Sub-technique of T1016 System Network Configuration Discovery.View on attack.mitre.org
Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Account Discovery, Remote System Discovery, and other discovery or Credential Access activity to support both ongoing and future campaigns.
Adversaries may collect various types of information about Wi-Fi networks from hosts. For example, on Windows names and passwords of all Wi-Fi networks a device has previously connected to may be available through `netsh wlan show profiles` to enumerate Wi-Fi names and then `netsh wlan show profile “Wi-Fi name” key=clear` to show a Wi-Fi network’s corresponding password. Additionally, names and other details of locally reachable Wi-Fi networks can be discovered using calls to `wlanAPI.dll` Native API functions.
On Linux, names and passwords of all Wi-Fi-networks a device has previously connected to may be available in files under ` /etc/NetworkManager/system-connections/`. On macOS, the password of a known Wi-Fi may be identified with ` security find-generic-password -wa wifiname` (requires admin username/password).
Rules on DetectionCode tagged with T1016.002.
| Used by | Procedure example |
|---|---|
| GroupMagic Hound | Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| MalwareCharmPower | CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details. |
| MalwareEmotet | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| MalwareMachete | Machete uses the |
| MalwarePUBLOAD | PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`. |
| Used by | Procedure example |
|---|---|
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.