Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.004 Credential API Hooking |
MalwareTrickBot | TrickBot has the ability to capture RDP credentials by capturing the |
| T1056.004 Credential API Hooking |
MalwareRDFSNIFFER | RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface. |
| T1056.004 Credential API Hooking |
MalwareNOKKI | NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine. |
| T1056.004 Credential API Hooking |
MalwareVersaMem | VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server. |
| T1056.004 Credential API Hooking |
MalwareUrsnif | Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
| T1056.004 Credential API Hooking |
MalwareZeus Panda | Zeus Panda hooks processes by leveraging its own IAT hooked functions. |
| T1056.004 Credential API Hooking |
MalwareZebrocy | Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method. |
| T1056.004 Credential API Hooking |
MalwareFinFisher | FinFisher hooks processes by modifying IAT pointers to CreateWindowEx. |
| T1056.004 Credential API Hooking |
MalwareCarberp | Carberp has hooked several Windows API functions to steal credentials. |
| T1056.004 Credential API Hooking |
MalwareZxShell | ZxShell hooks several API functions to spawn system threads. |
| T1056.004 Credential API Hooking |
ToolEmpire | Empire contains some modules that leverage API hooking to carry out tasks, such as netripper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.