Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarenjRAT | njRAT can collect data from a local system. |
| T1010 Application Window Discovery |
MalwarenjRAT | njRAT gathers information about opened windows during the initial infection. |
| T1012 Query Registry |
MalwarenjRAT | njRAT can read specific registry values. |
| T1018 Remote System Discovery |
MalwarenjRAT | njRAT can identify remote hosts on connected networks. |
| T1021.001 Remote Desktop Protocol |
MalwarenjRAT | njRAT has a module for performing remote desktop access. |
| T1027.004 Compile After Delivery |
MalwarenjRAT | njRAT has used AutoIt to compile the payload and main script into a single executable after delivery. |
| T1027.013 Encrypted/Encoded File |
MalwarenjRAT | njRAT has included a base64 encoded executable. |
| T1033 System Owner/User Discovery |
MalwarenjRAT | njRAT enumerates the current user during the initial infection. |
| T1041 Exfiltration Over C2 Channel |
MalwarenjRAT | njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1057 Process Discovery |
MalwarenjRAT | njRAT can search a list of running processes for Tr.exe. |
| T1059.001 PowerShell |
MalwarenjRAT | njRAT has executed PowerShell commands via auto-run registry key persistence. |
| T1059.003 Windows Command Shell |
MalwarenjRAT | njRAT can launch a command shell interface for executing commands. |
| T1070.004 File Deletion |
MalwarenjRAT | njRAT is capable of deleting files. |
| T1070.009 Clear Persistence |
MalwarenjRAT | njRAT is capable of manipulating and deleting registry keys, including those used for persistence. |
| T1071.001 Web Protocols |
MalwarenjRAT | njRAT has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwarenjRAT | njRAT enumerates the victim operating system and computer name during the initial infection. |
| T1083 File and Directory Discovery |
MalwarenjRAT | njRAT can browse file systems using a file manager module. |
| T1091 Replication Through Removable Media |
MalwarenjRAT | njRAT can be configured to spread via removable drives. |
| T1105 Ingress Tool Transfer |
MalwarenjRAT | njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies. |
| T1106 Native API |
MalwarenjRAT | njRAT has used the ShellExecute() function within a script. |
| T1112 Modify Registry |
MalwarenjRAT | njRAT can create, delete, or modify a specified Registry key or value. |
| T1113 Screen Capture |
MalwarenjRAT | njRAT can capture screenshots of the victim’s machines. |
| T1120 Peripheral Device Discovery |
MalwarenjRAT | njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system. |
| T1125 Video Capture |
MalwarenjRAT | njRAT can access the victim's webcam. |
| T1132.001 Standard Encoding |
MalwarenjRAT | njRAT uses Base64 encoding for C2 traffic. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarenjRAT | njRAT has added persistence via the Registry key |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
| T1568.001 Fast Flux DNS |
MalwarenjRAT | njRAT has used a fast flux DNS for C2 IP resolution. |
| T1571 Non-Standard Port |
MalwarenjRAT | njRAT has used port 1177 for HTTP C2 communications. |
| T1686.003 Windows Host Firewall |
MalwarenjRAT | njRAT has modified the Windows firewall to allow itself to communicate through the firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.