Meta tags:
Headings (most frequently used words):
audio, capture, procedure, examples, mitigations, detection, strategy, references,
Text of the page (most frequently used words):
retrieved (44), the (33), audio (31), 2018 (24), and (23), #capture (18), can (17), rat (15), november (14), april (13), 2019 (13), malware (12), may (12), 2017 (12), microphone (12), has (12), att (10), all (10), july (10), february (9), from (9), 2020 (8), devices (8), record (8), enterprise (7), techniques (7), september (7), for (7), 2026 (6), data (6), march (6), with (6), 2024 (6), system (6), ics (5), mobile (5), none (5), new (5), apt (5), 2016 (5), uses (5), powersploit (5), august (5), using (5), input (5), mitre (4), detection (4), january (4), october (4), june (4), threat (4), remcos (4), 2023 (4), group (4), machete (4), invisimole (4), flame (4), darkcomet (4), perform (4), recording (4), version (4), are (3), software (3), cti (3), mitigations (3), defenses (3), sub (3), government (3), targets (3), vermin (3), used (3), tajmahal (3), framework (3), t9000 (3), analysis (3), revenge (3), 2012 (3), nanocore (3), micropsia (3), team (3), macma (3), through (3), lightspy (3), targeting (3), macos (3), gostev (3), 2013 (3), janicab (3), part (3), imminent (3), monitor (3), dogcall (3), cobian (3), based (3), apt37 (3), attor (3), processes (3), accessing (3), followed (3), t1123 (3), ability (3), module (3), sound (3), microphones (3), computer (3), captures (3), recordings (3), victim (3), machine (3), capable (3), that (3), 2015 (2), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), fbi (2), flash (2), iran (2), cyber (2), deploy (2), great (2), grunzweig (2), support (2), operation (2), campaign (2), victims (2), espionage (2), actor (2), via (2), updates (2), chinese (2), wardle (2), mac (2), 2021 (2), osx (2), intelligence (2), research (2), attacks (2), 2014 (2), platform (2), signed (2), hromcova (2), since (2), december (2), reaper (2), fireeye (2), temp (2), spy (2), avfoundation (2), logs (2), files (2), disk (2), file (2), dll (2), writes (2), strategy (2), windows (2), linux (2), analytic (2), description (2), name (2), technique (2), void (2), manticore (2), application (2), infected (2), host (2), skype (2), api (2), video (2), rokrat (2), plugin (2), pupy (2), exfiltration (2), get (2), leverage (2), nightclub (2), mgbot (2), macspy (2), jrat (2), capability (2), evilgrab (2), derusbi (2), conversations (2), crimson (2), voice (2), cadelspy (2), capturing (2), bandook (2), available (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, 20260320, 001, actors, telegram, push, identified, lancaster, cortes, quasar, custom, ukraine, project, sophisticated, miller, osborn, advanced, modular, backdoor, complex, anti, scarcruft, continues, evolve, introduces, bluetooth, harvester, gannon, upgrades, delivery, infrastructure, bigger, livelli, shaheen, zhang, exploit, bacurio, salvio, wild, nicolas, verdier, powershellmafia, powershell, post, exploitation, faou, moustachedbouncer, against, foreign, diplomats, belarus, kasza, halfpop, nanocorerat, behind, increase, tax, themed, phishing, mails, digitrust, not, your, average, tsarfaty, hunter, daggerfly, telecoms, company, africa, facundo, muñoz, evasive, panda, delivers, popular, patrick, cdds, 2022, kate, steals, venezuelan, military, secrets, provide, reactionaries, hpreact, cylance, cut, latam, kaspersky, global, stuart, ashenbrenner, alden, schmidt, variant, 2025, kamluk, adwind, cross, thomas, called, brod, right, left, override, trick, cherpanov, hidden, story, hromcová, surprisingly, equipped, spyware, undercover, qianxin, center, continuous, colombian, institutions, corporations, unit, down, under, bunny, frog, munch, beetlejuice, questions, answers, pwc, bae, systems, cloud, hopper, technical, annex, nokki, almost, ties, knot, suspected, periscope, engineering, maritime, industries, kujawa, you, dirty, trendmicro, dedola, transparent, tribe, evolution, yadav, backdoored, symantec, security, response, attackers, back, door, threats, middle, eastern, galperin, got, letter, other, day, overlooked, north, korean, commands, tor, communications, meet, fantasy, creature, also, references, invoking, coreaudio, frameworks, tcc, unified, writing, aiff, wav, mp3, an0621, alsa, pulseaudio, executing, binaries, like, arecord, creation, suspicious, child, process, spawning, an0620, unusual, unauthorized, apis, winmm, avrt, user, accessible, directories, an0619, behavioral, across, det0221, this, type, attack, cannot, easily, mitigated, preventive, controls, abuse, features, gathered, during, zoom, session, g1055, s0257, voiceip, s0467, calls, encrypted, appdata, intel, s0098, eavesdropping, s0240, interception, s0379, s0332, s0192, microphoneaudio, s0194, load, lame, encoder, control, mcisendstringw, s1090, feeds, s0336, s0339, output, streams, s1146, sounds, s0282, s1016, s0409, apple, built, library, manage, then, transform, them, json, blobs, s1185, s0283, captured, sent, out, server, s0163, s0260, remote, monitoring, s0434, any, existing, hardware, s0143, s0152, s0213, performing, s0021, listen, s0334, surveillance, s0115, feature, s0338, compromised, s0454, modules, s0234, s0438, utility, known, soundwave, g0067, procedure, examples, live, permalink, last, modified, created, platforms, collection, tactic, scripts, interact, provided, operating, written, exfiltrated, later, adversary, peripheral, webcams, applications, call, services, purpose, listening, into, sensitive, gather, information, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, learn, more, about, started, detections,
Text of the page (random words):
audio capture technique t1123 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise audio capture audio capture an adversary can leverage a computer s peripheral devices e g microphones and webcams or applications e g voice and video call services to capture audio recordings for the purpose of listening into sensitive conversations to gather information 1 malware or scripts may be used to interact with the devices through an available api provided by the operating system or an application to capture audio audio files may be written to disk and exfiltrated later id t1123 sub techniques no sub techniques ⓘ tactic collection ⓘ platforms linux windows macos version 1 0 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description g0067 apt37 apt37 has used an audio capturing utility known as soundwave that captures microphone input 2 s0438 attor attor s has a plugin that is capable of recording audio using available input sound devices 1 s0234 bandook bandook has modules that are capable of capturing audio 3 s0454 cadelspy cadelspy has the ability to record audio from the compromised host 4 s0338 cobian rat cobian rat has a feature to perform voice recording on the victim s machine 5 s0115 crimson crimson can perform audio surveillance using microphones 6 s0334 darkcomet darkcomet can listen in to victims conversations through the system s microphone 7 8 s0021 derusbi derusbi is capable of performing audio captures 9 s0213 dogcall dogcall can capture microphone data from the victim s machine 10 s0152 evilgrab evilgrab has the capability to capture audio from a victim machine 11 s0143 flame flame can record audio using any existing hardware recording devices 12 13 s0434 imminent monitor imminent monitor has a remote microphone monitoring capability 14 15 s0260 invisimole invisimole can record sound using input audio devices 16 17 s0163 janicab janicab captured audio and sent it out to a c2 server 18 19 s0283 jrat jrat can capture microphone recordings 20 s1185 lightspy lightspy uses apple s built in avfoundation framework library to capture and manage audio recordings then transform them to json blobs for exfiltration 21 s0409 machete machete captures audio from the computer s microphone 22 23 24 s1016 macma macma has the ability to record audio 25 s0282 macspy macspy can record the sounds from microphones on a computer 26 s1146 mgbot mgbot can capture input and output audio streams from infected devices 27 28 s0339 micropsia micropsia can perform microphone recording 29 s0336 nanocore nanocore can capture audio feeds from the system 30 31 s1090 nightclub nightclub can load a module to leverage the lame encoder and mcisendstringw to control and capture audio 32 s0194 powersploit powersploit s get microphoneaudio exfiltration module can record system microphone audio 33 34 s0192 pupy pupy can record sound with the microphone 35 s0332 remcos remcos can capture data from the system s microphone 36 37 s0379 revenge rat revenge rat has a plugin for microphone interception 38 39 s0240 rokrat rokrat has an audio capture and eavesdropping module 40 s0098 t9000 t9000 uses the skype api to record audio and video calls it writes encrypted data to appdata intel skype 41 s0467 tajmahal tajmahal has the ability to capture voiceip application audio on an infected host 42 s0257 vermin vermin can perform audio capture 43 g1055 void manticore void manticore has gathered audio during a zoom session 44 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0221 behavioral detection strategy for t1123 audio capture across windows linux macos an0619 unusual or unauthorized processes accessing microphone apis e g winmm dll avrt dll followed by audio file writes to user accessible or temp directories an0620 processes accessing alsa pulseaudio devices or executing audio capture binaries like arecord followed by file creation or suspicious child process spawning