Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
MalwareAgent Tesla | Agent Tesla can collect the timestamp from the victim’s machine. |
| T1124 System Time Discovery |
MalwareStarProxy | StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value. |
| T1124 System Time Discovery |
MalwareShadowPad | ShadowPad has collected the current date and time of the victim system. |
| T1124 System Time Discovery |
MalwareAstaroth | Astaroth collects the timestamp from the infected machine. |
| T1124 System Time Discovery |
MalwareQakBot | QakBot can identify the system time on a targeted host. |
| T1124 System Time Discovery |
MalwareDEADWOOD | DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately. |
| T1124 System Time Discovery |
MalwareAzorult | Azorult can collect the time zone information from the system. |
| T1124 System Time Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine. |
| T1124 System Time Discovery |
MalwareStrifeWater | StrifeWater can collect the time zone from the victim's machine. |
| T1124 System Time Discovery |
ToolNet | The |
| T1124 System Time Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect start time information from a compromised host. |
| T1124 System Time Discovery |
ToolAsyncRAT | AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration. |
| T1124 System Time Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host. |
| T1124 System Time Discovery |
MalwareCanisterWorm | CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.” |
| T1125 Video Capture |
MalwareEvilGrab | EvilGrab has the capability to capture video from a victim machine. |
| T1125 Video Capture |
MalwareCrimson | Crimson can capture webcam video on targeted systems. |
| T1125 Video Capture |
MalwareMachete | Machete takes photos from the computer’s web camera. |
| T1125 Video Capture |
MalwareInvisiMole | InvisiMole can remotely activate the victim’s webcam to capture content. |
| T1125 Video Capture |
MalwareKazuar | Kazuar captures images from the webcam. |
| T1125 Video Capture |
MalwareDarkComet | DarkComet can access the victim’s webcam to take pictures. |
| T1125 Video Capture |
MalwareObliqueRAT | ObliqueRAT can capture images from webcams on compromised hosts. |
| T1125 Video Capture |
MalwareClambling | Clambling can record screen content in AVI format. |
| T1125 Video Capture |
MalwareBandook | Bandook has modules that are capable of capturing video from a victim's webcam. |
| T1125 Video Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1125 Video Capture |
MalwareSDBbot | SDBbot has the ability to record video on a compromised host. |
| T1125 Video Capture |
MalwareDerusbi | Derusbi is capable of capturing video. |
| T1125 Video Capture |
MalwareCobian RAT | Cobian RAT has a feature to access the webcam on the victim’s machine. |
| T1125 Video Capture |
MalwareNanoCore | NanoCore can access the victim's webcam and capture data. |
| T1125 Video Capture |
MalwareTajMahal | TajMahal has the ability to capture webcam video. |
| T1125 Video Capture |
MalwareRevenge RAT | Revenge RAT has the ability to access the webcam. |
| T1125 Video Capture |
MalwarePoetRAT | PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts. |
| T1125 Video Capture |
MalwareZxShell | ZxShell has a command to perform video device spying. |
| T1125 Video Capture |
MalwarenjRAT | njRAT can access the victim's webcam. |
| T1125 Video Capture |
MalwareAgent Tesla | Agent Tesla can access the victim’s webcam and record video. |
| T1125 Video Capture |
MalwarejRAT | jRAT has the capability to capture video from a webcam. |
| T1125 Video Capture |
MalwareWarzoneRAT | WarzoneRAT can access the webcam on a victim's machine. |
| T1125 Video Capture |
ToolEmpire | Empire can capture webcam data on Windows and macOS systems. |
| T1125 Video Capture |
ToolPcShare | PcShare can capture camera video as part of its collection process. |
| T1125 Video Capture |
ToolAsyncRAT | AsyncRAT can record screen content on targeted systems. |
| T1125 Video Capture |
ToolRemcos | Remcos can access a system’s webcam and take pictures. |
| T1125 Video Capture |
ToolConnectWise | ConnectWise can record video on remote hosts. |
| T1125 Video Capture |
ToolImminent Monitor | Imminent Monitor has a remote webcam monitoring capability. |
| T1125 Video Capture |
ToolPupy | Pupy can access a connected webcam and capture pictures. |
| T1125 Video Capture |
ToolQuasarRAT | QuasarRAT can perform webcam viewing. |
| T1125 Video Capture |
ToolQuick Assist | Quick Assist allows for the remote administrator to view the interactive session of the running machine, including full screen activity. |
| T1127.001 MSBuild |
MalwarePlugX | A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques. |
| T1127.001 MSBuild |
MalwareNOOPLDR | NOOPLDR can be executed via MSBuild. |
| T1127.001 MSBuild |
ToolEmpire | Empire can use built-in modules to abuse trusted utilities like MSBuild.exe. |
| T1129 Shared Modules |
MalwareBLINDINGCAN | BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine. |
| T1129 Shared Modules |
MalwareBumblebee | Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.