Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCharmPower | CharmPower can collect data and files from a compromised host. |
| T1008 Fallback Channels |
MalwareCharmPower | CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket. |
| T1012 Query Registry |
MalwareCharmPower | CharmPower has the ability to enumerate `Uninstall` registry values. |
| T1016 System Network Configuration Discovery |
MalwareCharmPower | CharmPower has the ability to use |
| T1016.002 Wi-Fi Discovery |
MalwareCharmPower | CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details. |
| T1041 Exfiltration Over C2 Channel |
MalwareCharmPower | CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST. |
| T1047 Windows Management Instrumentation |
MalwareCharmPower | CharmPower can use `wmic` to gather information from a system. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCharmPower | CharmPower can send victim data via FTP with credentials hardcoded in the script. |
| T1057 Process Discovery |
MalwareCharmPower | CharmPower has the ability to list running processes through the use of `tasklist`. |
| T1059.001 PowerShell |
MalwareCharmPower | CharmPower can use PowerShell for payload execution and C2 communication. |
| T1059.003 Windows Command Shell |
MalwareCharmPower | The C# implementation of the CharmPower command execution module can use |
| T1070.004 File Deletion |
MalwareCharmPower | CharmPower can delete created files from a compromised system. |
| T1071.001 Web Protocols |
MalwareCharmPower | CharmPower can use HTTP to communicate with C2. |
| T1082 System Information Discovery |
MalwareCharmPower | CharmPower can enumerate the OS version and computer name on a targeted system. |
| T1083 File and Directory Discovery |
MalwareCharmPower | CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer. |
| T1102 Web Service |
MalwareCharmPower | CharmPower can download additional modules from actor-controlled Amazon S3 buckets. |
| T1102.001 Dead Drop Resolver |
MalwareCharmPower | CharmPower can retrieve C2 domain information from actor-controlled S3 buckets. |
| T1105 Ingress Tool Transfer |
MalwareCharmPower | CharmPower has the ability to download additional modules to a compromised host. |
| T1112 Modify Registry |
MalwareCharmPower | CharmPower can remove persistence-related artifacts from the Registry. |
| T1113 Screen Capture |
MalwareCharmPower | CharmPower has the ability to capture screenshots. |
| T1132.001 Standard Encoding |
MalwareCharmPower | CharmPower can send additional modules over C2 encoded with base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCharmPower | CharmPower can decrypt downloaded modules prior to execution. |
| T1518 Software Discovery |
MalwareCharmPower | CharmPower can list the installed applications on a compromised host. |
| T1573.001 Symmetric Cryptography |
MalwareCharmPower | CharmPower can send additional modules over C2 encrypted with a simple substitution cipher. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.