Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1559.001 Component Object Model |
MalwareTrickBot | TrickBot used COM to setup scheduled task for persistence. |
| T1559.001 Component Object Model |
MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| T1559.001 Component Object Model |
MalwareUrsnif | Ursnif droppers have used COM objects to execute the malware's full executable payload. |
| T1559.001 Component Object Model |
MalwareSTATICPLUGIN | STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file. |
| T1559.001 Component Object Model |
MalwareInvisiMole | InvisiMole can use the |
| T1559.001 Component Object Model |
MalwareCLAIMLOADER | CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface. |
| T1559.001 Component Object Model |
MalwareNeoichor | Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2. |
| T1559.001 Component Object Model |
MalwareRaspberry Robin | Raspberry Robin creates an elevated COM object for |
| T1559.001 Component Object Model |
MalwareRustyWater | RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
| T1559.001 Component Object Model |
MalwareDarkTortilla | DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1559.001 Component Object Model |
MalwareMilan | Milan can use a COM component to generate scheduled tasks. |
| T1559.001 Component Object Model |
MalwareRamsay | Ramsay can use the Windows COM API to schedule tasks and maintain persistence. |
| T1559.001 Component Object Model |
MalwareFunnyDream | FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms. |
| T1559.001 Component Object Model |
MalwarePOWERSTATS | POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts. |
| T1559.001 Component Object Model |
MalwareGelsemium | Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process. |
| T1559.001 Component Object Model |
MalwareHermeticWizard | HermeticWizard can execute files on remote machines using DCOM. |
| T1559.001 Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.