Real-world descriptions of how a group, tool or campaign used a technique.
38 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
ToolRemcos | Remcos can list all windows on victim systems. |
| T1012 Query Registry |
ToolRemcos | Remcos can obtain Registry data from targeted systems. |
| T1027 Obfuscated Files or Information |
ToolRemcos | Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis. |
| T1027.013 Encrypted/Encoded File |
ToolRemcos | Remcos can use string encryption to hinder analysis. |
| T1033 System Owner/User Discovery |
ToolRemcos | Remcos can enumerate the username on targeted hosts. |
| T1055 Process Injection |
ToolRemcos | Remcos has a command to hide itself by injecting into another process. |
| T1056.001 Keylogging |
ToolRemcos | Remcos has a command for keylogging. |
| T1057 Process Discovery |
ToolRemcos | Remcos can discover running processes on compromised machines. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.005 Visual Basic |
ToolRemcos | Remcos can execute VBS remotely. |
| T1059.006 Python |
ToolRemcos | Remcos uses Python scripts. |
| T1059.007 JavaScript |
ToolRemcos | Remcos has the ability to execute JavaScript remotely. |
| T1070 Indicator Removal |
ToolRemcos | Remcos can clean saved cookies and logins from the web browser. |
| T1070.004 File Deletion |
ToolRemcos | Remcos can delete files and folders from victim machines. |
| T1082 System Information Discovery |
ToolRemcos | Remcos can collect the OS version and process architecture of compromised hosts. |
| T1083 File and Directory Discovery |
ToolRemcos | Remcos can search for files on the infected machine. |
| T1090 Proxy |
ToolRemcos | Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying. |
| T1105 Ingress Tool Transfer |
ToolRemcos | Remcos can upload and download files to and from the victim’s machine. |
| T1112 Modify Registry |
ToolRemcos | Remcos has full control of the Registry, including the ability to modify it. |
| T1113 Screen Capture |
ToolRemcos | Remcos takes automated screenshots of the infected machine. |
| T1115 Clipboard Data |
ToolRemcos | Remcos steals and modifies data from the clipboard. |
| T1123 Audio Capture |
ToolRemcos | Remcos can capture data from the system’s microphone. |
| T1125 Video Capture |
ToolRemcos | Remcos can access a system’s webcam and take pictures. |
| T1132.001 Standard Encoding |
ToolRemcos | Remcos can serialize collected data with Protobuf. |
| T1204.002 Malicious File |
ToolRemcos | Remcos has been executed by luring victims into opening malicious email attachments including Excel files. |
| T1491.001 Internal Defacement |
ToolRemcos | Remcos has the ability to modify the desktop wallpaper. |
| T1497.001 System Checks |
ToolRemcos | Remcos searches for Sandboxie and VMware on the system. |
| T1529 System Shutdown/Reboot |
ToolRemcos | Remcos can shutdown and restart remote devices. |
| T1543.003 Windows Service |
ToolRemcos | Remcos can terminate, suspend, and resume a process by PID. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolRemcos | Remcos can add itself to the Registry key |
| T1548.002 Bypass User Account Control |
ToolRemcos | Remcos has a command for UAC bypassing. |
| T1560.001 Archive via Utility |
ToolRemcos | Remcos can zip files and folders for upload. |
| T1564 Hide Artifacts |
ToolRemcos | Remcos can modify file attributes to hide the file. |
| T1564.003 Hidden Window |
ToolRemcos | Remcos can set `ProcessWindowStyle.Hidden` to hide windows. |
| T1566.001 Spearphishing Attachment |
ToolRemcos | Remcos has been spread through emails containing malicious documents. |
| T1568 Dynamic Resolution |
ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
| T1573.002 Asymmetric Cryptography |
ToolRemcos | Remcos can use TLS to encrypt C2 communication. |
| T1614 System Location Discovery |
ToolRemcos | Remcos can identify the location of targeted devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.