Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1025 Data from Removable Media |
MalwareBADNEWS | BADNEWS copies files with certain extensions from USB devices to |
| T1036.001 Invalid Code Signature |
MalwareBADNEWS | BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBADNEWS | BADNEWS attempts to hide its payloads using legitimate filenames. |
| T1039 Data from Network Shared Drive |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1053.005 Scheduled Task |
MalwareBADNEWS | BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute. |
| T1055.012 Process Hollowing |
MalwareBADNEWS | BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1056.001 Keylogging |
MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1059.003 Windows Command Shell |
MalwareBADNEWS | BADNEWS is capable of executing commands via cmd.exe. |
| T1071.001 Web Protocols |
MalwareBADNEWS | BADNEWS establishes a backdoor over HTTP. |
| T1074.001 Local Data Staging |
MalwareBADNEWS | BADNEWS copies documents under 15MB found on the victim system to is the user's |
| T1083 File and Directory Discovery |
MalwareBADNEWS | BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory. |
| T1102.001 Dead Drop Resolver |
MalwareBADNEWS | BADNEWS collects C2 information via a dead drop resolver. |
| T1102.002 Bidirectional Communication |
MalwareBADNEWS | BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs. |
| T1105 Ingress Tool Transfer |
MalwareBADNEWS | BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself. |
| T1106 Native API |
MalwareBADNEWS | BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute. |
| T1113 Screen Capture |
MalwareBADNEWS | BADNEWS has a command to take a screenshot and send it to the C2 server. |
| T1119 Automated Collection |
MalwareBADNEWS | BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory. |
| T1120 Peripheral Device Discovery |
MalwareBADNEWS | BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message. |
| T1132 Data Encoding |
MalwareBADNEWS | After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64. |
| T1132.001 Standard Encoding |
MalwareBADNEWS | BADNEWS encodes C2 traffic with base64. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBADNEWS | BADNEWS installs a registry Run key to establish persistence. |
| T1573.001 Symmetric Cryptography |
MalwareBADNEWS | BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23. |
| T1574.001 DLL |
MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.