ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0334×

18 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
MalwareDarkComet

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

T1027.002
Software Packing
MalwareDarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.

T1033
System Owner/User Discovery
MalwareDarkComet

DarkComet gathers the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareDarkComet

DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.

T1056.001
Keylogging
MalwareDarkComet

DarkComet has a keylogging capability.

T1057
Process Discovery
MalwareDarkComet

DarkComet can list active processes running on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

T1059.003
Windows Command Shell
MalwareDarkComet

DarkComet can launch a remote shell to execute commands on the victim’s machine.

T1071.001
Web Protocols
MalwareDarkComet

DarkComet can use HTTP for C2 communications.

T1082
System Information Discovery
MalwareDarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareDarkComet

DarkComet can load any files onto the infected machine to execute.

T1112
Modify Registry
MalwareDarkComet

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1115
Clipboard Data
MalwareDarkComet

DarkComet can steal data from the clipboard.

T1123
Audio Capture
MalwareDarkComet

DarkComet can listen in to victims' conversations through the system’s microphone.

T1125
Video Capture
MalwareDarkComet

DarkComet can access the victim’s webcam to take pictures.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1685
Disable or Modify Tools
MalwareDarkComet

DarkComet can disable Security Center functions like anti-virus.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.