ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1056.004×

11 examples

TechniqueUsed byProcedure example
T1056.004
Credential API Hooking
MalwareTrickBot

TrickBot has the ability to capture RDP credentials by capturing the CredEnumerateA API

T1056.004
Credential API Hooking
MalwareRDFSNIFFER

RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface.

T1056.004
Credential API Hooking
MalwareNOKKI

NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.

T1056.004
Credential API Hooking
MalwareVersaMem

VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server.

T1056.004
Credential API Hooking
MalwareUrsnif

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.

T1056.004
Credential API Hooking
MalwareZeus Panda

Zeus Panda hooks processes by leveraging its own IAT hooked functions.

T1056.004
Credential API Hooking
MalwareZebrocy

Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method.

T1056.004
Credential API Hooking
MalwareFinFisher

FinFisher hooks processes by modifying IAT pointers to CreateWindowEx.

T1056.004
Credential API Hooking
MalwareCarberp

Carberp has hooked several Windows API functions to steal credentials.

T1056.004
Credential API Hooking
MalwareZxShell

ZxShell hooks several API functions to spawn system threads.

T1056.004
Credential API Hooking
ToolEmpire

Empire contains some modules that leverage API hooking to carry out tasks, such as netripper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.