ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1113×

151 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
MalwareRCSession

RCSession can capture screenshots from a compromised host.

T1113
Screen Capture
MalwareQuietSieve

QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`.

T1113
Screen Capture
MalwareGRIFFON

GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system.

T1113
Screen Capture
Malwareyty

yty collects screenshots of the victim machine.

T1113
Screen Capture
MalwareDOGCALL

DOGCALL is capable of capturing screenshots of the victim's machine.

T1113
Screen Capture
MalwarePOWRUNER

POWRUNER can capture a screenshot from a victim.

T1113
Screen Capture
MalwareSharpStage

SharpStage has the ability to capture the victim's screen.

T1113
Screen Capture
MalwareHALFBAKED

HALFBAKED can obtain screenshots from the victim.

T1113
Screen Capture
MalwareKEYMARBLE

KEYMARBLE can capture screenshots of the victim’s machine.

T1113
Screen Capture
MalwareUrsnif

Ursnif has used hooked APIs to take screenshots.

T1113
Screen Capture
MalwareZLib

ZLib has the ability to obtain screenshots of the compromised system.

T1113
Screen Capture
MalwareRedLeaves

RedLeaves can capture screenshots.

T1113
Screen Capture
MalwareZeus Panda

Zeus Panda can take screenshots of the victim’s machine.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

T1113
Screen Capture
MalwareMatryoshka

Matryoshka is capable of performing screen captures.

T1113
Screen Capture
MalwareJanicab

Janicab captured screenshots and sent them out to a C2 server.

T1113
Screen Capture
MalwareTONESHELL

TONESHELL has conducted screen capturing.

T1113
Screen Capture
MalwareKasidet

Kasidet has the ability to initiate keylogging and screen captures.

T1113
Screen Capture
MalwareRainyDay

RainyDay has the ability to capture screenshots.

T1113
Screen Capture
MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1113
Screen Capture
MalwareCosmicDuke

CosmicDuke takes periodic screenshots and exfiltrates them.

T1113
Screen Capture
MalwareEvilGrab

EvilGrab has the capability to capture screenshots.

T1113
Screen Capture
MalwareAria-body

Aria-body has the ability to capture screenshots on compromised hosts.

T1113
Screen Capture
MalwareCrimson

Crimson contains a command to perform screen captures.

T1113
Screen Capture
MalwareDUSTTRAP

DUSTTRAP can capture screenshots.

T1113
Screen Capture
MalwareTurian

Turian has the ability to take screenshots.

T1113
Screen Capture
MalwareBADHATCH

BADHATCH can take screenshots and send them to an actor-controlled C2 server.

T1113
Screen Capture
MalwareMachete

Machete captures screenshots.

T1113
Screen Capture
MalwarePrikormka

Prikormka contains a module that captures screenshots of the victim's desktop.

T1113
Screen Capture
MalwareWoody RAT

Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+.

T1113
Screen Capture
MalwareMafalda

Mafalda can take a screenshot of the target machine and save it to a file.

T1113
Screen Capture
MalwareSHUTTERSPEED

SHUTTERSPEED can capture screenshots.

T1113
Screen Capture
MalwareFlawedAmmyy

FlawedAmmyy can capture screenshots.

T1113
Screen Capture
MalwareCuckoo Stealer

Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts.

T1113
Screen Capture
MalwareInvisiMole

InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping.

T1113
Screen Capture
MalwareFruitFly

FruitFly takes screenshots of the user's desktop.

T1113
Screen Capture
MalwareRDAT

RDAT can take a screenshot on the infected system.

T1113
Screen Capture
MalwareTRANSLATEXT

TRANSLATEXT has the ability to capture screenshots of new browser tabs, based on the presence of the `Capture` flag.

T1113
Screen Capture
MalwareMispadu

Mispadu has the ability to capture screenshots on compromised hosts.

T1113
Screen Capture
MalwareVERMIN

VERMIN can perform screen captures of the victim’s machine.

T1113
Screen Capture
MalwareHTTPTroy

HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server.

T1113
Screen Capture
MalwareMarkiRAT

MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’.

T1113
Screen Capture
MalwareKazuar

Kazuar captures screenshots of the victim’s screen.

T1113
Screen Capture
MalwarePOORAIM

POORAIM can perform screen capturing.

T1113
Screen Capture
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk.

T1113
Screen Capture
MalwareBlackEnergy

BlackEnergy is capable of taking screenshots.

T1113
Screen Capture
MalwareChrommme

Chrommme has the ability to capture screenshots.

T1113
Screen Capture
MalwareObliqueRAT

ObliqueRAT can capture a screenshot of the current screen.

T1113
Screen Capture
MalwareXAgentOSX

XAgentOSX contains the takeScreenShot (along with startTakeScreenShot and stopTakeScreenShot) functions to take screenshots using the CGGetActiveDisplayList, CGDisplayCreateImage, and NSImage:initWithCGImage methods.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.