ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1213×

35 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareLumma Stealer

Lumma Stealer has used SmartAssembly to obfuscate .NET payloads.

T1027.013
Encrypted/Encoded File
MalwareLumma Stealer

Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts.

T1036.008
Masquerade File Type
MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1041
Exfiltration Over C2 Channel
MalwareLumma Stealer

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1055.012
Process Hollowing
MalwareLumma Stealer

Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload.

T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1059.006
Python
MalwareLumma Stealer

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.010
AutoHotKey & AutoIT
MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1071.001
Web Protocols
MalwareLumma Stealer

Lumma Stealer has used HTTP and HTTP for command and control communication.

T1074.001
Local Data Staging
MalwareLumma Stealer

Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data.

T1082
System Information Discovery
MalwareLumma Stealer

Lumma Stealer has gathered various system information from victim machines.

T1113
Screen Capture
MalwareLumma Stealer

Lumma Stealer has taken screenshots of victim machines.

T1119
Automated Collection
MalwareLumma Stealer

Lumma Stealer has automated collection of various information including cryptocurrency wallet details.

T1140
Deobfuscate/Decode Files or Information
MalwareLumma Stealer

Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell.

T1176.001
Browser Extensions
MalwareLumma Stealer

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

T1195
Supply Chain Compromise
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

T1204
User Execution
MalwareLumma Stealer

Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell.

T1204.002
Malicious File
MalwareLumma Stealer

Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files.

T1217
Browser Information Discovery
MalwareLumma Stealer

Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1218.015
Electron Applications
MalwareLumma Stealer

Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software.

T1497.001
System Checks
MalwareLumma Stealer

Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection.

T1518.001
Security Software Discovery
MalwareLumma Stealer

Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.”

T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1553.002
Code Signing
MalwareLumma Stealer

Lumma Stealer has used valid code signing digital certificates from ConsolHQ LTD and Verandah Green Limited to appear legitimate.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1564.003
Hidden Window
MalwareLumma Stealer

Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window.

T1566.001
Spearphishing Attachment
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails containing malicious links.

T1573.002
Asymmetric Cryptography
MalwareLumma Stealer

Lumma Stealer has used HTTPS for command and control purposes.

T1574.001
DLL
MalwareLumma Stealer

Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution.

T1620
Reflective Code Loading
MalwareLumma Stealer

Lumma Stealer has used reflective loading techniques to load content into memory during execution.

T1622
Debugger Evasion
MalwareLumma Stealer

Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”.

T1685
Disable or Modify Tools
MalwareLumma Stealer

Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.