ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1553.005
Mark-of-the-Web Bypass
GroupAPT38

APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures.

T1553.005
Mark-of-the-Web Bypass
GroupTA505

TA505 has used .iso files to deploy malicious .lnk files.

T1553.005
Mark-of-the-Web Bypass
GroupAPT29

APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web.

T1553.006
Code Signing Policy Modification
GroupAPT39

APT39 has used malware to turn off the RequireSigned feature which ensures only signed DLLs can be run on Windows.

T1553.006
Code Signing Policy Modification
GroupTurla

Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges.

T1554
Compromise Host Software Binary
GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

T1554
Compromise Host Software Binary
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

T1555
Credentials from Password Stores
GroupVolt Typhoon

Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.

T1555
Credentials from Password Stores
GroupAPT41

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.

T1555
Credentials from Password Stores
GroupEvilnum

Evilnum can collect email credentials from victims.

T1555
Credentials from Password Stores
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.

T1555
Credentials from Password Stores
GroupFIN6

FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP.

T1555
Credentials from Password Stores
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555
Credentials from Password Stores
GroupAPT39

APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords.

T1555
Credentials from Password Stores
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555
Credentials from Password Stores
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook.

T1555
Credentials from Password Stores
GroupMalteiro

Malteiro has obtained credentials from mail clients via NirSoft MailPassView.

T1555
Credentials from Password Stores
GroupHEXANE

HEXANE has run `cmdkey` on victim machines to identify stored credentials.

T1555
Credentials from Password Stores
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.001
Keychain
GroupContagious Interview

Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain.

T1555.003
Credentials from Web Browsers
GroupAPT3

APT3 has used tools to dump passwords from browsers.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1555.003
Credentials from Web Browsers
GroupVolt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.

T1555.003
Credentials from Web Browsers
GroupPatchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.

T1555.003
Credentials from Web Browsers
GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

T1555.003
Credentials from Web Browsers
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555.003
Credentials from Web Browsers
GroupSandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.

T1555.003
Credentials from Web Browsers
GroupZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupTA505

TA505 has used malware to gather credentials from Internet Explorer.

T1555.003
Credentials from Web Browsers
GroupRedCurl

RedCurl used LaZagne to obtain passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
GroupMalteiro

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.

T1555.003
Credentials from Web Browsers
GroupAPT42

APT42 has used custom malware to steal credentials.

T1555.003
Credentials from Web Browsers
GroupLAPSUS$

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.

T1555.003
Credentials from Web Browsers
GroupMolerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1555.003
Credentials from Web Browsers
GroupInception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.

T1555.003
Credentials from Web Browsers
GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAjax Security Team

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.004
Windows Credential Manager
GroupOilRig

OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
GroupTurla

Turla has gathered credentials from the Windows Credential Manager tool.

T1555.004
Windows Credential Manager
GroupStealth Falcon

Stealth Falcon malware gathers passwords from the Windows Credential Vault.

T1555.004
Windows Credential Manager
GroupWizard Spider

Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.

T1555.005
Password Managers
GroupIndrik Spider

Indrik Spider has accessed and exported passwords from password managers.

T1555.005
Password Managers
GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

T1555.005
Password Managers
GroupUNC3886

UNC3886 has targeted KeyPass password database files for credential access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.