Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareAppleJeus | AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleJeus | AppleJeus has exfiltrated collected host information to a C2 server. |
| T1053.005 Scheduled Task |
MalwareAppleJeus | AppleJeus has created a scheduled SYSTEM task that runs when a user logs in. |
| T1059.004 Unix Shell |
MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1070.004 File Deletion |
MalwareAppleJeus | AppleJeus has deleted the MSI file after installation. |
| T1071.001 Web Protocols |
MalwareAppleJeus | AppleJeus has sent data to its C2 server via |
| T1082 System Information Discovery |
MalwareAppleJeus | AppleJeus has collected the victim host information after infection. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleJeus | AppleJeus has decoded files received from a C2. |
| T1204.001 Malicious Link |
MalwareAppleJeus | AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| T1204.002 Malicious File |
MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
| T1218.007 Msiexec |
MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| T1497.003 Time Based Checks |
MalwareAppleJeus | AppleJeus has waited a specified time before downloading a second stage payload. |
| T1543.003 Windows Service |
MalwareAppleJeus | AppleJeus can install itself as a service. |
| T1543.004 Launch Daemon |
MalwareAppleJeus | AppleJeus has placed a plist file within the |
| T1546.016 Installer Packages |
MalwareAppleJeus | During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions. |
| T1548.002 Bypass User Account Control |
MalwareAppleJeus | AppleJeus has presented the user with a UAC prompt to elevate privileges while installing. |
| T1553.002 Code Signing |
MalwareAppleJeus | AppleJeus has used a valid digital signature from Sectigo to appear legitimate. |
| T1564.001 Hidden Files and Directories |
MalwareAppleJeus | AppleJeus has added a leading |
| T1566.002 Spearphishing Link |
MalwareAppleJeus | AppleJeus has been distributed via spearphishing link. |
| T1569.001 Launchctl |
MalwareAppleJeus | AppleJeus has loaded a plist file using the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.