Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRedLine Stealer | RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram. |
| T1012 Query Registry |
MalwareRedLine Stealer | RedLine Stealer can query the Windows Registry. |
| T1016 System Network Configuration Discovery |
MalwareRedLine Stealer | RedLine Stealer can enumeate information about victims’ systems including IP addresses. |
| T1027.002 Software Packing |
MalwareRedLine Stealer | RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code. |
| T1027.010 Command Obfuscation |
MalwareRedLine Stealer | RedLine Stealer has obfuscated scripts within text files used in execution. |
| T1027.013 Encrypted/Encoded File |
MalwareRedLine Stealer | RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions. |
| T1033 System Owner/User Discovery |
MalwareRedLine Stealer | RedLine Stealer has obtained the username from the victim’s machine. |
| T1036 Masquerading |
MalwareRedLine Stealer | RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains. |
| T1041 Exfiltration Over C2 Channel |
MalwareRedLine Stealer | RedLine Stealer has sent victim data to its C2 server or RedLine panel server. |
| T1053.005 Scheduled Task |
MalwareRedLine Stealer | RedLine Stealer has achieved persistence via scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareRedLine Stealer | RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks. |
| T1059.011 Lua |
MalwareRedLine Stealer | RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior. |
| T1071.001 Web Protocols |
MalwareRedLine Stealer | RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications. |
| T1082 System Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information about the local system. |
| T1087.001 Local Account |
MalwareRedLine Stealer | RedLine Stealer has collected account information from the victim’s machine. |
| T1102 Web Service |
MalwareRedLine Stealer | RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads. |
| T1105 Ingress Tool Transfer |
MalwareRedLine Stealer | RedLine Stealer has the ability download additional payloads. |
| T1113 Screen Capture |
MalwareRedLine Stealer | RedLine Stealer can capture screenshots on a compromised host. |
| T1132.001 Standard Encoding |
MalwareRedLine Stealer | RedLine Stealer has used Base64 to encode command and control traffic. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRedLine Stealer | RedLine Stealer has decoded its payload prior to execution. |
| T1204.002 Malicious File |
MalwareRedLine Stealer | RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface. |
| T1217 Browser Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information from browsers and browser extensions. |
| T1218.007 Msiexec |
MalwareRedLine Stealer | RedLine Stealer has been installed via MSI Installer. |
| T1480 Execution Guardrails |
MalwareRedLine Stealer | RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRedLine Stealer | RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution. |
| T1518 Software Discovery |
MalwareRedLine Stealer | RedLine Stealer can get a list of programs on the victim device. |
| T1518.001 Security Software Discovery |
MalwareRedLine Stealer | RedLine Stealer has identified installed antivirus software on the system. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1553.002 Code Signing |
MalwareRedLine Stealer | RedLine Stealer has used both valid certificates and self-signed digital certificates to appear legitimate. |
| T1555 Credentials from Password Stores |
MalwareRedLine Stealer | RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1614 System Location Discovery |
MalwareRedLine Stealer | RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service. |
| T1614.001 System Language Discovery |
MalwareRedLine Stealer | RedLine Stealer can retrieve system default language and time zone. |
| T1657 Financial Theft |
MalwareRedLine Stealer | RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers. |
| T1685 Disable or Modify Tools |
MalwareRedLine Stealer | RedLine Stealer can disable security software and update services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.