Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareMosquito | Mosquito uses the |
| T1027.011 Fileless Storage |
MalwareMosquito | Mosquito stores configuration values under the Registry key |
| T1027.013 Encrypted/Encoded File |
MalwareMosquito | Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer. |
| T1033 System Owner/User Discovery |
MalwareMosquito | Mosquito runs |
| T1047 Windows Management Instrumentation |
MalwareMosquito | Mosquito's installer uses WMI to search for antivirus display names. |
| T1057 Process Discovery |
MalwareMosquito | Mosquito runs |
| T1059.001 PowerShell |
MalwareMosquito | Mosquito can launch PowerShell Scripts. |
| T1059.003 Windows Command Shell |
MalwareMosquito | Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server. |
| T1070.004 File Deletion |
MalwareMosquito | Mosquito deletes files using DeleteFileW API call. |
| T1105 Ingress Tool Transfer |
MalwareMosquito | Mosquito can upload and download files to the victim. |
| T1106 Native API |
MalwareMosquito | Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions. |
| T1112 Modify Registry |
MalwareMosquito | Mosquito can modify Registry keys under |
| T1218.011 Rundll32 |
MalwareMosquito | Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability. |
| T1518.001 Security Software Discovery |
MalwareMosquito | Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system. |
| T1546.015 Component Object Model Hijacking |
MalwareMosquito | Mosquito uses COM hijacking as a method of persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMosquito | Mosquito establishes persistence under the Registry key |
| T1573.001 Symmetric Cryptography |
MalwareMosquito | Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.