Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
GroupIndrik Spider | Indrik Spider has stored collected data in a .tmp file. |
| T1074.001 Local Data Staging |
GroupGALLIUM | GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1074.001 Local Data Staging |
GroupPatchwork | Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server. |
| T1074.001 Local Data Staging |
GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| T1074.001 Local Data Staging |
GroupmenuPass | menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin. |
| T1074.001 Local Data Staging |
GroupMuddyWater | MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder. |
| T1074.001 Local Data Staging |
GroupStorm-1811 | Storm-1811 has locally staged captured credentials for subsequent manual exfiltration. |
| T1074.001 Local Data Staging |
GroupTeamTNT | TeamTNT has aggregated collected credentials in text files before exfiltrating. |
| T1074.001 Local Data Staging |
GroupSidewinder | Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration. |
| T1074.001 Local Data Staging |
GroupMustang Panda | Mustang Panda has stored collected credential files in |
| T1074.001 Local Data Staging |
GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupUNC3886 | UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1074.001 Local Data Staging |
GroupFIN5 | FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment. |
| T1074.001 Local Data Staging |
GroupLotus Blossom | Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1074.001 Local Data Staging |
GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
| T1074.001 Local Data Staging |
GroupBackdoorDiplomacy | BackdoorDiplomacy has copied files of interest to the main drive's recycle bin. |
| T1074.001 Local Data Staging |
GroupAgrius | Agrius has used the folder, |
| T1074.001 Local Data Staging |
GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| T1074.001 Local Data Staging |
GroupAPT5 | APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`. |
| T1074.001 Local Data Staging |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server. |
| T1074.001 Local Data Staging |
GroupWizard Spider | Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupWIRTE | WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1074.001 Local Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts. |
| T1074.001 Local Data Staging |
GroupFIN13 | FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.