Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.011 Fileless Storage |
MalwareChaes | Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| T1033 System Owner/User Discovery |
MalwareChaes | Chaes has collected the username and UID from the infected machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChaes | Chaes has used an unsigned, crafted DLL module named |
| T1048 Exfiltration Over Alternative Protocol |
MalwareChaes | Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol. |
| T1056 Input Capture |
MalwareChaes | Chaes has a module to perform any API hooking it desires. |
| T1059.003 Windows Command Shell |
MalwareChaes | |
| T1059.005 Visual Basic |
MalwareChaes | Chaes has used VBscript to execute malicious code. |
| T1059.006 Python |
MalwareChaes | Chaes has used Python scripts for execution and the installation of additional files. |
| T1059.007 JavaScript |
MalwareChaes | Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process. |
| T1071.001 Web Protocols |
MalwareChaes | Chaes has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareChaes | Chaes has collected system information, including the machine name and OS version. |
| T1105 Ingress Tool Transfer |
MalwareChaes | Chaes can download additional files onto an infected machine. |
| T1106 Native API |
MalwareChaes | Chaes used the |
| T1112 Modify Registry |
MalwareChaes | Chaes can modify Registry values to stored information and establish persistence. |
| T1113 Screen Capture |
MalwareChaes | Chaes can capture screenshots of the infected machine. |
| T1132.001 Standard Encoding |
MalwareChaes | Chaes has used Base64 to encode C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChaes | Chaes has decrypted an AES encrypted binary file to trigger the download of other files. |
| T1185 Browser Session Hijacking |
MalwareChaes | Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts. |
| T1204.002 Malicious File |
MalwareChaes | Chaes requires the user to click on the malicious Word document to execute the next part of the attack. |
| T1218.004 InstallUtil |
MalwareChaes | Chaes has used Installutill to download content. |
| T1218.007 Msiexec |
MalwareChaes | Chaes has used .MSI files as an initial way to start the infection chain. |
| T1221 Template Injection |
MalwareChaes | Chaes changed the template target of the settings.xml file embedded in the Word document and populated that field with the downloaded URL of the next payload. |
| T1539 Steal Web Session Cookie |
MalwareChaes | Chaes has used a script that extracts the web session cookie and sends it to the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChaes | Chaes has added persistence via the Registry key |
| T1555.003 Credentials from Web Browsers |
MalwareChaes | Chaes can steal login credentials and stored financial information from the browser. |
| T1566.001 Spearphishing Attachment |
MalwareChaes | Chaes has been delivered by sending victims a phishing email containing a malicious .docx file. |
| T1573 Encrypted Channel |
MalwareChaes | Chaes has used encryption for its C2 channel. |
| T1574.001 DLL |
MalwareChaes | Chaes has used search order hijacking to load a malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.