Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareLAMEHUG | LAMEHUG has the ability to collect system information and files of interest from compromised systems. |
| T1007 System Service Discovery |
MalwareLAMEHUG | LAMEHUG can gather service information on targeted systems. |
| T1016 System Network Configuration Discovery |
MalwareLAMEHUG | LAMEHUG can enumerate network information on compromised hosts. |
| T1033 System Owner/User Discovery |
MalwareLAMEHUG | LAMEHUG can use `whoami` to enumerate the system user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLAMEHUG | LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareLAMEHUG | LAMEHUG can exfiltrate collected system information and documents to C2. |
| T1047 Windows Management Instrumentation |
MalwareLAMEHUG | LAMEHUG can use wmic to collect system information. |
| T1057 Process Discovery |
MalwareLAMEHUG | LAMEHUG can gather process information on targeted systems. |
| T1059.003 Windows Command Shell |
MalwareLAMEHUG | LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims. |
| T1059.006 Python |
MalwareLAMEHUG | LAMEHUG can use Python scripts for execution. |
| T1069.002 Domain Groups |
MalwareLAMEHUG | |
| T1071.001 Web Protocols |
MalwareLAMEHUG | LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2. |
| T1074.001 Local Data Staging |
MalwareLAMEHUG | LAMEHUG can save collected data and files of interest in `C:\ProgramData\info\` to consolidate for exfiltration. |
| T1082 System Information Discovery |
MalwareLAMEHUG | LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information. |
| T1083 File and Directory Discovery |
MalwareLAMEHUG | LAMEHUG can target directories on victim machines for file collection. |
| T1087.002 Domain Account |
MalwareLAMEHUG | LAMEHUG can use dsquery to enumerate domain user information. |
| T1102.002 Bidirectional Communication |
MalwareLAMEHUG | LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers. |
| T1119 Automated Collection |
MalwareLAMEHUG | LAMEHUG can recursively copy files from targeted directories on victim hosts. |
| T1132 Data Encoding |
MalwareLAMEHUG | LAMEHUG can encode queries sent to LLMs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLAMEHUG | LAMEHUG can decode and drop a decoy file attached to spearphishing emails. |
| T1204.002 Malicious File |
MalwareLAMEHUG | LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents. |
| T1482 Domain Trust Discovery |
MalwareLAMEHUG | LAMEHUG can gather Active Directory domain information. |
| T1560.001 Archive via Utility |
MalwareLAMEHUG | LAMEHUG can xcopy for file collection on targeted systems. |
| T1566.001 Spearphishing Attachment |
MalwareLAMEHUG | LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments. |
| T1573.002 Asymmetric Cryptography |
MalwareLAMEHUG | LAMEHUG can use SSH to transfer information to C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.