Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1559 Inter-Process Communication |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process. |
| T1559 Inter-Process Communication |
MalwarePITSTOP | PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`. |
| T1559 Inter-Process Communication |
MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| T1559 Inter-Process Communication |
MalwareMini Shai-Hulud | Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory. |
| T1559.001 Component Object Model |
MalwareTrickBot | TrickBot used COM to setup scheduled task for persistence. |
| T1559.001 Component Object Model |
MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| T1559.001 Component Object Model |
MalwareUrsnif | Ursnif droppers have used COM objects to execute the malware's full executable payload. |
| T1559.001 Component Object Model |
MalwareSTATICPLUGIN | STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file. |
| T1559.001 Component Object Model |
MalwareInvisiMole | InvisiMole can use the |
| T1559.001 Component Object Model |
MalwareCLAIMLOADER | CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface. |
| T1559.001 Component Object Model |
MalwareNeoichor | Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2. |
| T1559.001 Component Object Model |
MalwareRaspberry Robin | Raspberry Robin creates an elevated COM object for |
| T1559.001 Component Object Model |
MalwareRustyWater | RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
| T1559.001 Component Object Model |
MalwareDarkTortilla | DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1559.001 Component Object Model |
MalwareMilan | Milan can use a COM component to generate scheduled tasks. |
| T1559.001 Component Object Model |
MalwareRamsay | Ramsay can use the Windows COM API to schedule tasks and maintain persistence. |
| T1559.001 Component Object Model |
MalwareFunnyDream | FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms. |
| T1559.001 Component Object Model |
MalwarePOWERSTATS | POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts. |
| T1559.001 Component Object Model |
MalwareGelsemium | Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process. |
| T1559.001 Component Object Model |
MalwareHermeticWizard | HermeticWizard can execute files on remote machines using DCOM. |
| T1559.001 Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object. |
| T1559.002 Dynamic Data Exchange |
MalwareHAWKBALL | HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode. |
| T1559.002 Dynamic Data Exchange |
MalwareGravityRAT | GravityRAT has been delivered via Word documents using DDE for execution. |
| T1559.002 Dynamic Data Exchange |
MalwareKeyBoy | KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads. |
| T1559.002 Dynamic Data Exchange |
MalwareRTM | RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism. |
| T1559.002 Dynamic Data Exchange |
MalwareValak | Valak can execute tasks via OLE. |
| T1559.002 Dynamic Data Exchange |
MalwareRamsay | Ramsay has been delivered using OLE objects in malicious documents. |
| T1559.002 Dynamic Data Exchange |
MalwarePoetRAT | PoetRAT was delivered with documents using DDE to execute malicious code. |
| T1559.002 Dynamic Data Exchange |
MalwarePOWERSTATS | POWERSTATS can use DDE to execute additional payloads on compromised hosts. |
| T1560 Archive Collected Data |
MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareExaramel for Windows | Exaramel for Windows automatically encrypts files before sending them to the C2 server. |
| T1560 Archive Collected Data |
MalwareJumbledPath | JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices. |
| T1560 Archive Collected Data |
MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
| T1560 Archive Collected Data |
MalwareLurid | Lurid can compress data before sending it. |
| T1560 Archive Collected Data |
MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareNETWIRE | NETWIRE has the ability to compress archived screenshots. |
| T1560 Archive Collected Data |
MalwareAria-body | Aria-body has used ZIP to compress data gathered on a compromised host. |
| T1560 Archive Collected Data |
MalwareMachete | Machete stores zipped files with profile data from installed web browsers. |
| T1560 Archive Collected Data |
MalwarePowerLess | PowerLess can encrypt browser database files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwarePrikormka | After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish. |
| T1560 Archive Collected Data |
MalwareLoFiSe | LoFiSe can collect files into password-protected ZIP-archives for exfiltration. |
| T1560 Archive Collected Data |
MalwareVERMIN | VERMIN encrypts the collected files using 3-DES. |
| T1560 Archive Collected Data |
MalwareChrommme | Chrommme can encrypt and store on disk collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareRunningRAT | RunningRAT contains code to compress files. |
| T1560 Archive Collected Data |
MalwareEpic | Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server. |
| T1560 Archive Collected Data |
MalwareLightNeuron | LightNeuron contains a function to encrypt and store emails that it collects. |
| T1560 Archive Collected Data |
MalwareMuddyViper | MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
| T1560 Archive Collected Data |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used |
| T1560 Archive Collected Data |
MalwareLP-Notes | LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.