an0621 processes invoking avfoundation or coreaudio frameworks accessing input devices via tcc logs or unified logs followed by writing aiff wav mp3 files to disk references hromcova z 2019 october at commands tor based communications meet attor a fantasy creature and also a spy platform retrieved may 6 2020 fireeye 2018 february 20 apt37 reaper the overlooked north korean actor retrieved november 17 2024 galperin e et al 2016 august i got a letter from the government the other day retrieved april 25 2018 symantec security response 2015 december 7 iran based attackers use back door threats to spy on middle eastern targets retrieved april 17 2019 yadav a et al 2017 august 31 cobian rat a backdoored rat retrieved november 13 2018 dedola g 2020 august 20 transparent tribe evolution analysis part 1 retrieved september 2 2021 trendmicro 2014 september 03 darkcomet retrieved november 6 2018 kujawa a 2018 march 27 you dirty rat part 1 darkcomet retrieved november 6 2018 fireeye 2018 march 16 suspected chinese cyber espionage group temp periscope targeting u s engineering and maritime industries retrieved april 11 2018 grunzweig j 2018 october 01 nokki almost ties the knot with dogcall reaper group uses new malware to deploy rat retrieved november 5 2018 pwc and bae systems 2017 april operation cloud hopper technical annex retrieved april 13 2017 gostev a 2012 may 28 the flame questions and answers retrieved march 1 2017 gostev a 2012 may 30 flame bunny frog munch and beetlejuice retrieved march 1 2017 unit 42 2019 december 2 imminent monitor a rat down under retrieved may 5 2020 qianxin threat intelligence center 2019 february 18 apt c 36 continuous attacks targeting colombian government institutions and corporations retrieved may 5 2020 hromcová z 2018 june 07 invisimole surprisingly equipped spyware undercover since 2013 retrieved july 10 2018 hromcova z and cherpanov a 2020 june invisimole the hidden part of the story retrieved july 16 2020 brod 2013 july 15 signed mac malware using right to left override trick retrieved july 17 2017 thomas 2013 july 15 new signed malware called janicab retrieved july 17 2017 kamluk v gostev a 2016 february adwind a cross platform rat retrieved april 23 2019 stuart ashenbrenner alden schmidt 2024 april 25 lightspy malware variant targeting macos retrieved january 3 2025 kaspersky global research and analysis team 2014 august 20 el machete retrieved september 13 2019 the cylance threat research team 2017 march 22 el machete s malware attacks cut through latam retrieved september 13 2019 kate 2020 september 25 apt c 43 steals venezuelan military secrets to provide intelligence support for the reactionaries hpreact campaign retrieved november 20 2020 wardle p 2021 november 11 osx cdds osx macma retrieved june 30 2022 patrick wardle n d mac malware of 2017 retrieved september 21 2018 facundo muñoz 2023 april 26 evasive panda apt group delivers malware via updates for popular chinese software retrieved july 25 2024 threat hunter team 2023 april 20 daggerfly apt actor targets telecoms company in africa retrieved july 25 2024 tsarfaty y 2018 july 25 micropsia malware retrieved november 13 2018 the digitrust group 2017 january 01 nanocore is not your average rat retrieved november 9 2018 kasza a halfpop t 2016 february 09 nanocorerat behind an increase in tax themed phishing e mails retrieved november 9 2018 faou m 2023 august 10 moustachedbouncer espionage against foreign diplomats in belarus retrieved september 25 2023 powershellmafia 2012 may 26 powersploit a powershell post exploitation framework retrieved february 6 2018 powersploit n d powersploit retrieved february 6 2018 nicolas verdier n d retrieved january 29 2018 bacurio f salvio j 2017 february 14 remcos a new rat in the wild retrieved november 6 2018 zhang x 2024 november 8 new campaign uses remcos rat to exploit victims retrieved april 16 2026 livelli k et al 2018 november 12 operation shaheen retrieved may 1 2019 gannon m 2019 february 11 with upgrades in delivery and support infrastructure revenge rat malware is a bigger threat retrieved november 17 2024 great 2019 may 13 scarcruft continues to evolve introduces bluetooth harvester retrieved june 4 2019 grunzweig j and miller osborn j 2016 february 4 t9000 advanced modular backdoor uses complex anti analysis techniques retrieved april 15 2016 great 2019 april 10 project tajmahal a sophisticated new apt framework retrieved october 14 2019 lancaster t cortes j 2018 january 29 vermin quasar rat and custom malware used in ukraine retrieved july 5 2018 fbi 2026 march 20 fbi flash flash 20260320 001 government of iran cyber actors deploy telegram c2 to push malware to identified targets retrieved april 20 2026 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|