Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFoggyWeb | FoggyWeb can retrieve configuration data from a compromised AD FS server. |
| T1027.004 Compile After Delivery |
MalwareFoggyWeb | FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST. |
| T1027.013 Encrypted/Encoded File |
MalwareFoggyWeb | FoggyWeb has been XOR-encoded. |
| T1036 Masquerading |
MalwareFoggyWeb | FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFoggyWeb | FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file. |
| T1040 Network Sniffing |
MalwareFoggyWeb | FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor. |
| T1041 Exfiltration Over C2 Channel |
MalwareFoggyWeb | FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server. |
| T1057 Process Discovery |
MalwareFoggyWeb | FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's |
| T1071.001 Web Protocols |
MalwareFoggyWeb | FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests. |
| T1083 File and Directory Discovery |
MalwareFoggyWeb | FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server. |
| T1105 Ingress Tool Transfer |
MalwareFoggyWeb | FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server. |
| T1106 Native API |
MalwareFoggyWeb | FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed. |
| T1129 Shared Modules |
MalwareFoggyWeb | FoggyWeb's loader can call the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFoggyWeb | FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key. |
| T1550 Use Alternate Authentication Material |
MalwareFoggyWeb | FoggyWeb can allow abuse of a compromised AD FS server's SAML token. |
| T1552.004 Private Keys |
MalwareFoggyWeb | FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server. |
| T1560.002 Archive via Library |
MalwareFoggyWeb | FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class. |
| T1560.003 Archive via Custom Method |
MalwareFoggyWeb | FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file. |
| T1573.001 Symmetric Cryptography |
MalwareFoggyWeb | FoggyWeb has used a dynamic XOR key and custom XOR methodology for C2 communications. |
| T1574.001 DLL |
MalwareFoggyWeb | FoggyWeb's loader has used DLL Search Order Hijacking to load malicious code instead of the legitimate `version.dll` during the `Microsoft.IdentityServer.ServiceHost.exe` execution process. |
| T1620 Reflective Code Loading |
MalwareFoggyWeb | FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.