Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.007 Proc Filesystem |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1008 Fallback Channels |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset. |
| T1016 System Network Configuration Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to enumerate network interfaces. |
| T1020 Automated Exfiltration |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there. |
| T1027.013 Encrypted/Encoded File |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis. |
| T1033 System Owner/User Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems. |
| T1041 Exfiltration Over C2 Channel |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1049 System Network Connections Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1057 Process Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can locate GitHub Actions runner processes. |
| T1059.004 Unix Shell |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1059.006 Python |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence. |
| T1059.007 JavaScript |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file. |
| T1070.004 File Deletion |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration. |
| T1071.001 Web Protocols |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains. |
| T1074.001 Local Data Staging |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data. |
| T1082 System Information Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`. |
| T1083 File and Directory Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets. |
| T1105 Ingress Tool Transfer |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems. |
| T1119 Automated Collection |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify and collect credentials across over 50 file paths in Cloud, CI/CD, developer tooling, and container enviornments. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution. |
| T1213.003 Code Repositories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials. |
| T1213.006 Databases |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf. |
| T1480 Execution Guardrails |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube. |
| T1518 Software Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts. |
| T1526 Cloud Service Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search GitHub for Actions runner processes. |
| T1528 Steal Application Access Token |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens. |
| T1543.002 Systemd Service |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence. |
| T1546.016 Installer Packages |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution. |
| T1546.018 Python Startup Hooks |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup. |
| T1548.003 Sudo and Sudo Caching |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `sudo` for code execution. |
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.003 Shell History |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners. |
| T1552.004 Private Keys |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys. |
| T1552.007 Container API |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can query the Kubernetes API for credentials. |
| T1555 Credentials from Password Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor. |
| T1567.001 Exfiltration to Code Repository |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
| T1573.001 Symmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`. |
| T1573.002 Asymmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`. |
| T1580 Cloud Infrastructure Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to search for generic GitHub runners. |
| T1609 Container Administration Command |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes. |
| T1613 Container and Resource Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials. |
| T1657 Financial Theft |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero. |
| T1678 Delay Execution |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.