Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareGoopy | Goopy has the ability to exfiltrate documents from infected systems. |
| T1027.001 Binary Padding |
MalwareGoopy | Goopy has had null characters padded in its malicious DLL payload. |
| T1027.016 Junk Code Insertion |
MalwareGoopy | Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1033 System Owner/User Discovery |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoopy | Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoopy | Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel. |
| T1053.005 Scheduled Task |
MalwareGoopy | Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour. |
| T1057 Process Discovery |
MalwareGoopy | Goopy has checked for the Google Updater process to ensure Goopy was loaded properly. |
| T1059.003 Windows Command Shell |
MalwareGoopy | Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel. |
| T1059.005 Visual Basic |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1070.008 Clear Mailbox Data |
MalwareGoopy | Goopy has the ability to delete emails used for C2 once the content has been copied. |
| T1071.001 Web Protocols |
MalwareGoopy | Goopy has the ability to communicate with its C2 over HTTP. |
| T1071.003 Mail Protocols |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1071.004 DNS |
MalwareGoopy | Goopy has the ability to communicate with its C2 over DNS. |
| T1106 Native API |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name via |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoopy | Goopy has used a polymorphic decryptor to decrypt itself at runtime. |
| T1574.001 DLL |
MalwareGoopy | Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google. |
| T1685 Disable or Modify Tools |
MalwareGoopy | Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.