Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
GroupKimsuky | Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware. |
| T1113 Screen Capture |
GroupVolt Typhoon | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1113 Screen Capture |
GroupMuddyWater | MuddyWater has used malware that can capture screenshots of the victim’s machine. |
| T1113 Screen Capture |
GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| T1113 Screen Capture |
GroupFIN7 | FIN7 captured screenshots and desktop video recordings. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1113 Screen Capture |
GroupOilRig | OilRig has a tool called CANDYKING to capture a screenshot of user's desktop. |
| T1113 Screen Capture |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to take screenshots on targeted systems. |
| T1113 Screen Capture |
GroupGroup5 | Malware used by Group5 is capable of watching the victim's screen. |
| T1113 Screen Capture |
GroupWinter Vivern | Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines. |
| T1113 Screen Capture |
GroupDark Caracal | Dark Caracal took screenshots using their Windows malware. |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1113 Screen Capture |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
| T1113 Screen Capture |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines. |
| T1113 Screen Capture |
GroupSilence | Silence can capture victim screen activity. |
| T1113 Screen Capture |
GroupVOID MANTICORE | VOID MANTICORE has captured screen content during an active Zoom session. |
| T1113 Screen Capture |
GroupMagic Hound | Magic Hound malware can take a screenshot and upload the file to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.