ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0332×

38 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
ToolRemcos

Remcos can list all windows on victim systems.

T1012
Query Registry
ToolRemcos

Remcos can obtain Registry data from targeted systems.

T1027
Obfuscated Files or Information
ToolRemcos

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

T1027.013
Encrypted/Encoded File
ToolRemcos

Remcos can use string encryption to hinder analysis.

T1033
System Owner/User Discovery
ToolRemcos

Remcos can enumerate the username on targeted hosts.

T1055
Process Injection
ToolRemcos

Remcos has a command to hide itself by injecting into another process.

T1056.001
Keylogging
ToolRemcos

Remcos has a command for keylogging.

T1057
Process Discovery
ToolRemcos

Remcos can discover running processes on compromised machines.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.005
Visual Basic
ToolRemcos

Remcos can execute VBS remotely.

T1059.006
Python
ToolRemcos

Remcos uses Python scripts.

T1059.007
JavaScript
ToolRemcos

Remcos has the ability to execute JavaScript remotely.

T1070
Indicator Removal
ToolRemcos

Remcos can clean saved cookies and logins from the web browser.

T1070.004
File Deletion
ToolRemcos

Remcos can delete files and folders from victim machines.

T1082
System Information Discovery
ToolRemcos

Remcos can collect the OS version and process architecture of compromised hosts.

T1083
File and Directory Discovery
ToolRemcos

Remcos can search for files on the infected machine.

T1090
Proxy
ToolRemcos

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1112
Modify Registry
ToolRemcos

Remcos has full control of the Registry, including the ability to modify it.

T1113
Screen Capture
ToolRemcos

Remcos takes automated screenshots of the infected machine.

T1115
Clipboard Data
ToolRemcos

Remcos steals and modifies data from the clipboard.

T1123
Audio Capture
ToolRemcos

Remcos can capture data from the system’s microphone.

T1125
Video Capture
ToolRemcos

Remcos can access a system’s webcam and take pictures.

T1132.001
Standard Encoding
ToolRemcos

Remcos can serialize collected data with Protobuf.

T1204.002
Malicious File
ToolRemcos

Remcos has been executed by luring victims into opening malicious email attachments including Excel files.

T1491.001
Internal Defacement
ToolRemcos

Remcos has the ability to modify the desktop wallpaper.

T1497.001
System Checks
ToolRemcos

Remcos searches for Sandboxie and VMware on the system.

T1529
System Shutdown/Reboot
ToolRemcos

Remcos can shutdown and restart remote devices.

T1543.003
Windows Service
ToolRemcos

Remcos can terminate, suspend, and resume a process by PID.

T1547.001
Registry Run Keys / Startup Folder
ToolRemcos

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1548.002
Bypass User Account Control
ToolRemcos

Remcos has a command for UAC bypassing.

T1560.001
Archive via Utility
ToolRemcos

Remcos can zip files and folders for upload.

T1564
Hide Artifacts
ToolRemcos

Remcos can modify file attributes to hide the file.

T1564.003
Hidden Window
ToolRemcos

Remcos can set `ProcessWindowStyle.Hidden` to hide windows.

T1566.001
Spearphishing Attachment
ToolRemcos

Remcos has been spread through emails containing malicious documents.

T1568
Dynamic Resolution
ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

T1573.002
Asymmetric Cryptography
ToolRemcos

Remcos can use TLS to encrypt C2 communication.

T1614
System Location Discovery
ToolRemcos

Remcos can identify the location of targeted devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.