Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareLunarMail | LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarMail | LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively. |
| T1041 Exfiltration Over C2 Channel |
MalwareLunarMail | LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration. |
| T1059.005 Visual Basic |
MalwareLunarMail | LunarMail has been installed using a VBA macro. |
| T1070.004 File Deletion |
MalwareLunarMail | LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one. |
| T1070.008 Clear Mailbox Data |
MalwareLunarMail | LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration. |
| T1071.003 Mail Protocols |
MalwareLunarMail | LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI). |
| T1074.001 Local Data Staging |
MalwareLunarMail | LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration. |
| T1082 System Information Discovery |
MalwareLunarMail | LunarMail can capture environmental variables on compromised hosts. |
| T1083 File and Directory Discovery |
MalwareLunarMail | LunarMail can search its staging directory for output files it has produced. |
| T1095 Non-Application Layer Protocol |
MalwareLunarMail | LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain. |
| T1113 Screen Capture |
MalwareLunarMail | LunarMail can capture screenshots from compromised hosts. |
| T1114.001 Local Email Collection |
MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| T1137.006 Add-ins |
MalwareLunarMail | LunarMail has the ability to use Outlook add-ins for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarMail | LunarMail can decrypt strings to retrieve configuration settings. |
| T1204.002 Malicious File |
MalwareLunarMail | LunarMail has been installed through a malicious macro in a Microsoft Word document. |
| T1543 Create or Modify System Process |
MalwareLunarMail | LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.