ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0484×

25 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCarberp

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1014
Rootkit
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1021.005
VNC
MalwareCarberp

Carberp can start a remote VNC session by downloading a new plugin.

T1027.013
Encrypted/Encoded File
MalwareCarberp

Carberp has used XOR-based encryption to mask C2 server locations within the trojan.

T1036.005
Match Legitimate Resource Name or Location
MalwareCarberp

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1055.001
Dynamic-link Library Injection
MalwareCarberp

Carberp's bootkit can inject a malicious DLL into the address space of running processes.

T1055.004
Asynchronous Procedure Call
MalwareCarberp

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.

T1056.004
Credential API Hooking
MalwareCarberp

Carberp has hooked several Windows API functions to steal credentials.

T1057
Process Discovery
MalwareCarberp

Carberp has collected a list of running processes.

T1068
Exploitation for Privilege Escalation
MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1071.001
Web Protocols
MalwareCarberp

Carberp has connected to C2 servers via HTTP.

T1082
System Information Discovery
MalwareCarberp

Carberp has collected the operating system version from the infected system.

T1105
Ingress Tool Transfer
MalwareCarberp

Carberp can download and execute new plugins from the C2 server.

T1106
Native API
MalwareCarberp

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.

T1113
Screen Capture
MalwareCarberp

Carberp can capture display screenshots with the screens_dll.dll plugin.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1497
Virtualization/Sandbox Evasion
MalwareCarberp

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.

T1518.001
Security Software Discovery
MalwareCarberp

Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products.

T1542.003
Bootkit
MalwareCarberp

Carberp has installed a bootkit on the system to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarberp

Carberp has maintained persistence by placing itself inside the current user's startup folder.

T1555
Credentials from Password Stores
MalwareCarberp

Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients.

T1555.003
Credentials from Web Browsers
MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

T1564.001
Hidden Files and Directories
MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

T1685
Disable or Modify Tools
MalwareCarberp

Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.