Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMarkiRAT | MarkiRAT can upload data from the victim's machine to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareMarkiRAT | MarkiRAT can retrieve the victim’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMarkiRAT | MarkiRAT can masquerade as |
| T1041 Exfiltration Over C2 Channel |
MalwareMarkiRAT | MarkiRAT can exfiltrate locally stored data via its C2. |
| T1056.001 Keylogging |
MalwareMarkiRAT | MarkiRAT can capture all keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareMarkiRAT | MarkiRAT can search for different processes on a system. |
| T1059.003 Windows Command Shell |
MalwareMarkiRAT | MarkiRAT can utilize cmd.exe to execute commands in a victim's environment. |
| T1071.001 Web Protocols |
MalwareMarkiRAT | MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server. |
| T1074.001 Local Data Staging |
MalwareMarkiRAT | MarkiRAT can store collected data locally in a created .nfo file. |
| T1082 System Information Discovery |
MalwareMarkiRAT | MarkiRAT can obtain the computer name from a compromised host. |
| T1083 File and Directory Discovery |
MalwareMarkiRAT | MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb. |
| T1105 Ingress Tool Transfer |
MalwareMarkiRAT | MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin. |
| T1106 Native API |
MalwareMarkiRAT | MarkiRAT can run the ShellExecuteW API via the Windows Command Shell. |
| T1113 Screen Capture |
MalwareMarkiRAT | MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’. |
| T1115 Clipboard Data |
MalwareMarkiRAT | MarkiRAT can capture clipboard content. |
| T1197 BITS Jobs |
MalwareMarkiRAT | MarkiRAT can use BITS Utility to connect with the C2 server. |
| T1518 Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for the Telegram installation directory by enumerating the files on disk. |
| T1518.001 Security Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMarkiRAT | MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started. |
| T1547.009 Shortcut Modification |
MalwareMarkiRAT | MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable. |
| T1555.005 Password Managers |
MalwareMarkiRAT | MarkiRAT can gather information from the Keepass password manager. |
| T1614.001 System Language Discovery |
MalwareMarkiRAT | MarkiRAT can use the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.