Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has Base64-encoded command execution. |
| T1027.013 Encrypted/Encoded File |
MalwareTsundere Botnet | Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTsundere Botnet | Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software. |
| T1059.001 PowerShell |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via a PowerShell script. |
| T1059.007 JavaScript |
MalwareTsundere Botnet | Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component. |
| T1071.001 Web Protocols |
MalwareTsundere Botnet | Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes. |
| T1082 System Information Discovery |
MalwareTsundere Botnet | Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information. |
| T1102.001 Dead Drop Resolver |
MalwareTsundere Botnet | Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1105 Ingress Tool Transfer |
MalwareTsundere Botnet | Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTsundere Botnet | Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareTsundere Botnet | Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload. |
| T1218.007 Msiexec |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via an MSI installer. |
| T1480 Execution Guardrails |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTsundere Botnet | Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login. |
| T1564.003 Hidden Window |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareTsundere Botnet | Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server. |
| T1614 System Location Discovery |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.