Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareLatrodectus | Latrodectus can collect data from a compromised host using a stealer module. |
| T1016 System Network Configuration Discovery |
MalwareLatrodectus | Latrodectus can discover the IP and MAC address of a targeted host. |
| T1021.005 VNC |
MalwareLatrodectus | Latrodectus has routed C2 traffic using Keyhole VNC. |
| T1027.001 Binary Padding |
MalwareLatrodectus | Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.002 Software Packing |
MalwareLatrodectus | The Latrodectus payload has been packed for obfuscation. |
| T1027.007 Dynamic API Resolution |
MalwareLatrodectus | Latrodectus can resolve Windows APIs dynamically by hash. |
| T1027.013 Encrypted/Encoded File |
MalwareLatrodectus | Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1033 System Owner/User Discovery |
MalwareLatrodectus | Latrodectus can discover the username of an infected host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLatrodectus | Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS. |
| T1041 Exfiltration Over C2 Channel |
MalwareLatrodectus | Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1047 Windows Management Instrumentation |
MalwareLatrodectus | Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1053.005 Scheduled Task |
MalwareLatrodectus | Latrodectus can create scheduled tasks for persistence. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1059.003 Windows Command Shell |
MalwareLatrodectus | The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.007 JavaScript |
MalwareLatrodectus | Latrodectus has used JavaScript files as part its infection chain during malicious spam |
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1070.004 File Deletion |
MalwareLatrodectus | Latrodectus has the ability to delete itself. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1082 System Information Discovery |
MalwareLatrodectus | Latrodectus can gather operating system information. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1087.002 Domain Account |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts. |
| T1102 Web Service |
MalwareLatrodectus | Latrodectus has used Google Firebase to download malicious installation scripts. |
| T1104 Multi-Stage Channels |
MalwareLatrodectus | Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareLatrodectus | Latrodectus can download and execute PEs, DLLs, and shellcode from C2. |
| T1106 Native API |
MalwareLatrodectus | Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`. |
| T1132.001 Standard Encoding |
MalwareLatrodectus | Latrodectus has Base64-encoded the message body of a HTTP request sent to C2. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1204.001 Malicious Link |
MalwareLatrodectus | Latrodectus has been executed through malicious links distributed in email campaigns. |
| T1204.002 Malicious File |
MalwareLatrodectus | Latrodectus has lured users into opening malicious email attachments for execution. |
| T1218.007 Msiexec |
MalwareLatrodectus | Latrodectus has called `msiexec` to install remotely-hosted MSI files. |
| T1218.011 Rundll32 |
MalwareLatrodectus | Latrodectus can use rundll32.exe to execute downloaded DLLs. |
| T1482 Domain Trust Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts. |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1518.001 Security Software Discovery |
MalwareLatrodectus | Latrodectus has the ability to identify installed antivirus products. |
| T1529 System Shutdown/Reboot |
MalwareLatrodectus | Latrodectus has the ability to restart compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLatrodectus | Latrodectus can set an AutoRun key to establish persistence. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1564.004 NTFS File Attributes |
MalwareLatrodectus | Latrodectus can delete itself while its process is still running through the use of an alternate data stream. |
| T1566.001 Spearphishing Attachment |
MalwareLatrodectus | Latrodectus has been distributed through reply-chain phishing emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareLatrodectus | Latrodectus has been distributed to victims through emails containing malicious links. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
| T1622 Debugger Evasion |
MalwareLatrodectus | Latrodectus has the ability to check for the presence of debuggers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.