Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareStrelaStealer | StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload. |
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027.002 Software Packing |
MalwareStrelaStealer | StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult. |
| T1027.013 Encrypted/Encoded File |
MalwareStrelaStealer | StrelaStealer uses XOR-encoded strings to obfuscate items. |
| T1027.015 Compression |
MalwareStrelaStealer | StrelaStealer has been delivered via JScript files in a ZIP archive. |
| T1027.016 Junk Code Insertion |
MalwareStrelaStealer | StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1036 Masquerading |
MalwareStrelaStealer | StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`. |
| T1036.003 Rename Legitimate Utilities |
MalwareStrelaStealer | StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrelaStealer | StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1059.001 PowerShell |
MalwareStrelaStealer | StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation. |
| T1059.003 Windows Command Shell |
MalwareStrelaStealer | StrelaStealer has included BAT files in some instances for installation. |
| T1059.007 JavaScript |
MalwareStrelaStealer | StrelaStealer has been distributed as a malicious JavaScript object. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1082 System Information Discovery |
MalwareStrelaStealer | StrelaStealer variants collect victim system information for exfiltration. |
| T1105 Ingress Tool Transfer |
MalwareStrelaStealer | StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers. |
| T1119 Automated Collection |
MalwareStrelaStealer | StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution. |
| T1132.001 Standard Encoding |
MalwareStrelaStealer | StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStrelaStealer | StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file. |
| T1204.002 Malicious File |
MalwareStrelaStealer | StrelaStealer relies on user execution of a malicious file for installation. |
| T1218.011 Rundll32 |
MalwareStrelaStealer | StrelaStealer DLL payloads have been executed via `rundll32.exe`. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1480.002 Mutual Exclusion |
MalwareStrelaStealer | StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStrelaStealer | StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods. |
| T1518 Software Discovery |
MalwareStrelaStealer | StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1553.002 Code Signing |
MalwareStrelaStealer | StrelaStealer variants have used valid code signing certificates. |
| T1566.001 Spearphishing Attachment |
MalwareStrelaStealer | StrelaStealer has been distributed as a spearphishing attachment. |
| T1574.001 DLL |
MalwareStrelaStealer | StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable. |
| T1614.001 System Language Discovery |
MalwareStrelaStealer | StrelaStealer variants check system language settings via keyboard layout or similar mechanisms. |
| T1622 Debugger Evasion |
MalwareStrelaStealer | StrelaStealer variants include functionality to identify and evade debuggers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.