ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0673×

34 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDarkWatchman

DarkWatchman can collect files from a compromised host.

T1010
Application Window Discovery
MalwareDarkWatchman

DarkWatchman reports window names along with keylogger information to provide application context.

T1012
Query Registry
MalwareDarkWatchman

DarkWatchman can query the Registry to determine if it has already been installed on the system.

T1027.004
Compile After Delivery
MalwareDarkWatchman

DarkWatchman has used the csc.exe tool to compile a C# executable.

T1027.010
Command Obfuscation
MalwareDarkWatchman

DarkWatchman has used Base64 to encode PowerShell commands.

T1027.011
Fileless Storage
MalwareDarkWatchman

DarkWatchman can store configuration strings, keylogger, and output of components in the Registry.

T1027.015
Compression
MalwareDarkWatchman

DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims.

T1033
System Owner/User Discovery
MalwareDarkWatchman

DarkWatchman has collected the username from a victim machine.

T1036
Masquerading
MalwareDarkWatchman

DarkWatchman has used an icon mimicking a text file to mask a malicious executable.

T1047
Windows Management Instrumentation
MalwareDarkWatchman

DarkWatchman can use WMI to execute commands.

T1053.005
Scheduled Task
MalwareDarkWatchman

DarkWatchman has created a scheduled task for persistence.

T1056.001
Keylogging
MalwareDarkWatchman

DarkWatchman can track key presses with a keylogger module.

T1059.001
PowerShell
MalwareDarkWatchman

DarkWatchman can execute PowerShell commands and has used PowerShell to execute a keylogger.

T1059.003
Windows Command Shell
MalwareDarkWatchman

DarkWatchman can use `cmd.exe` to execute commands.

T1059.007
JavaScript
MalwareDarkWatchman

DarkWatchman uses JavaScript to perform its core functionalities.

T1070
Indicator Removal
MalwareDarkWatchman

DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.

T1070.004
File Deletion
MalwareDarkWatchman

DarkWatchman has been observed deleting its original launcher after installation.

T1071.001
Web Protocols
MalwareDarkWatchman

DarkWatchman uses HTTPS for command and control.

T1074.001
Local Data Staging
MalwareDarkWatchman

DarkWatchman can stage local data in the Windows Registry.

T1082
System Information Discovery
MalwareDarkWatchman

DarkWatchman can collect the OS version, system architecture, and computer name.

T1083
File and Directory Discovery
MalwareDarkWatchman

DarkWatchman has the ability to enumerate file and folder names.

T1112
Modify Registry
MalwareDarkWatchman

DarkWatchman can modify Registry values to store configuration strings, keylogger, and output of components.

T1120
Peripheral Device Discovery
MalwareDarkWatchman

DarkWatchman can list signed PnP drivers for smartcard readers.

T1124
System Time Discovery
MalwareDarkWatchman

DarkWatchman can collect time zone information and system `UPTIME`.

T1129
Shared Modules
MalwareDarkWatchman

DarkWatchman can load DLLs.

T1132.001
Standard Encoding
MalwareDarkWatchman

DarkWatchman encodes data using hexadecimal representation before sending it to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareDarkWatchman

DarkWatchman has the ability to self-extract as a RAR archive.

T1217
Browser Information Discovery
MalwareDarkWatchman

DarkWatchman can retrieve browser history.

T1490
Inhibit System Recovery
MalwareDarkWatchman

DarkWatchman can delete shadow volumes using vssadmin.exe.

T1518.001
Security Software Discovery
MalwareDarkWatchman

DarkWatchman can search for anti-virus products on the system.

T1566.001
Spearphishing Attachment
MalwareDarkWatchman

DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file.

T1568.002
Domain Generation Algorithms
MalwareDarkWatchman

DarkWatchman has used a DGA to generate a domain name for C2.

T1573.002
Asymmetric Cryptography
MalwareDarkWatchman

DarkWatchman can use TLS to encrypt its C2 channel.

T1614
System Location Discovery
MalwareDarkWatchman

DarkWatchman can identity the OS locale of a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.