Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on window names. |
| T1016 System Network Configuration Discovery |
MalwareGrandoreiro | Grandoreiro can determine the IP and physical location of the compromised host via IPinfo. |
| T1027.001 Binary Padding |
MalwareGrandoreiro | Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size. |
| T1027.011 Fileless Storage |
MalwareGrandoreiro | Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| T1027.013 Encrypted/Encoded File |
MalwareGrandoreiro | The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file. |
| T1033 System Owner/User Discovery |
MalwareGrandoreiro | Grandoreiro can collect the username from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGrandoreiro | Grandoreiro has named malicious browser extensions and update files to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrandoreiro | Grandoreiro can send data it retrieves to the C2 server. |
| T1056.001 Keylogging |
MalwareGrandoreiro | Grandoreiro can log keystrokes on the victim's machine. |
| T1057 Process Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on process names. |
| T1059.005 Visual Basic |
MalwareGrandoreiro | Grandoreiro can use VBScript to execute malicious code. |
| T1070.004 File Deletion |
MalwareGrandoreiro | Grandoreiro can delete .LNK files created in the Startup folder. |
| T1071.001 Web Protocols |
MalwareGrandoreiro | Grandoreiro has the ability to use HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareGrandoreiro | Grandoreiro can collect the computer name and OS version from a compromised host. |
| T1087.003 Email Account |
MalwareGrandoreiro | Grandoreiro can parse Outlook .pst files to extract e-mail addresses. |
| T1102.001 Dead Drop Resolver |
MalwareGrandoreiro | Grandoreiro can obtain C2 information from Google Docs. |
| T1102.002 Bidirectional Communication |
MalwareGrandoreiro | Grandoreiro can utilize web services including Google sites to send and receive C2 data. |
| T1105 Ingress Tool Transfer |
MalwareGrandoreiro | Grandoreiro can download its second stage from a hardcoded URL within the loader's code. |
| T1106 Native API |
MalwareGrandoreiro | Grandoreiro can execute through the |
| T1112 Modify Registry |
MalwareGrandoreiro | Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including |
| T1115 Clipboard Data |
MalwareGrandoreiro | Grandoreiro can capture clipboard data from a compromised host. |
| T1124 System Time Discovery |
MalwareGrandoreiro | Grandoreiro can determine the time on the victim machine via IPinfo. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGrandoreiro | Grandoreiro can decrypt its encrypted internal strings. |
| T1176.001 Browser Extensions |
MalwareGrandoreiro | Grandoreiro can use malicious browser extensions to steal cookies and other user information. |
| T1185 Browser Session Hijacking |
MalwareGrandoreiro | Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1189 Drive-by Compromise |
MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| T1204.001 Malicious Link |
MalwareGrandoreiro | Grandoreiro has used malicious links to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareGrandoreiro | Grandoreiro has infected victims via malicious attachments. |
| T1218.007 Msiexec |
MalwareGrandoreiro | Grandoreiro can use MSI files to execute DLLs. |
| T1222.001 Windows Permissions |
MalwareGrandoreiro | Grandoreiro can modify the binary ACL to prevent security tools from running. |
| T1497.001 System Checks |
MalwareGrandoreiro | Grandoreiro can detect VMWare via its I/O port and Virtual PC via the |
| T1518.001 Security Software Discovery |
MalwareGrandoreiro | Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections. |
| T1539 Steal Web Session Cookie |
MalwareGrandoreiro | Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrandoreiro | Grandoreiro can use run keys and create link files in the startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareGrandoreiro | Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions. |
| T1548.002 Bypass User Account Control |
MalwareGrandoreiro | Grandoreiro can bypass UAC by registering as the default handler for .MSC files. |
| T1555.003 Credentials from Web Browsers |
MalwareGrandoreiro | Grandoreiro can steal cookie data and credentials from Google Chrome. |
| T1566.002 Spearphishing Link |
MalwareGrandoreiro | Grandoreiro has been spread via malicious links embedded in e-mails. |
| T1568.002 Domain Generation Algorithms |
MalwareGrandoreiro | Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily. |
| T1573.002 Asymmetric Cryptography |
MalwareGrandoreiro | Grandoreiro can use SSL in C2 communication. |
| T1685 Disable or Modify Tools |
MalwareGrandoreiro | Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running. |
| T1686 Disable or Modify System Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686.002 Network Device Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.