ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1217×

18 examples

TechniqueUsed byProcedure example
T1217
Browser Information Discovery
MalwareMachete

Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers.

T1217
Browser Information Discovery
MalwarePowerLess

PowerLess has a browser info stealer module that can read Chrome and Edge browser database files.

T1217
Browser Information Discovery
MalwareMafalda

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.

T1217
Browser Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.

T1217
Browser Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim browser bookmarks.

T1217
Browser Information Discovery
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1217
Browser Information Discovery
MalwareLightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareDarkWatchman

DarkWatchman can retrieve browser history.

T1217
Browser Information Discovery
MalwareLumma Stealer

Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers.

T1217
Browser Information Discovery
MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information from browsers and browser extensions.

T1217
Browser Information Discovery
MalwareSUGARDUMP

SUGARDUMP has collected browser bookmark and history information.

T1217
Browser Information Discovery
MalwareCalisto

Calisto collects information on bookmarks from Google Chrome.

T1217
Browser Information Discovery
MalwareTroll Stealer

Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions.

T1217
Browser Information Discovery
MalwareLizar

Lizar can retrieve browser history and database files.

T1217
Browser Information Discovery
MalwareDtrack

Dtrack can retrieve browser history.

T1217
Browser Information Discovery
ToolEmpire

Empire has the ability to gather browser data such as bookmarks and visited sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.