Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwareSMOKEDHAM | The SMOKEDHAM source code is embedded in the dropper as an encrypted string. |
| T1033 System Owner/User Discovery |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1041 Exfiltration Over C2 Channel |
MalwareSMOKEDHAM | SMOKEDHAM has exfiltrated data to its C2 server. |
| T1056.001 Keylogging |
MalwareSMOKEDHAM | SMOKEDHAM can continuously capture keystrokes. |
| T1059.001 PowerShell |
MalwareSMOKEDHAM | SMOKEDHAM can execute Powershell commands sent from its C2 server. |
| T1071.001 Web Protocols |
MalwareSMOKEDHAM | SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests. |
| T1082 System Information Discovery |
MalwareSMOKEDHAM | SMOKEDHAM has used the |
| T1087.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1090.004 Domain Fronting |
MalwareSMOKEDHAM | SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain. |
| T1098.007 Additional Local or Domain Groups |
MalwareSMOKEDHAM | SMOKEDHAM has added user accounts to local Admin groups. |
| T1102 Web Service |
MalwareSMOKEDHAM | SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1105 Ingress Tool Transfer |
MalwareSMOKEDHAM | SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites. |
| T1112 Modify Registry |
MalwareSMOKEDHAM | SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP. |
| T1113 Screen Capture |
MalwareSMOKEDHAM | SMOKEDHAM can capture screenshots of the victim’s desktop. |
| T1132.001 Standard Encoding |
MalwareSMOKEDHAM | SMOKEDHAM has encoded its C2 traffic with Base64. |
| T1136.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has created user accounts. |
| T1204.001 Malicious Link |
MalwareSMOKEDHAM | SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1564.002 Hidden Users |
MalwareSMOKEDHAM | SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen. |
| T1573.001 Symmetric Cryptography |
MalwareSMOKEDHAM | SMOKEDHAM has encrypted its C2 traffic with RC4. |
| T1598.003 Spearphishing Link |
MalwareSMOKEDHAM | SMOKEDHAM has been delivered via malicious links in phishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.