Real-world descriptions of how a group, tool or campaign used a technique.
39 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBumblebee | Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1008 Fallback Channels |
MalwareBumblebee | Bumblebee can use backup C2 servers if the primary server fails. |
| T1012 Query Registry |
MalwareBumblebee | Bumblebee can check the Registry for specific keys. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1033 System Owner/User Discovery |
MalwareBumblebee | Bumblebee has the ability to identify the user name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBumblebee | Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer. |
| T1041 Exfiltration Over C2 Channel |
MalwareBumblebee | Bumblebee can send collected data in JSON format to C2. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1053.005 Scheduled Task |
MalwareBumblebee | Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task. |
| T1055 Process Injection |
MalwareBumblebee | Bumblebee can inject code into multiple processes on infected endpoints. |
| T1055.001 Dynamic-link Library Injection |
MalwareBumblebee | The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.004 Asynchronous Procedure Call |
MalwareBumblebee | Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2. |
| T1057 Process Discovery |
MalwareBumblebee | Bumblebee can identify processes associated with analytical tools. |
| T1059.001 PowerShell |
MalwareBumblebee | Bumblebee can use PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareBumblebee | Bumblebee can use `cmd.exe` to drop and run files. |
| T1059.005 Visual Basic |
MalwareBumblebee | Bumblebee can create a Visual Basic script to enable persistence. |
| T1070.004 File Deletion |
MalwareBumblebee | Bumblebee can uninstall its loader through the use of a `Sdl` command. |
| T1082 System Information Discovery |
MalwareBumblebee | Bumblebee can enumerate the OS version and domain on a targeted system. |
| T1102 Web Service |
MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1106 Native API |
MalwareBumblebee | Bumblebee can use multiple Native APIs. |
| T1129 Shared Modules |
MalwareBumblebee | Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll. |
| T1132.001 Standard Encoding |
MalwareBumblebee | Bumblebee has the ability to base64 encode C2 server responses. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBumblebee | Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts. |
| T1204.001 Malicious Link |
MalwareBumblebee | Bumblebee has relied upon a user downloading a file from a OneDrive link for execution. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1218.008 Odbcconf |
MalwareBumblebee | Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts. |
| T1218.011 Rundll32 |
MalwareBumblebee | Bumblebee has used `rundll32` for execution of the loader component. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBumblebee | Bumblebee has the ability to perform anti-virtualization checks. |
| T1497.001 System Checks |
MalwareBumblebee | Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products. |
| T1497.003 Time Based Checks |
MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| T1518.001 Security Software Discovery |
MalwareBumblebee | Bumblebee can identify specific analytical tools based on running processes. |
| T1548.002 Bypass User Account Control |
MalwareBumblebee | Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges. |
| T1559.001 Component Object Model |
MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| T1560 Archive Collected Data |
MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareBumblebee | Bumblebee has been spread through e-mail campaigns with malicious links. |
| T1573.001 Symmetric Cryptography |
MalwareBumblebee | Bumblebee can encrypt C2 requests and responses with RC4 |
| T1622 Debugger Evasion |
MalwareBumblebee | Bumblebee can search for tools used in static analysis. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.