ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0283×

28 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwarejRAT

jRAT can list local services.

T1016
System Network Configuration Discovery
MalwarejRAT

jRAT can gather victim internal and external IPs.

T1021.001
Remote Desktop Protocol
MalwarejRAT

jRAT can support RDP control.

T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1027.002
Software Packing
MalwarejRAT

jRAT payloads have been packed.

T1029
Scheduled Transfer
MalwarejRAT

jRAT can be configured to reconnect at certain intervals.

T1037.005
Startup Items
MalwarejRAT

jRAT can list and manage startup entries.

T1047
Windows Management Instrumentation
MalwarejRAT

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1049
System Network Connections Discovery
MalwarejRAT

jRAT can list network connections.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1057
Process Discovery
MalwarejRAT

jRAT can query and kill system processes.

T1059.003
Windows Command Shell
MalwarejRAT

jRAT has command line access.

T1059.005
Visual Basic
MalwarejRAT

jRAT has been distributed as HTA files with VBScript.

T1059.007
JavaScript
MalwarejRAT

jRAT has been distributed as HTA files with JScript.

T1070.004
File Deletion
MalwarejRAT

jRAT has a function to delete files from the victim’s machine.

T1082
System Information Discovery
MalwarejRAT

jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor.

T1083
File and Directory Discovery
MalwarejRAT

jRAT can browse file systems.

T1090
Proxy
MalwarejRAT

jRAT can serve as a SOCKS proxy server.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

T1113
Screen Capture
MalwarejRAT

jRAT has the capability to take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwarejRAT

jRAT can capture clipboard data.

T1120
Peripheral Device Discovery
MalwarejRAT

jRAT can map UPnP ports.

T1123
Audio Capture
MalwarejRAT

jRAT can capture microphone recordings.

T1125
Video Capture
MalwarejRAT

jRAT has the capability to capture video from a webcam.

T1518.001
Security Software Discovery
MalwarejRAT

jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1552.001
Credentials In Files
MalwarejRAT

jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk.

T1552.004
Private Keys
MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

T1555.003
Credentials from Web Browsers
MalwarejRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.