ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1090×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareNightClub

NightClub can use a file monitor to steal specific files from targeted systems.

T1010
Application Window Discovery
MalwareNightClub

NightClub can use `GetForegroundWindow` to enumerate the active window.

T1027
Obfuscated Files or Information
MalwareNightClub

NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`.

T1036.004
Masquerade Task or Service
MalwareNightClub

NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service.

T1036.005
Match Legitimate Resource Name or Location
MalwareNightClub

NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper.

T1041
Exfiltration Over C2 Channel
MalwareNightClub

NightClub can use SMTP and DNS for file exfiltration and C2.

T1056.001
Keylogging
MalwareNightClub

NightClub can use a plugin for keylogging.

T1057
Process Discovery
MalwareNightClub

NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window.

T1070.006
Timestomp
MalwareNightClub

NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll.

T1071.003
Mail Protocols
MalwareNightClub

NightClub can use emails for C2 communications.

T1071.004
DNS
MalwareNightClub

NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request.

T1074.001
Local Data Staging
MalwareNightClub

NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts.

T1083
File and Directory Discovery
MalwareNightClub

NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files.

T1105
Ingress Tool Transfer
MalwareNightClub

NightClub can load multiple additional plugins on an infected host.

T1106
Native API
MalwareNightClub

NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`.

T1112
Modify Registry
MalwareNightClub

NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.

T1113
Screen Capture
MalwareNightClub

NightClub can load a module to call `CreateCompatibleDC` and `GdipSaveImageToStream` for screen capture.

T1120
Peripheral Device Discovery
MalwareNightClub

NightClub has the ability to monitor removable drives.

T1123
Audio Capture
MalwareNightClub

NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio.

T1132.002
Non-Standard Encoding
MalwareNightClub

NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`.

T1543.003
Windows Service
MalwareNightClub

NightClub has created a Windows service named `WmdmPmSp` to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.