Wi-Fi Discovery

T1016.002

Sub-technique of T1016 System Network Configuration Discovery.View on attack.mitre.org

About this technique

Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Account Discovery, Remote System Discovery, and other discovery or Credential Access activity to support both ongoing and future campaigns.

Adversaries may collect various types of information about Wi-Fi networks from hosts. For example, on Windows names and passwords of all Wi-Fi networks a device has previously connected to may be available through `netsh wlan show profiles` to enumerate Wi-Fi names and then `netsh wlan show profile “Wi-Fi name” key=clear` to show a Wi-Fi network’s corresponding password. Additionally, names and other details of locally reachable Wi-Fi networks can be discovered using calls to `wlanAPI.dll` Native API functions.

On Linux, names and passwords of all Wi-Fi-networks a device has previously connected to may be available in files under ` /etc/NetworkManager/system-connections/`. On macOS, the password of a known Wi-Fi may be identified with ` security find-generic-password -wa wifiname` (requires admin username/password).

Detection rules0

Rules on DetectionCode tagged with T1016.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software5

Campaigns1

Procedure examples7

Groups1

Used byProcedure example
GroupMagic Hound

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

Software5

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.

MalwareCharmPower

CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details.

MalwareEmotet

Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.

MalwareMachete

Machete uses the netsh wlan show networks mode=bssid and netsh wlan show interfaces commands to list all nearby WiFi networks and connected interfaces.

MalwarePUBLOAD

PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`.

Campaigns1

Used byProcedure example
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system.

References6

  1. Binary Defense Emotes Wi-Fi Spreader Open source
    Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023.
  2. BleepingComputer Agent Tesla steal wifi passwords Open source
    Sergiu Gatlan. (2020, April 16). Hackers steal WiFi passwords using upgraded Agent Tesla malware. Retrieved September 8, 2023.
  3. Check Point APT35 CharmPower January 2022 Open source
    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.
  4. Find Wi-Fi Password on Mac Open source
    Ruslana Lishchuk. (2021, March 26). How to Find a Saved Wi-Fi Password on a Mac. Retrieved September 8, 2023.
  5. Malware Bytes New AgentTesla variant steals WiFi credentials Open source
    Hossein Jazi. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved September 8, 2023.
  6. Wi-Fi Password of All Connected Networks in Windows/Linux Open source
    Geeks for Geeks. (n.d.). Wi-Fi Password of All Connected Networks in Windows/Linux. Retrieved September 8, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.