Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCarberp | Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey. |
| T1014 Rootkit |
MalwareCarberp | Carberp has used user mode rootkit techniques to remain hidden on the system. |
| T1021.005 VNC |
MalwareCarberp | Carberp can start a remote VNC session by downloading a new plugin. |
| T1027.013 Encrypted/Encoded File |
MalwareCarberp | Carberp has used XOR-based encryption to mask C2 server locations within the trojan. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCarberp | Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe". |
| T1041 Exfiltration Over C2 Channel |
MalwareCarberp | Carberp has exfiltrated data via HTTP to already established C2 servers. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarberp | Carberp's bootkit can inject a malicious DLL into the address space of running processes. |
| T1055.004 Asynchronous Procedure Call |
MalwareCarberp | Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread. |
| T1056.004 Credential API Hooking |
MalwareCarberp | Carberp has hooked several Windows API functions to steal credentials. |
| T1057 Process Discovery |
MalwareCarberp | Carberp has collected a list of running processes. |
| T1068 Exploitation for Privilege Escalation |
MalwareCarberp | Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation. |
| T1071.001 Web Protocols |
MalwareCarberp | Carberp has connected to C2 servers via HTTP. |
| T1082 System Information Discovery |
MalwareCarberp | Carberp has collected the operating system version from the infected system. |
| T1105 Ingress Tool Transfer |
MalwareCarberp | Carberp can download and execute new plugins from the C2 server. |
| T1106 Native API |
MalwareCarberp | Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories. |
| T1113 Screen Capture |
MalwareCarberp | Carberp can capture display screenshots with the screens_dll.dll plugin. |
| T1185 Browser Session Hijacking |
MalwareCarberp | Carberp has captured credentials when a user performs login through a SSL session. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCarberp | Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software. |
| T1518.001 Security Software Discovery |
MalwareCarberp | Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products. |
| T1542.003 Bootkit |
MalwareCarberp | Carberp has installed a bootkit on the system to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCarberp | Carberp has maintained persistence by placing itself inside the current user's startup folder. |
| T1555 Credentials from Password Stores |
MalwareCarberp | Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients. |
| T1555.003 Credentials from Web Browsers |
MalwareCarberp | Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome. |
| T1564.001 Hidden Files and Directories |
MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
| T1685 Disable or Modify Tools |
MalwareCarberp | Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.