Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHiddenFace | HiddenFace can upload files from the victim machine to C2 nodes. |
| T1008 Fallback Channels |
MalwareHiddenFace | HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands. |
| T1027.007 Dynamic API Resolution |
MalwareHiddenFace | HiddenFace can dynamically resolve Windows APIs. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenFace | HiddenFace has encrypted its payload with AES. |
| T1033 System Owner/User Discovery |
MalwareHiddenFace | HiddenFace can collect the username associated with the compromised host. |
| T1053.005 Scheduled Task |
MalwareHiddenFace | HiddenFace has used scheduled tasks for execution and persistence. |
| T1055 Process Injection |
MalwareHiddenFace | HiddenFace can inject code directly into legitimate applications. |
| T1057 Process Discovery |
MalwareHiddenFace | HiddenFace can check running processes against a list of blocklisted applications. |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1090.001 Internal Proxy |
MalwareHiddenFace | HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1105 Ingress Tool Transfer |
MalwareHiddenFace | HiddenFace can download files from the C2 to victim systems. |
| T1112 Modify Registry |
MalwareHiddenFace | HiddenFace can store its configuration file in the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenFace | HiddenFace has the ability to decrypt its payload prior to execution. |
| T1480 Execution Guardrails |
MalwareHiddenFace | HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found. |
| T1480.002 Mutual Exclusion |
MalwareHiddenFace | HiddenFace can create a mutex to ensure only one instance is running at a time. |
| T1497.003 Time Based Checks |
MalwareHiddenFace | HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis. |
| T1518.001 Security Software Discovery |
MalwareHiddenFace | HiddenFace can identify processes identified with security applications and tooling. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1571 Non-Standard Port |
MalwareHiddenFace | HiddenFace's passive mode listens on TCP 47000. |
| T1572 Protocol Tunneling |
MalwareHiddenFace | HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenFace | HiddenFace can use a randomly selected symmetric encryption algorithm for C2. |
| T1573.002 Asymmetric Cryptography |
MalwareHiddenFace | HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.