Dray Agha. (2022, August 16). Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY. Retrieved May 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
ToolNPPSPY | NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext. |
| T1056 Input Capture |
ToolNPPSPY | NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext. |
| T1112 Modify Registry |
ToolNPPSPY | NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process. |
| T1119 Automated Collection |
ToolNPPSPY | NPPSPY collection is automatically recorded to a specified file on the victim machine. |
| T1552 Unsecured Credentials |
ToolNPPSPY | NPPSPY captures credentials by recording them through an alternative network listener registered to the |
| T1557 Adversary-in-the-Middle |
ToolNPPSPY | NPPSPY opens a new network listener for the |
| T1684.001 Impersonation |
ToolNPPSPY | NPPSPY creates a network listener using the misspelled label |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.