Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareKOCTOPUS | KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKOCTOPUS | KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries. |
| T1059.001 PowerShell |
MalwareKOCTOPUS | KOCTOPUS has used PowerShell commands to download additional files. |
| T1059.003 Windows Command Shell |
MalwareKOCTOPUS | KOCTOPUS has used `cmd.exe` and batch files for execution. |
| T1059.005 Visual Basic |
MalwareKOCTOPUS | KOCTOPUS has used VBScript to call wscript to execute a PowerShell command. |
| T1070.009 Clear Persistence |
MalwareKOCTOPUS | KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
| T1082 System Information Discovery |
MalwareKOCTOPUS | KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command. |
| T1090 Proxy |
MalwareKOCTOPUS | KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1105 Ingress Tool Transfer |
MalwareKOCTOPUS | KOCTOPUS has executed a PowerShell command to download a file to the system. |
| T1106 Native API |
MalwareKOCTOPUS | KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution. |
| T1112 Modify Registry |
MalwareKOCTOPUS | KOCTOPUS has added and deleted keys from the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKOCTOPUS | KOCTOPUS has deobfuscated itself before executing its commands. |
| T1204.001 Malicious Link |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking on a malicious link delivered via email. |
| T1204.002 Malicious File |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking a malicious document for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKOCTOPUS | KOCTOPUS can set the AutoRun Registry key with a PowerShell command. |
| T1548.002 Bypass User Account Control |
MalwareKOCTOPUS | KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe. |
| T1564.003 Hidden Window |
MalwareKOCTOPUS | KOCTOPUS has used |
| T1566.001 Spearphishing Attachment |
MalwareKOCTOPUS | KOCTOPUS has been distributed via spearphishing emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareKOCTOPUS | KOCTOPUS has been distributed as a malicious link within an email. |
| T1685 Disable or Modify Tools |
MalwareKOCTOPUS | KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.