ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1552.004×

14 examples

TechniqueUsed byProcedure example
T1552.004
Private Keys
MalwareMachete

Machete has scanned and looked for cryptographic keys and certificate file extensions.

T1552.004
Private Keys
MalwareMafalda

Mafalda can collect a Chrome encryption key used to protect browser cookies.

T1552.004
Private Keys
MalwareHildegard

Hildegard has searched for private keys in .ssh.

T1552.004
Private Keys
MalwareFoggyWeb

FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server.

T1552.004
Private Keys
MalwareTroll Stealer

Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems.

T1552.004
Private Keys
MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1552.004
Private Keys
MalwareKinsing

Kinsing has searched for private keys.

T1552.004
Private Keys
MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

T1552.004
Private Keys
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1552.004
Private Keys
ToolEmpire

Empire can use modules like Invoke-SessionGopher to extract private key and session information.

T1552.004
Private Keys
ToolMimikatz

Mimikatz's CRYPTO::Extract module can extract keys by interacting with Windows cryptographic application programming interface (API) functions.

T1552.004
Private Keys
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys.

T1552.004
Private Keys
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh.

T1552.004
Private Keys
MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.