Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareHOPLIGHT | HOPLIGHT has the capability to harvest credentials and passwords from the SAM database. |
| T1008 Fallback Channels |
MalwareHOPLIGHT | HOPLIGHT has multiple C2 channels in place in case one fails. |
| T1012 Query Registry |
MalwareHOPLIGHT | A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key |
| T1041 Exfiltration Over C2 Channel |
MalwareHOPLIGHT | HOPLIGHT has used its C2 channel to exfiltrate data. |
| T1047 Windows Management Instrumentation |
MalwareHOPLIGHT | HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository. |
| T1055 Process Injection |
MalwareHOPLIGHT | HOPLIGHT has injected into running processes. |
| T1059.003 Windows Command Shell |
MalwareHOPLIGHT | HOPLIGHT can launch cmd.exe to execute commands on the system. |
| T1082 System Information Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting victim machine information like OS version. |
| T1083 File and Directory Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed enumerating system drives and partitions. |
| T1090 Proxy |
MalwareHOPLIGHT | HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators. |
| T1105 Ingress Tool Transfer |
MalwareHOPLIGHT | HOPLIGHT has the ability to connect to a remote host in order to upload and download files. |
| T1112 Modify Registry |
MalwareHOPLIGHT | HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system. |
| T1124 System Time Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting system time from victim machines. |
| T1132.001 Standard Encoding |
MalwareHOPLIGHT | HOPLIGHT has utilized Zlib compression to obfuscate the communications payload. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareHOPLIGHT | HOPLIGHT can use WMI event subscriptions to create persistence. |
| T1550.002 Pass the Hash |
MalwareHOPLIGHT | HOPLIGHT has been observed loading several APIs associated with Pass the Hash. |
| T1569.002 Service Execution |
MalwareHOPLIGHT | HOPLIGHT has used svchost.exe to execute a malicious DLL . |
| T1571 Non-Standard Port |
MalwareHOPLIGHT | HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method. |
| T1652 Device Driver Discovery |
MalwareHOPLIGHT | HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`. |
| T1680 Local Storage Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting victim machine volume information. |
| T1686 Disable or Modify System Firewall |
MalwareHOPLIGHT |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.