Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareMgBot | MgBot includes modules for dumping and capturing credentials from process memory. |
| T1005 Data from Local System |
MalwareMgBot | MgBot includes modules for collecting files from local systems based on a given set of properties and filenames. |
| T1018 Remote System Discovery |
MalwareMgBot | MgBot includes modules for performing ARP scans of local connected systems. |
| T1025 Data from Removable Media |
MalwareMgBot | MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria. |
| T1033 System Owner/User Discovery |
MalwareMgBot | MgBot includes modules for identifying local users and administrators on victim machines. |
| T1046 Network Service Discovery |
MalwareMgBot | MgBot includes modules for performing HTTP and server service scans. |
| T1056.001 Keylogging |
MalwareMgBot | MgBot includes keylogger payloads focused on the QQ chat application. |
| T1057 Process Discovery |
MalwareMgBot | MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running. |
| T1087.001 Local Account |
MalwareMgBot | MgBot includes modules for identifying local administrator accounts on victim systems. |
| T1087.002 Domain Account |
MalwareMgBot | MgBot includes modules for collecting information on Active Directory domain accounts. |
| T1115 Clipboard Data |
MalwareMgBot | MgBot can capture clipboard data. |
| T1123 Audio Capture |
MalwareMgBot | MgBot can capture input and output audio streams from infected devices. |
| T1213.006 Databases |
MalwareMgBot | MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices. |
| T1482 Domain Trust Discovery |
MalwareMgBot | MgBot includes modules for collecting information on local domain users and permissions. |
| T1539 Steal Web Session Cookie |
MalwareMgBot | MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers. |
| T1555 Credentials from Password Stores |
MalwareMgBot | MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.