ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0385×

31 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarenjRAT

njRAT can collect data from a local system.

T1010
Application Window Discovery
MalwarenjRAT

njRAT gathers information about opened windows during the initial infection.

T1012
Query Registry
MalwarenjRAT

njRAT can read specific registry values.

T1018
Remote System Discovery
MalwarenjRAT

njRAT can identify remote hosts on connected networks.

T1021.001
Remote Desktop Protocol
MalwarenjRAT

njRAT has a module for performing remote desktop access.

T1027.004
Compile After Delivery
MalwarenjRAT

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

T1027.013
Encrypted/Encoded File
MalwarenjRAT

njRAT has included a base64 encoded executable.

T1033
System Owner/User Discovery
MalwarenjRAT

njRAT enumerates the current user during the initial infection.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1057
Process Discovery
MalwarenjRAT

njRAT can search a list of running processes for Tr.exe.

T1059.001
PowerShell
MalwarenjRAT

njRAT has executed PowerShell commands via auto-run registry key persistence.

T1059.003
Windows Command Shell
MalwarenjRAT

njRAT can launch a command shell interface for executing commands.

T1070.004
File Deletion
MalwarenjRAT

njRAT is capable of deleting files.

T1070.009
Clear Persistence
MalwarenjRAT

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

T1071.001
Web Protocols
MalwarenjRAT

njRAT has used HTTP for C2 communications.

T1082
System Information Discovery
MalwarenjRAT

njRAT enumerates the victim operating system and computer name during the initial infection.

T1083
File and Directory Discovery
MalwarenjRAT

njRAT can browse file systems using a file manager module.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

T1106
Native API
MalwarenjRAT

njRAT has used the ShellExecute() function within a script.

T1112
Modify Registry
MalwarenjRAT

njRAT can create, delete, or modify a specified Registry key or value.

T1113
Screen Capture
MalwarenjRAT

njRAT can capture screenshots of the victim’s machines.

T1120
Peripheral Device Discovery
MalwarenjRAT

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.

T1125
Video Capture
MalwarenjRAT

njRAT can access the victim's webcam.

T1132.001
Standard Encoding
MalwarenjRAT

njRAT uses Base64 encoding for C2 traffic.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1568.001
Fast Flux DNS
MalwarenjRAT

njRAT has used a fast flux DNS for C2 IP resolution.

T1571
Non-Standard Port
MalwarenjRAT

njRAT has used port 1177 for HTTP C2 communications.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.