Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareLumma Stealer | Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1027.013 Encrypted/Encoded File |
MalwareLumma Stealer | Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts. |
| T1036.008 Masquerade File Type |
MalwareLumma Stealer | Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1055.012 Process Hollowing |
MalwareLumma Stealer | Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1059.001 PowerShell |
MalwareLumma Stealer | Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1059.006 Python |
MalwareLumma Stealer | Lumma Stealer has used malicious Python scripts to execute payloads. |
| T1059.010 AutoHotKey & AutoIT |
MalwareLumma Stealer | Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1074.001 Local Data Staging |
MalwareLumma Stealer | Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1113 Screen Capture |
MalwareLumma Stealer | Lumma Stealer has taken screenshots of victim machines. |
| T1119 Automated Collection |
MalwareLumma Stealer | Lumma Stealer has automated collection of various information including cryptocurrency wallet details. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLumma Stealer | Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell. |
| T1176.001 Browser Extensions |
MalwareLumma Stealer | Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1204 User Execution |
MalwareLumma Stealer | Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell. |
| T1204.002 Malicious File |
MalwareLumma Stealer | Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files. |
| T1217 Browser Information Discovery |
MalwareLumma Stealer | Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers. |
| T1218.005 Mshta |
MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| T1218.015 Electron Applications |
MalwareLumma Stealer | Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software. |
| T1497.001 System Checks |
MalwareLumma Stealer | Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection. |
| T1518.001 Security Software Discovery |
MalwareLumma Stealer | Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.” |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLumma Stealer | Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`. |
| T1553.002 Code Signing |
MalwareLumma Stealer | Lumma Stealer has used valid code signing digital certificates from ConsolHQ LTD and Verandah Green Limited to appear legitimate. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1564.003 Hidden Window |
MalwareLumma Stealer | Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window. |
| T1566.001 Spearphishing Attachment |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails containing malicious links. |
| T1573.002 Asymmetric Cryptography |
MalwareLumma Stealer | Lumma Stealer has used HTTPS for command and control purposes. |
| T1574.001 DLL |
MalwareLumma Stealer | Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution. |
| T1620 Reflective Code Loading |
MalwareLumma Stealer | Lumma Stealer has used reflective loading techniques to load content into memory during execution. |
| T1622 Debugger Evasion |
MalwareLumma Stealer | Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”. |
| T1685 Disable or Modify Tools |
MalwareLumma Stealer | Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.