ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0526×

20 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareKGH_SPY

KGH_SPY can send a file containing victim system information to C2.

T1027.013
Encrypted/Encoded File
MalwareKGH_SPY

KGH_SPY has used encrypted strings in its installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareKGH_SPY

KGH_SPY has masqueraded as a legitimate Windows tool.

T1037.001
Logon Script (Windows)
MalwareKGH_SPY

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

T1041
Exfiltration Over C2 Channel
MalwareKGH_SPY

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1056.001
Keylogging
MalwareKGH_SPY

KGH_SPY can perform keylogging by polling the GetAsyncKeyState() function.

T1059.001
PowerShell
MalwareKGH_SPY

KGH_SPY can execute PowerShell commands on the victim's machine.

T1059.003
Windows Command Shell
MalwareKGH_SPY

KGH_SPY has the ability to set a Registry key to run a cmd.exe command.

T1071.001
Web Protocols
MalwareKGH_SPY

KGH_SPY can send data to C2 with HTTP POST requests.

T1074.001
Local Data Staging
MalwareKGH_SPY

KGH_SPY can save collected system information to a file named "info" before exfiltration.

T1083
File and Directory Discovery
MalwareKGH_SPY

KGH_SPY can enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer
MalwareKGH_SPY

KGH_SPY has the ability to download and execute code from remote servers.

T1114.001
Local Email Collection
MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

T1140
Deobfuscate/Decode Files or Information
MalwareKGH_SPY

KGH_SPY can decrypt encrypted strings and write them to a newly created folder.

T1204.002
Malicious File
MalwareKGH_SPY

KGH_SPY has been spread through Word documents containing malicious macros.

T1518
Software Discovery
MalwareKGH_SPY

KGH_SPY can collect information on installed applications.

T1555
Credentials from Password Stores
MalwareKGH_SPY

KGH_SPY can collect credentials from WINSCP.

T1555.003
Credentials from Web Browsers
MalwareKGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.

T1555.004
Windows Credential Manager
MalwareKGH_SPY

KGH_SPY can collect credentials from the Windows Credential Manager.

T1680
Local Storage Discovery
MalwareKGH_SPY

KGH_SPY can collect drive information from a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.