Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareXLoader | XLoader uses various packers, including CyaX, to obfuscate malicious executables. |
| T1027.013 Encrypted/Encoded File |
MalwareXLoader | XLoader features encrypted functions using the RC4 algorithm and bytecode operations. |
| T1033 System Owner/User Discovery |
MalwareXLoader | XLoader can identify the username from a victim machine. |
| T1053.005 Scheduled Task |
MalwareXLoader | XLoader can create scheduled tasks for persistence. |
| T1055.004 Asynchronous Procedure Call |
MalwareXLoader | XLoader injects code into the APC queue using `NtQueueApcThread` API. |
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1056.001 Keylogging |
MalwareXLoader | XLoader can capture keystrokes from the victim machine. |
| T1059.010 AutoHotKey & AutoIT |
MalwareXLoader | XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine. |
| T1070.004 File Deletion |
MalwareXLoader | XLoader can delete malicious executables from compromised machines. |
| T1071.001 Web Protocols |
MalwareXLoader | XLoader uses HTTP and HTTPS for command and control communication. |
| T1082 System Information Discovery |
MalwareXLoader | XLoader can collect system information and supported language information from the victim machine. |
| T1106 Native API |
MalwareXLoader | XLoader uses the native Windows API for functionality, including defense evasion. |
| T1113 Screen Capture |
MalwareXLoader | XLoader can capture screenshots on compromised hosts. |
| T1115 Clipboard Data |
MalwareXLoader | XLoader can collect data stored in the victim's clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareXLoader | XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader. |
| T1185 Browser Session Hijacking |
MalwareXLoader | XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions. |
| T1203 Exploitation for Client Execution |
MalwareXLoader | XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798. |
| T1497 Virtualization/Sandbox Evasion |
MalwareXLoader | XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis. |
| T1497.001 System Checks |
MalwareXLoader | XLoader performs timing checks using the Read-Time Stamp Counter (RDTSC) instruction on the victim CPU. |
| T1529 System Shutdown/Reboot |
MalwareXLoader | XLoader can initiate a system reboot or shutdown. |
| T1539 Steal Web Session Cookie |
MalwareXLoader | XLoader can capture web session cookies and session information from victim browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXLoader | XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start. |
| T1555 Credentials from Password Stores |
MalwareXLoader | XLoader can collect credentials stored in email clients. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1566.001 Spearphishing Attachment |
MalwareXLoader | XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads. |
| T1583.001 Domains |
MalwareXLoader | XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap. |
| T1622 Debugger Evasion |
MalwareXLoader | XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed. |
| T1685 Disable or Modify Tools |
MalwareXLoader | XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.