ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1246×

23 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareBeaverTail

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

T1005
Data from Local System
MalwareBeaverTail

BeaverTail has exfiltrated data collected from local systems.

T1027.013
Encrypted/Encoded File
MalwareBeaverTail

BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions.

T1036
Masquerading
MalwareBeaverTail

BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes.

T1041
Exfiltration Over C2 Channel
MalwareBeaverTail

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1070.004
File Deletion
MalwareBeaverTail

BeaverTail has deleted files from a compromised host after they were exfiltrated.

T1071.001
Web Protocols
MalwareBeaverTail

BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure.

T1074.001
Local Data Staging
MalwareBeaverTail

BeaverTail has staged collected data to the system’s temporary directory.

T1082
System Information Discovery
MalwareBeaverTail

BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server.

T1083
File and Directory Discovery
MalwareBeaverTail

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1124
System Time Discovery
MalwareBeaverTail

BeaverTail has obtained and sent the current timestamp associated with the victim device to C2.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1204.002
Malicious File
MalwareBeaverTail

BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1555
Credentials from Password Stores
MalwareBeaverTail

BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`.

T1555.001
Keychain
MalwareBeaverTail

BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1560.001
Archive via Utility
MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

T1571
Non-Standard Port
MalwareBeaverTail

BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244.

T1654
Log Enumeration
MalwareBeaverTail

BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1657
Financial Theft
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.