Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwarePenquin | Penquin can report the IP of the compromised host to attacker controlled infrastructure. |
| T1027.005 Indicator Removal from Tools |
MalwarePenquin | Penquin can remove strings from binaries. |
| T1027.013 Encrypted/Encoded File |
MalwarePenquin | Penquin has encrypted strings in the binary for obfuscation. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePenquin | Penquin has mimicked the Cron binary to hide itself on compromised systems. |
| T1040 Network Sniffing |
MalwarePenquin | Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1041 Exfiltration Over C2 Channel |
MalwarePenquin | Penquin can execute the command code |
| T1053.003 Cron |
MalwarePenquin | Penquin can use Cron to create periodic and pre-scheduled background jobs. |
| T1059.004 Unix Shell |
MalwarePenquin | Penquin can execute remote commands using bash scripts. |
| T1070.004 File Deletion |
MalwarePenquin | Penquin can delete downloaded executables after running them. |
| T1082 System Information Discovery |
MalwarePenquin | Penquin can report the file system type of a compromised host to C2. |
| T1083 File and Directory Discovery |
MalwarePenquin | Penquin can use the command code |
| T1095 Non-Application Layer Protocol |
MalwarePenquin | The Penquin C2 mechanism is based on TCP and UDP packets. |
| T1105 Ingress Tool Transfer |
MalwarePenquin | Penquin can execute the command code |
| T1205 Traffic Signaling |
MalwarePenquin | Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions. |
| T1205.002 Socket Filters |
MalwarePenquin | Penquin installs a `TCP` and `UDP` filter on the `eth0` interface. |
| T1222.002 Linux and Mac Permissions |
MalwarePenquin | Penquin can add the executable flag to a downloaded file. |
| T1573.002 Asymmetric Cryptography |
MalwarePenquin | Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman. |
| T1680 Local Storage Discovery |
MalwarePenquin | Penquin can report the disk space of a compromised host to C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.