Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1005 Data from Local System |
MalwareInvisiMole | InvisiMole can collect data from the system, and can monitor changes in specified directories. |
| T1007 System Service Discovery |
MalwareInvisiMole | InvisiMole can obtain running services on the victim. |
| T1008 Fallback Channels |
MalwareInvisiMole | InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1010 Application Window Discovery |
MalwareInvisiMole | InvisiMole can enumerate windows and child windows on a compromised host. |
| T1012 Query Registry |
MalwareInvisiMole | InvisiMole can enumerate Registry values, keys, and data. |
| T1016 System Network Configuration Discovery |
MalwareInvisiMole | InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1025 Data from Removable Media |
MalwareInvisiMole | InvisiMole can collect jpeg files from connected MTP devices. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027.005 Indicator Removal from Tools |
MalwareInvisiMole | InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1033 System Owner/User Discovery |
MalwareInvisiMole | InvisiMole lists local users and session information. |
| T1036.004 Masquerade Task or Service |
MalwareInvisiMole | InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInvisiMole | InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1046 Network Service Discovery |
MalwareInvisiMole | InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1053.005 Scheduled Task |
MalwareInvisiMole | InvisiMole has used scheduled tasks named |
| T1055 Process Injection |
MalwareInvisiMole | InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure. |
| T1055.002 Portable Executable Injection |
MalwareInvisiMole | InvisiMole can inject its backdoor as a portable executable into a target process. |
| T1055.004 Asynchronous Procedure Call |
MalwareInvisiMole | InvisiMole can inject its code into a trusted process via the APC queue. |
| T1055.015 ListPlanting |
MalwareInvisiMole | InvisiMole has used ListPlanting to inject code into a trusted process. |
| T1056.001 Keylogging |
MalwareInvisiMole | InvisiMole can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareInvisiMole | InvisiMole can obtain a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareInvisiMole | InvisiMole can launch a remote shell to execute commands. |
| T1059.007 JavaScript |
MalwareInvisiMole | InvisiMole can use a JavaScript file as part of its execution chain. |
| T1068 Exploitation for Privilege Escalation |
MalwareInvisiMole | InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges. |
| T1070.004 File Deletion |
MalwareInvisiMole | InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers. |
| T1070.005 Network Share Connection Removal |
MalwareInvisiMole | InvisiMole can disconnect previously connected remote drives. |
| T1070.006 Timestomp |
MalwareInvisiMole | InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times. |
| T1071.001 Web Protocols |
MalwareInvisiMole | InvisiMole uses HTTP for C2 communications. |
| T1071.004 DNS |
MalwareInvisiMole | InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1080 Taint Shared Content |
MalwareInvisiMole | InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network. |
| T1082 System Information Discovery |
MalwareInvisiMole | InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size. |
| T1083 File and Directory Discovery |
MalwareInvisiMole | InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask. |
| T1087.001 Local Account |
MalwareInvisiMole | InvisiMole has a command to list account information on the victim’s machine. |
| T1090.001 Internal Proxy |
MalwareInvisiMole | InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareInvisiMole | InvisiMole has used TCP to download additional modules. |
| T1105 Ingress Tool Transfer |
MalwareInvisiMole | InvisiMole can upload files to the victim's machine for operations. |
| T1106 Native API |
MalwareInvisiMole | InvisiMole can use winapiexec tool for indirect execution of |
| T1112 Modify Registry |
MalwareInvisiMole | InvisiMole has a command to create, set, copy, or delete a specified Registry key or value. |
| T1113 Screen Capture |
MalwareInvisiMole | InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping. |
| T1119 Automated Collection |
MalwareInvisiMole | InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file. |
| T1123 Audio Capture |
MalwareInvisiMole | InvisiMole can record sound using input audio devices. |
| T1124 System Time Discovery |
MalwareInvisiMole | InvisiMole gathers the local system time from the victim’s machine. |
| T1125 Video Capture |
MalwareInvisiMole | InvisiMole can remotely activate the victim’s webcam to capture content. |
| T1132.002 Non-Standard Encoding |
MalwareInvisiMole | InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests. |
| T1135 Network Share Discovery |
MalwareInvisiMole | InvisiMole can gather network share information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareInvisiMole | InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher. |
| T1203 Exploitation for Client Execution |
MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| T1204.002 Malicious File |
MalwareInvisiMole | InvisiMole can deliver trojanized versions of software and documents, relying on user execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.