Real-world descriptions of how a group, tool or campaign used a technique.
71 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareQakBot | QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated. |
| T1010 Application Window Discovery |
MalwareQakBot | QakBot has the ability to enumerate windows on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1016.001 Internet Connection Discovery |
MalwareQakBot | QakBot can measure the download speed on a targeted host. |
| T1018 Remote System Discovery |
MalwareQakBot | QakBot can identify remote systems through the |
| T1027 Obfuscated Files or Information |
MalwareQakBot | QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells. |
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1027.002 Software Packing |
MalwareQakBot | QakBot can encrypt and pack malicious payloads. |
| T1027.005 Indicator Removal from Tools |
MalwareQakBot | QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.006 HTML Smuggling |
MalwareQakBot | QakBot has been delivered in ZIP files via HTML smuggling. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1027.011 Fileless Storage |
MalwareQakBot | QakBot can store its configuration information in a randomly named subkey under |
| T1033 System Owner/User Discovery |
MalwareQakBot | QakBot can identify the user name on a compromised system. |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1041 Exfiltration Over C2 Channel |
MalwareQakBot | QakBot can send stolen information to C2 nodes including passwords, accounts, and emails. |
| T1047 Windows Management Instrumentation |
MalwareQakBot | QakBot can execute WMI queries to gather information. |
| T1049 System Network Connections Discovery |
MalwareQakBot | QakBot can use |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1055.012 Process Hollowing |
MalwareQakBot | QakBot can use process hollowing to execute its main payload. |
| T1056.001 Keylogging |
MalwareQakBot | QakBot can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareQakBot | QakBot has the ability to check running processes. |
| T1059.001 PowerShell |
MalwareQakBot | QakBot can use PowerShell to download and execute payloads. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1059.007 JavaScript |
MalwareQakBot | The QakBot web inject module can inject Java Script into web banking pages visited by the victim. |
| T1069.001 Local Groups |
MalwareQakBot | QakBot can use |
| T1070.004 File Deletion |
MalwareQakBot | QakBot can delete folders and files including overwriting its executable with legitimate programs. |
| T1071.001 Web Protocols |
MalwareQakBot | QakBot has the ability to use HTTP and HTTPS in communication with C2 servers. |
| T1074.001 Local Data Staging |
MalwareQakBot | QakBot has stored stolen emails and other data into new folders prior to exfiltration. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1083 File and Directory Discovery |
MalwareQakBot | QakBot can identify whether it has been run previously on a host by checking for a specified folder. |
| T1090.002 External Proxy |
MalwareQakBot | QakBot has a module that can proxy C2 communications. |
| T1091 Replication Through Removable Media |
MalwareQakBot | QakBot has the ability to use removable drives to spread through compromised networks. |
| T1095 Non-Application Layer Protocol |
MalwareQakBot | QakBot has the ability use TCP to send or receive C2 packets. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1106 Native API |
MalwareQakBot | QakBot can use |
| T1110 Brute Force |
MalwareQakBot | QakBot can conduct brute force attacks to capture credentials. |
| T1112 Modify Registry |
MalwareQakBot | QakBot can modify the Registry to store its configuration information in a randomly named subkey under |
| T1114.001 Local Email Collection |
MalwareQakBot | QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns. |
| T1120 Peripheral Device Discovery |
MalwareQakBot | QakBot can identify peripheral devices on targeted systems. |
| T1124 System Time Discovery |
MalwareQakBot | QakBot can identify the system time on a targeted host. |
| T1132.001 Standard Encoding |
MalwareQakBot | QakBot can Base64 encode system information sent to C2. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQakBot | QakBot can deobfuscate and re-assemble code strings for execution. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1210 Exploitation of Remote Services |
MalwareQakBot | QakBot can move laterally using worm-like functionality through exploitation of SMB. |
| T1218.007 Msiexec |
MalwareQakBot | QakBot can use MSIExec to spawn multiple cmd.exe processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.