Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareKONNI | KONNI has stored collected information and discovered processes in a tmp file. |
| T1016 System Network Configuration Discovery |
MalwareKONNI | KONNI can collect the IP address from the victim’s machine. |
| T1027.002 Software Packing |
MalwareKONNI | KONNI has been packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareKONNI | KONNI is heavily obfuscated and includes encrypted configuration files. |
| T1033 System Owner/User Discovery |
MalwareKONNI | KONNI can collect the username from the victim’s machine. |
| T1036.004 Masquerade Task or Service |
MalwareKONNI | KONNI has pretended to be the xmlProv Network Provisioning service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKONNI | KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file. |
| T1041 Exfiltration Over C2 Channel |
MalwareKONNI | KONNI has sent data and files to its C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKONNI | KONNI has used FTP to exfiltrate reconnaissance data out. |
| T1049 System Network Connections Discovery |
MalwareKONNI | KONNI has used |
| T1056.001 Keylogging |
MalwareKONNI | KONNI has the capability to perform keylogging. |
| T1057 Process Discovery |
MalwareKONNI | KONNI has used the command |
| T1059.001 PowerShell |
MalwareKONNI | KONNI used PowerShell to download and execute a specific 64-bit version of the malware. |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1059.007 JavaScript |
MalwareKONNI | KONNI has executed malicious JavaScript code. |
| T1070.004 File Deletion |
MalwareKONNI | KONNI can delete files. |
| T1071.001 Web Protocols |
MalwareKONNI | KONNI has used HTTP POST for C2. |
| T1082 System Information Discovery |
MalwareKONNI | KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used |
| T1083 File and Directory Discovery |
MalwareKONNI | A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together. |
| T1105 Ingress Tool Transfer |
MalwareKONNI | KONNI can download files and execute them on the victim’s machine. |
| T1106 Native API |
MalwareKONNI | KONNI has hardcoded API calls within its functions to use on the victim's machine. |
| T1112 Modify Registry |
MalwareKONNI | KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence. |
| T1113 Screen Capture |
MalwareKONNI | KONNI can take screenshots of the victim’s machine. |
| T1115 Clipboard Data |
MalwareKONNI | KONNI had a feature to steal data from the clipboard. |
| T1132.001 Standard Encoding |
MalwareKONNI | KONNI has used a custom base64 key to encode stolen data before exfiltration. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1134.004 Parent PID Spoofing |
MalwareKONNI | KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKONNI | KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process. |
| T1204.002 Malicious File |
MalwareKONNI | KONNI has relied on a victim to enable malicious macros within an attachment delivered via email. |
| T1218.011 Rundll32 |
MalwareKONNI | KONNI has used Rundll32 to execute its loader for privilege escalation purposes. |
| T1543.003 Windows Service |
MalwareKONNI | KONNI has registered itself as a service using its export function. |
| T1546.015 Component Object Model Hijacking |
MalwareKONNI | KONNI has modified ComSysApp service to load the malicious DLL payload. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKONNI | A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareKONNI | A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareKONNI | KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify". |
| T1555.003 Credentials from Web Browsers |
MalwareKONNI | KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera. |
| T1560 Archive Collected Data |
MalwareKONNI | KONNI has encrypted data and files prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
MalwareKONNI | KONNI has been delivered via spearphishing campaigns through a malicious Word document. |
| T1573.001 Symmetric Cryptography |
MalwareKONNI | KONNI has used AES to encrypt C2 traffic. |
| T1680 Local Storage Discovery |
MalwareKONNI | KONNI can gather information on connected drives and disk space from the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.