Real-world descriptions of how a group, tool or campaign used a technique.
48 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1119 Automated Collection |
MalwareProxysvc | Proxysvc automatically collects data about the victim and sends it to the control server. |
| T1119 Automated Collection |
MalwareRotaJakiro | Depending on the Linux distribution, RotaJakiro executes a set of commands to collect device information and sends the collected information to the C2 server. |
| T1119 Automated Collection |
MalwareWindTail | WindTail can identify and add files that possess specific file extensions to an array for archiving. |
| T1119 Automated Collection |
MalwareBankshot | Bankshot recursively generates a list of files within a directory and sends them back to the control server. |
| T1119 Automated Collection |
MalwareStrongPity | StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions. |
| T1119 Automated Collection |
MalwareAppleSeed | AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration. |
| T1119 Automated Collection |
MalwareNETWIRE | NETWIRE can automatically archive collected data. |
| T1119 Automated Collection |
MalwareLoFiSe | LoFiSe can collect all the files from the working directory every three hours and place them into a password-protected archive for further exfiltration. |
| T1119 Automated Collection |
MalwareInvisiMole | InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file. |
| T1119 Automated Collection |
MalwareVERMIN | VERMIN saves each collected file with the automatically generated format {0:dd-MM-yyyy}.txt . |
| T1119 Automated Collection |
MalwarePACEMAKER | PACEMAKER can enter a loop to read `/proc/` entries every 2 seconds in order to read a target application's memory. |
| T1119 Automated Collection |
MalwareLumma Stealer | Lumma Stealer has automated collection of various information including cryptocurrency wallet details. |
| T1119 Automated Collection |
MalwareRover | Rover automatically collects files from the local system and removable drives based on a predefined list of file extensions on a regular timeframe. |
| T1119 Automated Collection |
MalwareLightNeuron | LightNeuron can be configured to automatically collect files under a specified directory. |
| T1119 Automated Collection |
MalwareDarkGate | DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified. |
| T1119 Automated Collection |
MalwareMetamorfo | Metamorfo has automatically collected mouse clicks, continuous screenshots on the machine, and set timers to collect the contents of the clipboard and website browsing. |
| T1119 Automated Collection |
MalwareT9000 | T9000 searches removable storage devices for files with a pre-defined list of file extensions (e.g. * .doc, *.ppt, *.xls, *.docx, *.pptx, *.xlsx). Any matching files are encrypted and written to a local user directory. |
| T1119 Automated Collection |
MalwareMicropsia | Micropsia executes an RAR tool to recursively archive files based on a predefined list of file extensions (*.xls, *.xlsx, *.csv, *.odt, *.doc, *.docx, *.ppt, *.pptx, *.pdf, *.mdb, *.accdb, *.accde, *.txt). |
| T1119 Automated Collection |
MalwareAttor | Attor has automatically collected data about the compromised system. |
| T1119 Automated Collection |
MalwareCrutch | Crutch can automatically monitor removable drives in a loop and copy interesting files. |
| T1119 Automated Collection |
MalwareRTM | RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings. |
| T1119 Automated Collection |
MalwareStrelaStealer | StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution. |
| T1119 Automated Collection |
MalwareMESSAGETAP | MESSAGETAP checks two files, keyword_parm.txt and parm.txt, for instructions on how to target and save data parsed and extracted from SMS message data from the network traffic. If an SMS message contained either a phone number, IMSI number, or keyword that matched the predefined list, it is saved to a CSV file for later theft by the threat actor. |
| T1119 Automated Collection |
Malwareccf32 | ccf32 can be used to automatically collect files from a compromised host. |
| T1119 Automated Collection |
MalwareZebrocy | Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz. |
| T1119 Automated Collection |
MalwareValak | Valak can download a module to search for and build a report of harvested credential data. |
| T1119 Automated Collection |
MalwareUSBStealer | For all non-removable drives on a victim, USBStealer executes automated collection of certain files for later exfiltration. |
| T1119 Automated Collection |
MalwareTajMahal | TajMahal has the ability to index and compress files into a send queue for exfiltration. |
| T1119 Automated Collection |
MalwareRaccoon Stealer | Raccoon Stealer collects files and directories from victim systems based on configuration data downloaded from command and control servers. |
| T1119 Automated Collection |
MalwareGoldFinder | GoldFinder logged and stored information related to the route or hops a packet took from a compromised machine to a hardcoded C2 server, including the target C2 URL, HTTP response/status code, HTTP response headers and values, and data received from the C2 node. |
| T1119 Automated Collection |
MalwareRamsay | Ramsay can conduct an initial scan for Microsoft Word documents on the local system, removable media, and connected network drives, before tagging and collecting them. It can continue tagging documents to collect with follow up scans. |
| T1119 Automated Collection |
MalwareFunnyDream | FunnyDream can monitor files for changes and automatically collect them. |
| T1119 Automated Collection |
MalwareOutSteel | OutSteel can automatically scan for and collect files with specific extensions. |
| T1119 Automated Collection |
MalwareLAMEHUG | LAMEHUG can recursively copy files from targeted directories on victim hosts. |
| T1119 Automated Collection |
MalwarePoetRAT | PoetRAT used file system monitoring to track modification and enable automatic exfiltration. |
| T1119 Automated Collection |
MalwareShai-Hulud | Shai-Hulud has the ability to automatically collect host data, secrets, system information, and endpoints. |
| T1119 Automated Collection |
MalwareBADNEWS | BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory. |
| T1119 Automated Collection |
MalwareHelminth | A Helminth VBScript receives a batch script to execute a set of commands in a command prompt. |
| T1119 Automated Collection |
MalwareComnie | Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server. |
| T1119 Automated Collection |
ToolNPPSPY | NPPSPY collection is automatically recorded to a specified file on the victim machine. |
| T1119 Automated Collection |
ToolShimRatReporter | ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators. |
| T1119 Automated Collection |
ToolPacu | Pacu can automatically collect data, such as CloudFormation templates, EC2 user data, AWS Inspector reports, and IAM credential reports. |
| T1119 Automated Collection |
ToolEmpire | Empire can automatically gather the username, domain name, machine name, and other information from a compromised system. |
| T1119 Automated Collection |
ToolPoshC2 | PoshC2 contains a module for recursively parsing through files and directories to gather valid credit card numbers. |
| T1119 Automated Collection |
ToolROADTools | ROADTools automatically gathers data from Azure AD environments using the Azure Graph API. |
| T1119 Automated Collection |
ToolMythic | Mythic supports scripting of file downloads from agents. |
| T1119 Automated Collection |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify and collect credentials across over 50 file paths in Cloud, CI/CD, developer tooling, and container enviornments. |
| T1119 Automated Collection |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to automatically compile gathered credentials from configuration files and password vaults within an archive and exfiltrate stolen data leveraging both a primary and fallback C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.