Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareDarkTortilla | DarkTortilla can retrieve information about a compromised system's running services. |
| T1016.001 Internet Connection Discovery |
MalwareDarkTortilla | DarkTortilla can check for internet connectivity by issuing HTTP GET requests. |
| T1027 Obfuscated Files or Information |
MalwareDarkTortilla | DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators. |
| T1036 Masquerading |
MalwareDarkTortilla | DarkTortilla's payload has been renamed `PowerShellInfo.exe`. |
| T1047 Windows Management Instrumentation |
MalwareDarkTortilla | DarkTortilla can use WMI queries to obtain system information. |
| T1055.001 Dynamic-link Library Injection |
MalwareDarkTortilla | DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection. |
| T1056.001 Keylogging |
MalwareDarkTortilla | DarkTortilla can download a keylogging module. |
| T1057 Process Discovery |
MalwareDarkTortilla | DarkTortilla can enumerate a list of running processes on a compromised system. |
| T1059.003 Windows Command Shell |
MalwareDarkTortilla | DarkTortilla can use `cmd.exe` to add registry keys for persistence. |
| T1071.001 Web Protocols |
MalwareDarkTortilla | DarkTortilla has used HTTP and HTTPS for C2. |
| T1082 System Information Discovery |
MalwareDarkTortilla | DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects. |
| T1102 Web Service |
MalwareDarkTortilla | DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin. |
| T1105 Ingress Tool Transfer |
MalwareDarkTortilla | DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit. |
| T1106 Native API |
MalwareDarkTortilla | DarkTortilla can use a variety of API calls for persistence and defense evasion. |
| T1112 Modify Registry |
MalwareDarkTortilla | DarkTortilla has modified registry keys for persistence. |
| T1115 Clipboard Data |
MalwareDarkTortilla | DarkTortilla can download a clipboard information stealer module. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkTortilla | DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher. |
| T1204.002 Malicious File |
MalwareDarkTortilla | DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution. |
| T1497.001 System Checks |
MalwareDarkTortilla | DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie. |
| T1497.003 Time Based Checks |
MalwareDarkTortilla | DarkTortilla can implement the `kernel32.dll` Sleep function to delay execution for up to 300 seconds before implementing persistence or processing an addon package. |
| T1518.001 Security Software Discovery |
MalwareDarkTortilla | DarkTortilla can check for the Kaspersky Anti-Virus suite. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder. |
| T1547.004 Winlogon Helper DLL |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key. |
| T1559.001 Component Object Model |
MalwareDarkTortilla | DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder. |
| T1564 Hide Artifacts |
MalwareDarkTortilla | DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry. |
| T1566.001 Spearphishing Attachment |
MalwareDarkTortilla | DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents. |
| T1574.012 COR_PROFILER |
MalwareDarkTortilla | DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
| T1622 Debugger Evasion |
MalwareDarkTortilla | DarkTortilla can detect debuggers by using functions such as `DebuggerIsAttached` and `DebuggerIsLogging`. DarkTortilla can also detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.