Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1203 Exploitation for Client Execution |
MalwareVersaMem | VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers. |
| T1203 Exploitation for Client Execution |
MalwareHAWKBALL | HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload. |
| T1203 Exploitation for Client Execution |
MalwareBankshot | Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines. |
| T1203 Exploitation for Client Execution |
MalwareWoody RAT | Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery. |
| T1203 Exploitation for Client Execution |
MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| T1203 Exploitation for Client Execution |
MalwareXbash | Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution. |
| T1203 Exploitation for Client Execution |
MalwareDealersChoice | DealersChoice leverages vulnerable versions of Flash to perform execution. |
| T1203 Exploitation for Client Execution |
MalwareXLoader | XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798. |
| T1203 Exploitation for Client Execution |
MalwareSpeakUp | SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1203 Exploitation for Client Execution |
MalwareEvilBunny | EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| T1203 Exploitation for Client Execution |
MalwareSUPERNOVA | SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148). |
| T1203 Exploitation for Client Execution |
MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| T1203 Exploitation for Client Execution |
MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.