ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0240×

30 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareROKRAT

ROKRAT can collect host data and specific file types.

T1010
Application Window Discovery
MalwareROKRAT

ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing.

T1012
Query Registry
MalwareROKRAT

ROKRAT can access the HKLM\System\CurrentControlSet\Services\mssmbios\Data\SMBiosData Registry key to obtain the System manufacturer value to identify the machine type.

T1027
Obfuscated Files or Information
MalwareROKRAT

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1033
System Owner/User Discovery
MalwareROKRAT

ROKRAT can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareROKRAT

ROKRAT can send collected files back over same C2 channel.

T1055
Process Injection
MalwareROKRAT

ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`.

T1056.001
Keylogging
MalwareROKRAT

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1057
Process Discovery
MalwareROKRAT

ROKRAT can list the current running processes on the system.

T1059.005
Visual Basic
MalwareROKRAT

ROKRAT has used Visual Basic for execution.

T1070.004
File Deletion
MalwareROKRAT

ROKRAT can request to delete files.

T1071.001
Web Protocols
MalwareROKRAT

ROKRAT can use HTTP and HTTPS for command and control communication.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1102.002
Bidirectional Communication
MalwareROKRAT

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1106
Native API
MalwareROKRAT

ROKRAT can use a variety of API calls to execute shellcode.

T1112
Modify Registry
MalwareROKRAT

ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

T1115
Clipboard Data
MalwareROKRAT

ROKRAT can extract clipboard data from a compromised host.

T1123
Audio Capture
MalwareROKRAT

ROKRAT has an audio capture and eavesdropping module.

T1140
Deobfuscate/Decode Files or Information
MalwareROKRAT

ROKRAT can decrypt strings using the victim's hostname as the key.

T1204.002
Malicious File
MalwareROKRAT

ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1480.001
Environmental Keying
MalwareROKRAT

ROKRAT relies on a specific victim hostname to execute and decrypt important strings.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1555.003
Credentials from Web Browsers
MalwareROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.

T1555.004
Windows Credential Manager
MalwareROKRAT

ROKRAT can steal credentials by leveraging the Windows Vault mechanism.

T1566.001
Spearphishing Attachment
MalwareROKRAT

ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

T1622
Debugger Evasion
MalwareROKRAT

ROKRAT can check for debugging tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.