Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareEmotet | Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| T1016.002 Wi-Fi Discovery |
MalwareEmotet | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| T1021.002 SMB/Windows Admin Shares |
MalwareEmotet | Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement. |
| T1027.001 Binary Padding |
MalwareEmotet | Emotet inflates malicious files and malware as an evasion technique. |
| T1027.002 Software Packing |
MalwareEmotet | Emotet has used custom packers to protect its payloads. |
| T1027.009 Embedded Payloads |
MalwareEmotet | Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1027.010 Command Obfuscation |
MalwareEmotet | Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareEmotet | Emotet uses obfuscated URLs to download a ZIP file. |
| T1033 System Owner/User Discovery |
MalwareEmotet | Emotet has enumerated all users connected to network shares. |
| T1036.004 Masquerade Task or Service |
MalwareEmotet | Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`. |
| T1040 Network Sniffing |
MalwareEmotet | Emotet has been observed to hook network APIs to monitor network traffic. |
| T1041 Exfiltration Over C2 Channel |
MalwareEmotet | Emotet has exfiltrated data over its C2 channel. |
| T1047 Windows Management Instrumentation |
MalwareEmotet | Emotet has used WMI to execute powershell.exe. |
| T1053.005 Scheduled Task |
MalwareEmotet | Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmotet | Emotet has been observed injecting in to Explorer.exe and other processes. |
| T1055.012 Process Hollowing |
MalwareEmotet | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code. |
| T1057 Process Discovery |
MalwareEmotet | Emotet has been observed enumerating local processes. |
| T1059.001 PowerShell |
MalwareEmotet | Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz. |
| T1059.003 Windows Command Shell |
MalwareEmotet | Emotet has used cmd.exe to run a PowerShell script. |
| T1059.005 Visual Basic |
MalwareEmotet | Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads. |
| T1071.001 Web Protocols |
MalwareEmotet | Emotet has used HTTP for command and control. |
| T1078.003 Local Accounts |
MalwareEmotet | Emotet can brute force a local admin password, then use it to facilitate lateral movement. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1105 Ingress Tool Transfer |
MalwareEmotet | Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code. |
| T1106 Native API |
MalwareEmotet | Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares. |
| T1110.001 Password Guessing |
MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| T1114 Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1114.001 Local Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that scrapes email data from Outlook. |
| T1132.001 Standard Encoding |
MalwareEmotet | Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| T1135 Network Share Discovery |
MalwareEmotet | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmotet | Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets. |
| T1204.001 Malicious Link |
MalwareEmotet | Emotet has relied upon users clicking on a malicious link delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareEmotet | Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1210 Exploitation of Remote Services |
MalwareEmotet | Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. |
| T1218.010 Regsvr32 |
MalwareEmotet | Emotet uses RegSvr32 to execute the DLL payload. |
| T1543.003 Windows Service |
MalwareEmotet | Emotet has been observed creating new services to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmotet | Emotet has been observed adding the downloaded payload to the |
| T1552.001 Credentials In Files |
MalwareEmotet | Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user. |
| T1555.003 Credentials from Web Browsers |
MalwareEmotet | Emotet has been observed dropping browser password grabber modules. |
| T1566.001 Spearphishing Attachment |
MalwareEmotet | Emotet has been delivered by phishing emails containing attachments. |
| T1566.002 Spearphishing Link |
MalwareEmotet | Emotet has been delivered by phishing emails containing links. |
| T1570 Lateral Tool Transfer |
MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| T1571 Non-Standard Port |
MalwareEmotet | Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S. |
| T1573 Encrypted Channel |
MalwareEmotet | Emotet has encrypted data before sending to the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareEmotet | Emotet is known to use RSA keys for encrypting C2 traffic. |
| T1620 Reflective Code Loading |
MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.