ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0622×

32 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareAppleSeed

AppleSeed can collect data on a compromised host.

T1008
Fallback Channels
MalwareAppleSeed

AppleSeed can use a second channel for C2 when the primary channel is in upload mode.

T1016
System Network Configuration Discovery
MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

T1025
Data from Removable Media
MalwareAppleSeed

AppleSeed can find and collect data from removable media devices.

T1027
Obfuscated Files or Information
MalwareAppleSeed

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

T1027.002
Software Packing
MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

T1030
Data Transfer Size Limits
MalwareAppleSeed

AppleSeed has divided files if the size is 0x1000000 bytes or more.

T1036
Masquerading
MalwareAppleSeed

AppleSeed can disguise JavaScript files as PDFs.

T1036.005
Match Legitimate Resource Name or Location
MalwareAppleSeed

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

T1041
Exfiltration Over C2 Channel
MalwareAppleSeed

AppleSeed can exfiltrate files via the C2 channel.

T1056.001
Keylogging
MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1057
Process Discovery
MalwareAppleSeed

AppleSeed can enumerate the current process on a compromised host.

T1059.001
PowerShell
MalwareAppleSeed

AppleSeed has the ability to execute its payload via PowerShell.

T1059.007
JavaScript
MalwareAppleSeed

AppleSeed has the ability to use JavaScript to execute PowerShell.

T1070.004
File Deletion
MalwareAppleSeed

AppleSeed can delete files from a compromised host after they are exfiltrated.

T1071.001
Web Protocols
MalwareAppleSeed

AppleSeed has the ability to communicate with C2 over HTTP.

T1074.001
Local Data Staging
MalwareAppleSeed

AppleSeed can stage files in a central location prior to exfiltration.

T1082
System Information Discovery
MalwareAppleSeed

AppleSeed can identify the OS version of a targeted system.

T1083
File and Directory Discovery
MalwareAppleSeed

AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories.

T1106
Native API
MalwareAppleSeed

AppleSeed has the ability to use multiple dynamically resolved API calls.

T1113
Screen Capture
MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

T1119
Automated Collection
MalwareAppleSeed

AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration.

T1124
System Time Discovery
MalwareAppleSeed

AppleSeed can pull a timestamp from the victim's machine.

T1134
Access Token Manipulation
MalwareAppleSeed

AppleSeed can gain system level privilege by passing SeDebugPrivilege to the AdjustTokenPrivilege API.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleSeed

AppleSeed can decode its payload prior to execution.

T1204.002
Malicious File
MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

T1218.010
Regsvr32
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

T1560
Archive Collected Data
MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

T1560.001
Archive via Utility
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

T1566.001
Spearphishing Attachment
MalwareAppleSeed

AppleSeed has been distributed to victims through malicious e-mail attachments.

T1567
Exfiltration Over Web Service
MalwareAppleSeed

AppleSeed has exfiltrated files using web services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.