Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1614 System Location Discovery |
MalwareAmadey | Amadey does not run any tasks or install additional malware if the victim machine is based in Russia. |
| T1614 System Location Discovery |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine. |
| T1614 System Location Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”. |
| T1614 System Location Discovery |
MalwareCrimson | Crimson can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
MalwareGootloader | Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea. |
| T1614 System Location Discovery |
MalwareHexEval Loader | HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions. |
| T1614 System Location Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can determine the geographical location of a victim host by checking the language. |
| T1614 System Location Discovery |
MalwareSameCoin | SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location. |
| T1614 System Location Discovery |
MalwareRagnar Locker | Before executing malicious code, Ragnar Locker checks the Windows API |
| T1614 System Location Discovery |
MalwareSocGholish | SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations. |
| T1614 System Location Discovery |
MalwareDarkWatchman | DarkWatchman can identity the OS locale of a compromised host. |
| T1614 System Location Discovery |
MalwarePlugX | PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`. |
| T1614 System Location Discovery |
MalwarePureCrypter | PureCrypter can use `kernel32!GetGeoInfo` to determine system location. |
| T1614 System Location Discovery |
MalwareDarkGate | DarkGate queries system locale information during execution. Later versions of DarkGate query |
| T1614 System Location Discovery |
MalwareSaint Bot | Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova. |
| T1614 System Location Discovery |
MalwareGlassWorm | GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute. |
| T1614 System Location Discovery |
MalwareRedLine Stealer | RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service. |
| T1614 System Location Discovery |
MalwareSDBbot | SDBbot can collected the country code of a compromised machine. |
| T1614 System Location Discovery |
MalwareRaccoon Stealer | Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present. |
| T1614 System Location Discovery |
MalwareAshTag | AshTag can check geolocation on targeted systems. |
| T1614 System Location Discovery |
MalwareGrimAgent | GrimAgent can identify the country code on a compromised host. |
| T1614 System Location Discovery |
MalwareXORIndex Loader | XORIndex Loader can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
ToolRemcos | Remcos can identify the location of targeted devices. |
| T1614 System Location Discovery |
ToolQuasarRAT | QuasarRAT can determine the country a victim host is located in. |
| T1614 System Location Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.