Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134.001 Token Impersonation/Theft |
MalwareStuxnet | Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager. |
| T1134.001 Token Impersonation/Theft |
MalwareHavoc | Havoc has a module capable of token impersonation. |
| T1134.001 Token Impersonation/Theft |
MalwareAria-body | Aria-body has the ability to duplicate a token from ntprint.exe. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| T1134.001 Token Impersonation/Theft |
MalwareBADHATCH | BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token. |
| T1134.001 Token Impersonation/Theft |
MalwareOkrum | Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API. |
| T1134.001 Token Impersonation/Theft |
MalwareSiloscape | Siloscape impersonates the main thread of |
| T1134.001 Token Impersonation/Theft |
MalwareFooder | Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| T1134.001 Token Impersonation/Theft |
MalwareLP-Notes | LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API. |
| T1134.001 Token Impersonation/Theft |
MalwareShamoon | Shamoon can impersonate tokens using |
| T1134.001 Token Impersonation/Theft |
MalwareTarrask | Tarrask leverages token theft to obtain `lsass.exe` security permissions. |
| T1134.001 Token Impersonation/Theft |
MalwareFinFisher | FinFisher uses token manipulation with NtFilterToken as part of UAC bypass. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| T1134.001 Token Impersonation/Theft |
MalwareREvil | REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user. |
| T1134.001 Token Impersonation/Theft |
MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| T1134.001 Token Impersonation/Theft |
ToolSILENTTRINITY | SILENTTRINITY can find a process owned by a specific user and impersonate the associated token. |
| T1134.001 Token Impersonation/Theft |
ToolPupy | Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.