ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0670×

30 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareWarzoneRAT

WarzoneRAT can collect data from a compromised host.

T1014
Rootkit
MalwareWarzoneRAT

WarzoneRAT can include a rootkit to hide processes, files, and startup.

T1021.001
Remote Desktop Protocol
MalwareWarzoneRAT

WarzoneRAT has the ability to control an infected PC using RDP.

T1021.005
VNC
MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a VNC console.

T1041
Exfiltration Over C2 Channel
MalwareWarzoneRAT

WarzoneRAT can send collected victim data to its C2 server.

T1055
Process Injection
MalwareWarzoneRAT

WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation.

T1056.001
Keylogging
MalwareWarzoneRAT

WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API.

T1057
Process Discovery
MalwareWarzoneRAT

WarzoneRAT can obtain a list of processes on a compromised host.

T1059.001
PowerShell
MalwareWarzoneRAT

WarzoneRAT can use PowerShell to download files and execute commands.

T1059.003
Windows Command Shell
MalwareWarzoneRAT

WarzoneRAT can use `cmd.exe` to execute malicious code.

T1082
System Information Discovery
MalwareWarzoneRAT

WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details.

T1083
File and Directory Discovery
MalwareWarzoneRAT

WarzoneRAT can enumerate directories on a compromise host.

T1090
Proxy
MalwareWarzoneRAT

WarzoneRAT has the capability to act as a reverse proxy.

T1095
Non-Application Layer Protocol
MalwareWarzoneRAT

WarzoneRAT can communicate with its C2 server via TCP over port 5200.

T1105
Ingress Tool Transfer
MalwareWarzoneRAT

WarzoneRAT can download and execute additional files.

T1106
Native API
MalwareWarzoneRAT

WarzoneRAT can use a variety of API calls on a compromised host.

T1112
Modify Registry
MalwareWarzoneRAT

WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation.

T1125
Video Capture
MalwareWarzoneRAT

WarzoneRAT can access the webcam on a victim's machine.

T1140
Deobfuscate/Decode Files or Information
MalwareWarzoneRAT

WarzoneRAT can use XOR 0x45 to decrypt obfuscated code.

T1204.002
Malicious File
MalwareWarzoneRAT

WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution.

T1221
Template Injection
MalwareWarzoneRAT

WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document.

T1546.015
Component Object Model Hijacking
MalwareWarzoneRAT

WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter.

T1547.001
Registry Run Keys / Startup Folder
MalwareWarzoneRAT

WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys.

T1548.002
Bypass User Account Control
MalwareWarzoneRAT

WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module.

T1555.003
Credentials from Web Browsers
MalwareWarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.

T1564
Hide Artifacts
MalwareWarzoneRAT

WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`.

T1564.003
Hidden Window
MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility.

T1566.001
Spearphishing Attachment
MalwareWarzoneRAT

WarzoneRAT has been distributed as a malicious attachment within an email.

T1573.001
Symmetric Cryptography
MalwareWarzoneRAT

WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`.

T1685
Disable or Modify Tools
MalwareWarzoneRAT

WarzoneRAT can disarm Windows Defender during the UAC process to evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.