Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareCardinal RAT | Cardinal RAT can communicate over multiple C2 host and port combinations. |
| T1012 Query Registry |
MalwareCardinal RAT | Cardinal RAT contains watchdog functionality that periodically ensures |
| T1027.004 Compile After Delivery |
MalwareCardinal RAT | Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code. |
| T1027.013 Encrypted/Encoded File |
MalwareCardinal RAT | Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded. |
| T1033 System Owner/User Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the username from a victim machine. |
| T1055 Process Injection |
MalwareCardinal RAT | Cardinal RAT injects into a newly spawned process created from a native Windows executable. |
| T1056.001 Keylogging |
MalwareCardinal RAT | Cardinal RAT can log keystrokes. |
| T1057 Process Discovery |
MalwareCardinal RAT | Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance. |
| T1059.003 Windows Command Shell |
MalwareCardinal RAT | Cardinal RAT can execute commands. |
| T1070.004 File Deletion |
MalwareCardinal RAT | Cardinal RAT can uninstall itself, including deleting its executable. |
| T1071.001 Web Protocols |
MalwareCardinal RAT | Cardinal RAT is downloaded using HTTP over port 443. |
| T1082 System Information Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine. |
| T1083 File and Directory Discovery |
MalwareCardinal RAT | Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload). |
| T1090 Proxy |
MalwareCardinal RAT | Cardinal RAT can act as a reverse proxy. |
| T1105 Ingress Tool Transfer |
MalwareCardinal RAT | Cardinal RAT can download and execute additional payloads. |
| T1112 Modify Registry |
MalwareCardinal RAT | Cardinal RAT sets |
| T1113 Screen Capture |
MalwareCardinal RAT | Cardinal RAT can capture screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCardinal RAT | Cardinal RAT decodes many of its artifacts and is decrypted (AES-128) after being downloaded. |
| T1204.002 Malicious File |
MalwareCardinal RAT | Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCardinal RAT | Cardinal RAT establishes Persistence by setting the |
| T1560.002 Archive via Library |
MalwareCardinal RAT | Cardinal RAT applies compression to C2 traffic using the ZLIB library. |
| T1573.001 Symmetric Cryptography |
MalwareCardinal RAT | Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.