ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0652×

22 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMarkiRAT

MarkiRAT can upload data from the victim's machine to the C2 server.

T1033
System Owner/User Discovery
MalwareMarkiRAT

MarkiRAT can retrieve the victim’s username.

T1036.005
Match Legitimate Resource Name or Location
MalwareMarkiRAT

MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.

T1041
Exfiltration Over C2 Channel
MalwareMarkiRAT

MarkiRAT can exfiltrate locally stored data via its C2.

T1056.001
Keylogging
MalwareMarkiRAT

MarkiRAT can capture all keystrokes on a compromised host.

T1057
Process Discovery
MalwareMarkiRAT

MarkiRAT can search for different processes on a system.

T1059.003
Windows Command Shell
MalwareMarkiRAT

MarkiRAT can utilize cmd.exe to execute commands in a victim's environment.

T1071.001
Web Protocols
MalwareMarkiRAT

MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server.

T1074.001
Local Data Staging
MalwareMarkiRAT

MarkiRAT can store collected data locally in a created .nfo file.

T1082
System Information Discovery
MalwareMarkiRAT

MarkiRAT can obtain the computer name from a compromised host.

T1083
File and Directory Discovery
MalwareMarkiRAT

MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb.

T1105
Ingress Tool Transfer
MalwareMarkiRAT

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.

T1106
Native API
MalwareMarkiRAT

MarkiRAT can run the ShellExecuteW API via the Windows Command Shell.

T1113
Screen Capture
MalwareMarkiRAT

MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’.

T1115
Clipboard Data
MalwareMarkiRAT

MarkiRAT can capture clipboard content.

T1197
BITS Jobs
MalwareMarkiRAT

MarkiRAT can use BITS Utility to connect with the C2 server.

T1518
Software Discovery
MalwareMarkiRAT

MarkiRAT can check for the Telegram installation directory by enumerating the files on disk.

T1518.001
Security Software Discovery
MalwareMarkiRAT

MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareMarkiRAT

MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started.

T1547.009
Shortcut Modification
MalwareMarkiRAT

MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable.

T1555.005
Password Managers
MalwareMarkiRAT

MarkiRAT can gather information from the Keepass password manager.

T1614.001
System Language Discovery
MalwareMarkiRAT

MarkiRAT can use the GetKeyboardLayout API to check if a compromised host's keyboard is set to Persian.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.