ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1113×

19 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
GroupKimsuky

Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware.

T1113
Screen Capture
GroupVolt Typhoon

Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

T1113
Screen Capture
GroupMuddyWater

MuddyWater has used malware that can capture screenshots of the victim’s machine.

T1113
Screen Capture
GroupGamaredon Group

Gamaredon Group's malware can take screenshots of the compromised computer every minute.

T1113
Screen Capture
GroupFIN7

FIN7 captured screenshots and desktop video recordings.

T1113
Screen Capture
GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

T1113
Screen Capture
GroupOilRig

OilRig has a tool called CANDYKING to capture a screenshot of user's desktop.

T1113
Screen Capture
GroupMoustachedBouncer

MoustachedBouncer has used plugins to take screenshots on targeted systems.

T1113
Screen Capture
GroupGroup5

Malware used by Group5 is capable of watching the victim's screen.

T1113
Screen Capture
GroupWinter Vivern

Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines.

T1113
Screen Capture
GroupDark Caracal

Dark Caracal took screenshots using their Windows malware.

T1113
Screen Capture
GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1113
Screen Capture
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots.

T1113
Screen Capture
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1113
Screen Capture
GroupVOID MANTICORE

VOID MANTICORE has captured screen content during an active Zoom session.

T1113
Screen Capture
GroupMagic Hound

Magic Hound malware can take a screenshot and upload the file to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.