Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareRustyWater | RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027.013 Encrypted/Encoded File |
MalwareRustyWater | RustyWater has encrypted all strings in the code using position independent XOR encryption. |
| T1033 System Owner/User Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRustyWater | RustyWater has used reddit.exe as its file name and a Cloudflare logo. |
| T1055.002 Portable Executable Injection |
MalwareRustyWater | RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1071.001 Web Protocols |
MalwareRustyWater | RustyWater has used the Rust request library for HTTP C2 communication. |
| T1082 System Information Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s computer name. |
| T1087.002 Domain Account |
MalwareRustyWater | RustyWater has gathered the domain membership of the victim machine’s user. |
| T1106 Native API |
MalwareRustyWater | RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object. Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe. |
| T1132.001 Standard Encoding |
MalwareRustyWater | RustyWater has encoded collected data with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRustyWater | RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini. |
| T1204.002 Malicious File |
MalwareRustyWater | RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1518.001 Security Software Discovery |
MalwareRustyWater | RustyWater has attempted to detect more than 25 antivirus and EDR tools. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRustyWater | RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key. |
| T1559.001 Component Object Model |
MalwareRustyWater | RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
| T1566.001 Spearphishing Attachment |
MalwareRustyWater | RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage. |
| T1573.001 Symmetric Cryptography |
MalwareRustyWater | RustyWater has encrypted encoded data with XOR before sending it to the C2 server. |
| T1622 Debugger Evasion |
MalwareRustyWater | RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts. |
| T1678 Delay Execution |
MalwareRustyWater | RustyWater has generated random sleep intervals between C2 communication. |
| T1684.001 Impersonation |
MalwareRustyWater | RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.