Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRaccoon Stealer | Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes. |
| T1012 Query Registry |
MalwareRaccoon Stealer | Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1027.007 Dynamic API Resolution |
MalwareRaccoon Stealer | Raccoon Stealer dynamically links key WinApi functions during execution. |
| T1027.013 Encrypted/Encoded File |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1041 Exfiltration Over C2 Channel |
MalwareRaccoon Stealer | Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1070.004 File Deletion |
MalwareRaccoon Stealer | Raccoon Stealer can remove files related to use and installation. |
| T1071.001 Web Protocols |
MalwareRaccoon Stealer | Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions. |
| T1082 System Information Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information. |
| T1083 File and Directory Discovery |
MalwareRaccoon Stealer | Raccoon Stealer identifies target files and directories for collection based on a configuration file. |
| T1087.001 Local Account |
MalwareRaccoon Stealer | Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`. |
| T1105 Ingress Tool Transfer |
MalwareRaccoon Stealer | Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft. |
| T1113 Screen Capture |
MalwareRaccoon Stealer | Raccoon Stealer can capture screenshots from victim systems. |
| T1119 Automated Collection |
MalwareRaccoon Stealer | Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers. |
| T1124 System Time Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers victim machine timezone information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4-encrypted, base64-encoded strings to obfuscate functionality and command and control servers. |
| T1195 Supply Chain Compromise |
MalwareRaccoon Stealer | Raccoon Stealer has been distributed through cracked software downloads. |
| T1213 Data from Information Repositories |
MalwareRaccoon Stealer | Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service. |
| T1518 Software Discovery |
MalwareRaccoon Stealer | Raccoon Stealer is capable of identifying running software on victim machines. |
| T1539 Steal Web Session Cookie |
MalwareRaccoon Stealer | Raccoon Stealer attempts to steal cookies and related information in browser history. |
| T1555.003 Credentials from Web Browsers |
MalwareRaccoon Stealer | Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers. |
| T1560 Archive Collected Data |
MalwareRaccoon Stealer | Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration. |
| T1614 System Location Discovery |
MalwareRaccoon Stealer | Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.