ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1033×

40 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
GroupAPT38

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

T1033
System Owner/User Discovery
GroupGALLIUM

GALLIUM used whoami and query user to obtain information about the victim user.

T1033
System Owner/User Discovery
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

T1033
System Owner/User Discovery
GroupKimsuky

Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1033
System Owner/User Discovery
GroupPatchwork

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1033
System Owner/User Discovery
GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

T1033
System Owner/User Discovery
GroupDragonfly

Dragonfly used the command query user on victim hosts.

T1033
System Owner/User Discovery
GroupAPT32

APT32 collected the victim's username and executed the whoami command on the victim's machine. APT32 executed shellcode to collect the username on the victim's machine.

T1033
System Owner/User Discovery
GroupHAFNIUM

HAFNIUM has used `whoami` to gather user information.

T1033
System Owner/User Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s username.

T1033
System Owner/User Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's username to send to a C2 server.

T1033
System Owner/User Discovery
GroupStorm-1811

Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.

T1033
System Owner/User Discovery
GroupFIN7

FIN7 has used the command `cmd.exe /C quser` to collect user session information.

T1033
System Owner/User Discovery
GroupSandworm Team

Sandworm Team has collected the username from a compromised host.

T1033
System Owner/User Discovery
GroupSidewinder

Sidewinder has used tools to identify the user of a compromised host.

T1033
System Owner/User Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2.

T1033
System Owner/User Discovery
GroupAPT39

APT39 used Remexi to collect usernames from the system.

T1033
System Owner/User Discovery
GroupAPT37

APT37 identifies the victim username.

T1033
System Owner/User Discovery
GroupOilRig

OilRig has run whoami on a victim.

T1033
System Owner/User Discovery
GroupTropic Trooper

Tropic Trooper used letmein to scan for saved usernames on the target system.

T1033
System Owner/User Discovery
GroupAquatic Panda

Aquatic Panda gathers information on recently logged-in users on victim devices.

T1033
System Owner/User Discovery
GroupKe3chang

Ke3chang has used implants capable of collecting the signed-in username.

T1033
System Owner/User Discovery
GroupWinter Vivern

Winter Vivern PowerShell scripts execute `whoami` to identify the executing user.

T1033
System Owner/User Discovery
GroupStealth Falcon

Stealth Falcon malware gathers the registered user and primary owner name via WMI.

T1033
System Owner/User Discovery
GroupChimera

Chimera has used the quser command to show currently logged on users.

T1033
System Owner/User Discovery
GroupMirrorFace

MirrorFace has used Windows native tools to enumerate user information.

T1033
System Owner/User Discovery
GroupMedusa Group

Medusa Group has utilized PsExec to execute `quser` to discover the user session information.

T1033
System Owner/User Discovery
GroupWindshift

Windshift has used malware to identify the username on a compromised host.

T1033
System Owner/User Discovery
GroupLuminousMoth

LuminousMoth has used a malicious DLL to collect the username from compromised hosts.

T1033
System Owner/User Discovery
GroupLazarus Group

Various Lazarus Group malware enumerates logged-on users.

T1033
System Owner/User Discovery
GroupEarth Lusca

Earth Lusca collected information on user accounts via the whoami command.

T1033
System Owner/User Discovery
GroupWizard Spider

Wizard Spider has used "whoami" to identify the local user and their privileges.

T1033
System Owner/User Discovery
GroupMoonstone Sleet

Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions.

T1033
System Owner/User Discovery
GroupHEXANE

HEXANE has run `whoami` on compromised machines to identify the current user.

T1033
System Owner/User Discovery
GroupMagic Hound

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1033
System Owner/User Discovery
GroupThreat Group-3390

Threat Group-3390 has used `whoami` to collect system user information.

T1033
System Owner/User Discovery
GroupFIN10

FIN10 has used Meterpreter to enumerate users on remote systems.

T1033
System Owner/User Discovery
GroupFIN8

FIN8 has executed the command `quser` to display the session details of a compromised machine.

T1033
System Owner/User Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.