ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1240×

35 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRedLine Stealer

RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram.

T1012
Query Registry
MalwareRedLine Stealer

RedLine Stealer can query the Windows Registry.

T1016
System Network Configuration Discovery
MalwareRedLine Stealer

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1027.002
Software Packing
MalwareRedLine Stealer

RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code.

T1027.010
Command Obfuscation
MalwareRedLine Stealer

RedLine Stealer has obfuscated scripts within text files used in execution.

T1027.013
Encrypted/Encoded File
MalwareRedLine Stealer

RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions.

T1033
System Owner/User Discovery
MalwareRedLine Stealer

RedLine Stealer has obtained the username from the victim’s machine.

T1036
Masquerading
MalwareRedLine Stealer

RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains.

T1041
Exfiltration Over C2 Channel
MalwareRedLine Stealer

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1053.005
Scheduled Task
MalwareRedLine Stealer

RedLine Stealer has achieved persistence via scheduled tasks.

T1059.003
Windows Command Shell
MalwareRedLine Stealer

RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks.

T1059.011
Lua
MalwareRedLine Stealer

RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior.

T1071.001
Web Protocols
MalwareRedLine Stealer

RedLine Stealer has utilized HTTP for C2 communications. RedLine Stealer has also conducted C2 communications to hardcoded C2 servers over HTTPS. RedLine Stealer has leveraged SOAP protocol for C2 communications.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1087.001
Local Account
MalwareRedLine Stealer

RedLine Stealer has collected account information from the victim’s machine.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1105
Ingress Tool Transfer
MalwareRedLine Stealer

RedLine Stealer has the ability download additional payloads.

T1113
Screen Capture
MalwareRedLine Stealer

RedLine Stealer can capture screenshots on a compromised host.

T1132.001
Standard Encoding
MalwareRedLine Stealer

RedLine Stealer has used Base64 to encode command and control traffic.

T1140
Deobfuscate/Decode Files or Information
MalwareRedLine Stealer

RedLine Stealer has decoded its payload prior to execution.

T1204.002
Malicious File
MalwareRedLine Stealer

RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface.

T1217
Browser Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information from browsers and browser extensions.

T1218.007
Msiexec
MalwareRedLine Stealer

RedLine Stealer has been installed via MSI Installer.

T1480
Execution Guardrails
MalwareRedLine Stealer

RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host.

T1497
Virtualization/Sandbox Evasion
MalwareRedLine Stealer

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1518
Software Discovery
MalwareRedLine Stealer

RedLine Stealer can get a list of programs on the victim device.

T1518.001
Security Software Discovery
MalwareRedLine Stealer

RedLine Stealer has identified installed antivirus software on the system.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1553.002
Code Signing
MalwareRedLine Stealer

RedLine Stealer has used both valid certificates and self-signed digital certificates to appear legitimate.

T1555
Credentials from Password Stores
MalwareRedLine Stealer

RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1614.001
System Language Discovery
MalwareRedLine Stealer

RedLine Stealer can retrieve system default language and time zone.

T1657
Financial Theft
MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

T1685
Disable or Modify Tools
MalwareRedLine Stealer

RedLine Stealer can disable security software and update services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.