Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareRDAT | RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2. |
| T1001.002 Steganography |
MalwareRDAT | RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator. |
| T1008 Fallback Channels |
MalwareRDAT | RDAT has used HTTP if DNS C2 communications were not functioning. |
| T1027.003 Steganography |
MalwareRDAT | RDAT can also embed data within a BMP image prior to exfiltration. |
| T1030 Data Transfer Size Limits |
MalwareRDAT | RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions. |
| T1036.004 Masquerade Task or Service |
MalwareRDAT | RDAT has used Windows Video Service as a name for malicious services. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRDAT | RDAT has masqueraded as VMware.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareRDAT | RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel. |
| T1059.003 Windows Command Shell |
MalwareRDAT | RDAT has executed commands using |
| T1070.004 File Deletion |
MalwareRDAT | RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system. |
| T1071.001 Web Protocols |
MalwareRDAT | RDAT can use HTTP communications for C2, as well as using the WinHTTP library to make requests to the Exchange Web Services API. |
| T1071.003 Mail Protocols |
MalwareRDAT | RDAT can use email attachments for C2 communications. |
| T1071.004 DNS |
MalwareRDAT | RDAT has used DNS to communicate with the C2. |
| T1105 Ingress Tool Transfer |
MalwareRDAT | RDAT can download files via DNS. |
| T1113 Screen Capture |
MalwareRDAT | RDAT can take a screenshot on the infected system. |
| T1132.001 Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via base32-encoded subdomains. |
| T1132.002 Non-Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRDAT | RDAT can deobfuscate the base64-encoded and AES-encrypted files downloaded from the C2 server. |
| T1543.003 Windows Service |
MalwareRDAT | RDAT has created a service when it is installed on the victim machine. |
| T1573.001 Symmetric Cryptography |
MalwareRDAT | RDAT has used AES ciphertext to encode C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.