ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1680×

88 examples

TechniqueUsed byProcedure example
T1680
Local Storage Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected disk information, including type and free space available.

T1680
Local Storage Discovery
MalwareNinja

Ninja can obtain information on physical drives from targeted hosts.

T1680
Local Storage Discovery
MalwareProxysvc

Proxysvc collects volume information for all drives on the system.

T1680
Local Storage Discovery
MalwareTorisma

Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive.

T1680
Local Storage Discovery
MalwareNOKKI

NOKKI can gather information on drives on the victim’s machine.

T1680
Local Storage Discovery
Malwareyty

yty gathers the the serial number of the main disk volume.

T1680
Local Storage Discovery
MalwareKOPILUWAK

KOPILUWAK can discover logical drive information on compromised hosts.

T1680
Local Storage Discovery
MalwareSardonic

Sardonic has the ability to collect the C:\ drive serial number from a compromised machine.

T1680
Local Storage Discovery
MalwareKEYMARBLE

KEYMARBLE has the capability to collect information on disk devices.

T1680
Local Storage Discovery
MalwareBankshot

Bankshot gathers disk type and disk free space.

T1680
Local Storage Discovery
MalwareSharpDisco

SharpDisco can use a plugin to enumerate system drives.

T1680
Local Storage Discovery
MalwareStrongPity

StrongPity can identify the hard disk volume serial number on a compromised host.

T1680
Local Storage Discovery
MalwareNebulae

Nebulae can discover logical drive information including the drive type, free space, and volume information.

T1680
Local Storage Discovery
MalwareTONESHELL

TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine.

T1680
Local Storage Discovery
MalwareMedusa Ransomware

Medusa Ransomware has enumerated logical drives on infected hosts.

T1680
Local Storage Discovery
MalwaremacOS.OSAMiner

macOS.OSAMiner has checked to ensure there is enough disk space using the Unix utility `df`.

T1680
Local Storage Discovery
MalwareAria-body

Aria-body has the ability to identify disk information on a compromised host.

T1680
Local Storage Discovery
MalwareCrimson

Crimson contains a command to collect disk drive information.

T1680
Local Storage Discovery
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `GetLogicalDrives()` and `GetDriveType()` functions to enumerate all the drives visible to the system.

T1680
Local Storage Discovery
MalwareAvenger

Avenger has the ability to identify the host volume ID.

T1680
Local Storage Discovery
MalwarePUBLOAD

PUBLOAD has leveraged `wmic logicaldisk get` to map local network drives.

T1680
Local Storage Discovery
MalwareWoody RAT

Woody RAT can retrieve information about storage drives from an infected machine.

T1680
Local Storage Discovery
MalwareMafalda

Mafalda can enumerate all drives on a compromised host.

T1680
Local Storage Discovery
MalwareSUGARUSH

MoonWind can obtain the number of drives on the victim machine.

T1680
Local Storage Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting victim machine volume information.

T1680
Local Storage Discovery
MalwareInvisiMole

InvisiMole can gather information on the mapped drives and system volume serial number.

T1680
Local Storage Discovery
MalwareWhisperGate

WhisperGate has the ability to enumerate fixed logical drives on a targeted system.

T1680
Local Storage Discovery
MalwareBlackCat

BlackCat can enumerate local drives.

T1680
Local Storage Discovery
MalwareNightdoor

Nightdoor can collect information about disk drives, their total and free space, and file system type.

T1680
Local Storage Discovery
MalwareKazuar

Kazuar gathers information on local drives.

T1680
Local Storage Discovery
MalwareRising Sun

Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume.

T1680
Local Storage Discovery
MalwareChrommme

Chrommme has the ability to list drives.

T1680
Local Storage Discovery
MalwareHELLOKITTY

HELLOKITTY can enumerate logical drives on a target system.

T1680
Local Storage Discovery
MalwareCORESHELL

CORESHELL collects the volume serial number from the victim and sends the information to its C2 server.

T1680
Local Storage Discovery
MalwareRunningRAT

RunningRAT gathers logical drives information and volume information.

T1680
Local Storage Discovery
MalwareBabuk

Babuk can enumerate disk volumes, get disk information, and query service status.

T1680
Local Storage Discovery
MalwareBlackMould

BlackMould can enumerate local drives on a compromised host.

T1680
Local Storage Discovery
MalwarePlugX

PlugX has collected a list of all mapped drives on the infected host.

T1680
Local Storage Discovery
MalwareReaver

Reaver collects volume serial number from the victim.

T1680
Local Storage Discovery
MalwareEpic

Epic collects disk space information.

T1680
Local Storage Discovery
MalwareCuba

Cuba can enumerate local drives, disk type, and disk free space.

T1680
Local Storage Discovery
MalwareDEATHRANSOM

DEATHRANSOM can enumerate logical drives on a target system.

T1680
Local Storage Discovery
MalwareDarkGate

DarkGate uses the Delphi methods Sysutils::DiskSize and GlobalMemoryStatusEx to collect disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment.

T1680
Local Storage Discovery
MalwareMongall

Mongall can identify drives on compromised hosts.

T1680
Local Storage Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate local drive configuration.

T1680
Local Storage Discovery
MalwareTYPEFRAME

TYPEFRAME can gather the disk volume information.

T1680
Local Storage Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DriveList to retrieve drive information.

T1680
Local Storage Discovery
MalwareRoyal

Royal can use `GetLogicalDrives` to enumerate logical drives.

T1680
Local Storage Discovery
MalwareBandook

Bandook can collect information about the drives available on the system.

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.