT | ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareROKRAT | ROKRAT can retrieve additional malicious payloads from its C2 server. |
| T1106 Native API |
MalwareROKRAT | ROKRAT can use a variety of API calls to execute shellcode. |
| T1112 Modify Registry |
MalwareROKRAT | ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host. |
| T1113 Screen Capture |
MalwareROKRAT | ROKRAT can capture screenshots of the infected system using the `gdi32` library. |
| T1115 Clipboard Data |
MalwareROKRAT | ROKRAT can extract clipboard data from a compromised host. |
| T1123 Audio Capture |
MalwareROKRAT | ROKRAT has an audio capture and eavesdropping module. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROKRAT | ROKRAT can decrypt strings using the victim's hostname as the key. |
| T1204.002 Malicious File |
MalwareROKRAT | ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1480.001 Environmental Keying |
MalwareROKRAT | ROKRAT relies on a specific victim hostname to execute and decrypt important strings. |
| T1497.001 System Checks |
MalwareROKRAT | ROKRAT can check for VMware-related files and DLLs related to sandboxes. |
| T1555.003 Credentials from Web Browsers |
MalwareROKRAT | ROKRAT can steal credentials stored in Web browsers by querying the sqlite database. |
| T1555.004 Windows Credential Manager |
MalwareROKRAT | ROKRAT can steal credentials by leveraging the Windows Vault mechanism. |
| T1566.001 Spearphishing Attachment |
MalwareROKRAT | ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareROKRAT | ROKRAT can send collected data to cloud storage services such as PCloud. |
| T1622 Debugger Evasion |
MalwareROKRAT | ROKRAT can check for debugging tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.