Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareNightClub | NightClub can use a file monitor to steal specific files from targeted systems. |
| T1010 Application Window Discovery |
MalwareNightClub | NightClub can use `GetForegroundWindow` to enumerate the active window. |
| T1027 Obfuscated Files or Information |
MalwareNightClub | NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1036.004 Masquerade Task or Service |
MalwareNightClub | NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNightClub | NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper. |
| T1041 Exfiltration Over C2 Channel |
MalwareNightClub | NightClub can use SMTP and DNS for file exfiltration and C2. |
| T1056.001 Keylogging |
MalwareNightClub | NightClub can use a plugin for keylogging. |
| T1057 Process Discovery |
MalwareNightClub | NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window. |
| T1070.006 Timestomp |
MalwareNightClub | NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll. |
| T1071.003 Mail Protocols |
MalwareNightClub | NightClub can use emails for C2 communications. |
| T1071.004 DNS |
MalwareNightClub | NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request. |
| T1074.001 Local Data Staging |
MalwareNightClub | NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts. |
| T1083 File and Directory Discovery |
MalwareNightClub | NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1105 Ingress Tool Transfer |
MalwareNightClub | NightClub can load multiple additional plugins on an infected host. |
| T1106 Native API |
MalwareNightClub | NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`. |
| T1112 Modify Registry |
MalwareNightClub | NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence. |
| T1113 Screen Capture |
MalwareNightClub | NightClub can load a module to call `CreateCompatibleDC` and `GdipSaveImageToStream` for screen capture. |
| T1120 Peripheral Device Discovery |
MalwareNightClub | NightClub has the ability to monitor removable drives. |
| T1123 Audio Capture |
MalwareNightClub | NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio. |
| T1132.002 Non-Standard Encoding |
MalwareNightClub | NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`. |
| T1543.003 Windows Service |
MalwareNightClub | NightClub has created a Windows service named `WmdmPmSp` to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.