ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0379×

18 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareRevenge RAT

Revenge RAT has a plugin for credential harvesting.

T1016
System Network Configuration Discovery
MalwareRevenge RAT

Revenge RAT collects the IP address and MAC address from the system.

T1021.001
Remote Desktop Protocol
MalwareRevenge RAT

Revenge RAT has a plugin to perform RDP access.

T1033
System Owner/User Discovery
MalwareRevenge RAT

Revenge RAT gathers the username from the system.

T1053.005
Scheduled Task
MalwareRevenge RAT

Revenge RAT schedules tasks to run malicious scripts at different intervals.

T1056.001
Keylogging
MalwareRevenge RAT

Revenge RAT has a plugin for keylogging.

T1059.001
PowerShell
MalwareRevenge RAT

Revenge RAT uses the PowerShell command Reflection.Assembly to load itself into memory to aid in execution.

T1059.003
Windows Command Shell
MalwareRevenge RAT

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1082
System Information Discovery
MalwareRevenge RAT

Revenge RAT collects the CPU information, OS information, and system language.

T1102.002
Bidirectional Communication
MalwareRevenge RAT

Revenge RAT used blogpost.com as its primary command and control server during a campaign.

T1105
Ingress Tool Transfer
MalwareRevenge RAT

Revenge RAT has the ability to upload and download files.

T1113
Screen Capture
MalwareRevenge RAT

Revenge RAT has a plugin for screen capture.

T1123
Audio Capture
MalwareRevenge RAT

Revenge RAT has a plugin for microphone interception.

T1125
Video Capture
MalwareRevenge RAT

Revenge RAT has the ability to access the webcam.

T1132.001
Standard Encoding
MalwareRevenge RAT

Revenge RAT uses Base64 to encode information sent to the C2 server.

T1202
Indirect Command Execution
MalwareRevenge RAT

Revenge RAT uses the Forfiles utility to execute commands on the system.

T1218.005
Mshta
MalwareRevenge RAT

Revenge RAT uses mshta.exe to run malicious scripts on the system.

T1547.004
Winlogon Helper DLL
MalwareRevenge RAT

Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.