Real-world descriptions of how a group, tool or campaign used a technique.
55 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTrickBot | TrickBot collects local files and information from the victim’s local machine. |
| T1007 System Service Discovery |
MalwareTrickBot | TrickBot collects a list of install programs and services on the system’s machine. |
| T1008 Fallback Channels |
MalwareTrickBot | TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1018 Remote System Discovery |
MalwareTrickBot | TrickBot can enumerate computers and network devices. |
| T1021.005 VNC |
MalwareTrickBot | TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network |
| T1027 Obfuscated Files or Information |
MalwareTrickBot | TrickBot uses non-descriptive names to hide functionality. |
| T1027.002 Software Packing |
MalwareTrickBot | TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.013 Encrypted/Encoded File |
MalwareTrickBot | TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. |
| T1033 System Owner/User Discovery |
MalwareTrickBot | TrickBot can identify the user and groups the user belongs to on a compromised host. |
| T1036 Masquerading |
MalwareTrickBot | The TrickBot downloader has used an icon to appear as a Microsoft Word document. |
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1053.005 Scheduled Task |
MalwareTrickBot | TrickBot creates a scheduled task on the system that provides persistence. |
| T1055 Process Injection |
MalwareTrickBot | TrickBot has used |
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1056.004 Credential API Hooking |
MalwareTrickBot | TrickBot has the ability to capture RDP credentials by capturing the |
| T1057 Process Discovery |
MalwareTrickBot | TrickBot uses module networkDll for process list discovery. |
| T1059.001 PowerShell |
MalwareTrickBot | TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers. |
| T1059.003 Windows Command Shell |
MalwareTrickBot | TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine. |
| T1069 Permission Groups Discovery |
MalwareTrickBot | TrickBot can identify the groups the user on a compromised host belongs to. |
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1082 System Information Discovery |
MalwareTrickBot | TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareTrickBot | TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information. |
| T1087.001 Local Account |
MalwareTrickBot | TrickBot collects the users of the system. |
| T1087.003 Email Account |
MalwareTrickBot | TrickBot collects email addresses from Outlook. |
| T1090.002 External Proxy |
MalwareTrickBot | TrickBot has been known to reach a command and control server via one of nine proxy IP addresses. |
| T1105 Ingress Tool Transfer |
MalwareTrickBot | TrickBot downloads several additional files and saves them to the victim's machine. |
| T1106 Native API |
MalwareTrickBot | TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used |
| T1110.004 Credential Stuffing |
MalwareTrickBot | TrickBot uses brute-force attack against RDP with rdpscanDll module. |
| T1112 Modify Registry |
MalwareTrickBot | TrickBot can modify registry entries. |
| T1132.001 Standard Encoding |
MalwareTrickBot | TrickBot can Base64-encode C2 commands. |
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTrickBot | TrickBot decodes the configuration data and modules. |
| T1185 Browser Session Hijacking |
MalwareTrickBot | TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. |
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1210 Exploitation of Remote Services |
MalwareTrickBot | TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll. |
| T1219 Remote Access Tools |
MalwareTrickBot | TrickBot uses vncDll module to remote control the victim machine. |
| T1482 Domain Trust Discovery |
MalwareTrickBot | TrickBot can gather information about domain trusts by utilizing Nltest. |
| T1495 Firmware Corruption |
MalwareTrickBot | TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device. |
| T1497.003 Time Based Checks |
MalwareTrickBot | TrickBot has used |
| T1542.003 Bootkit |
MalwareTrickBot | TrickBot can implant malicious code into a compromised device's firmware. |
| T1543.003 Windows Service |
MalwareTrickBot | TrickBot establishes persistence by creating an autostart service that allows it to run whenever the machine boots. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrickBot | TrickBot establishes persistence in the Startup folder. |
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1552.002 Credentials in Registry |
MalwareTrickBot | TrickBot has retrieved PuTTY credentials by querying the |
| T1553.002 Code Signing |
MalwareTrickBot | TrickBot has come with a signed downloader component. |
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1555.005 Password Managers |
MalwareTrickBot | TrickBot can steal passwords from the KeePass open source password manager. |
| T1559.001 Component Object Model |
MalwareTrickBot | TrickBot used COM to setup scheduled task for persistence. |
| T1564.003 Hidden Window |
MalwareTrickBot | TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.