Millenium RAT MITRE ATT&CK Mapping
Techniques documented or strongly associated in public research, mapped across nine tactics. Every entry includes source, version, and confidence.
How does Millenium RAT map to MITRE ATT&CK? Millenium RAT behavior maps across nine MITRE ATT&CK tactics: Initial Access (phishing/social engineering), Execution, Persistence (Registry Run Keys), Credential Access (input capture, browser credentials), Discovery, Defense Evasion (sandbox evasion, masquerading, obfuscated config), Collection (screen/audio capture, local data), Exfiltration over the Telegram C2 channel, and Impact (data destruction/encryption). Mappings can differ between researchers.
Methodology: Every technique entry includes a Technique ID, name, tactic, why it applies, evidence/source, relevant Millenium RAT version, and confidence level. ATT&CK mappings can differ between researchers. No ATT&CK IDs are invented merely to fill the matrix.
Initial Access
1Execution
2Persistence
1Credential Access
2Discovery
5Defense Evasion
3Collection
4Exfiltration
1Impact
2Full technique table
| ID | Name | Tactic | Version | Source | Confidence |
|---|---|---|---|---|---|
| T1566 | Phishing | Initial Access | 2.x / 4.x | Group-IB | high |
| T1204 | User Execution | Execution | 2.x / 4.x | Group-IB | high |
| T1059 | Command and Scripting Interpreter | Execution | 4.x | Group-IB | medium |
| T1547.001 | Registry Run Keys / Startup Folder | Persistence | 2.x / 4.x | Group-IB / CYFIRMA | high |
| T1056 | Input Capture | Credential Access | 2.x / 4.x | Symantec / Group-IB | high |
| T1555.003 | Credentials from Web Browsers | Credential Access | 2.x / 4.x | Symantec / Group-IB | high |
| T1057 | Process Discovery | Discovery | 2.x / 4.x | CYFIRMA / Group-IB | high |
| T1083 | File and Directory Discovery | Discovery | 4.x | Group-IB | medium |
| T1033 | System Owner/User Discovery | Discovery | 2.x / 4.x | CYFIRMA | high |
| T1082 | System Information Discovery | Discovery | 2.x / 4.x | CYFIRMA / Group-IB | high |
| T1518.001 | Software Discovery: Security Software | Discovery | 2.x / 4.x | CYFIRMA | high |
| T1497 | Virtualization/Sandbox Evasion | Defense Evasion | 2.x / 4.x | CYFIRMA / Group-IB | high |
| T1036 | Masquerading | Defense Evasion | 4.x | Group-IB | high |
| T1027 | Obfuscated Files or Information | Defense Evasion | 4.x | Group-IB | high |
| T1113 | Screen Capture | Collection | 2.x / 4.x | Symantec / Group-IB | high |
| T1123 | Audio Capture | Collection | 4.x | Group-IB | medium |
| T1119 | Automated Collection | Collection | 4.x | Group-IB | medium |
| T1005 | Data from Local System | Collection | 2.x / 4.x | Group-IB | high |
| T1041 | Exfiltration Over C2 Channel | Exfiltration | 2.x / 4.x | Group-IB / CYFIRMA | high |
| T1485 | Data Destruction | Impact | 4.x | Group-IB | medium |
| T1486 | Data Encrypted for Impact | Impact | 4.x | Group-IB | medium |
- ▸Millenium RAT maps across all nine major ATT&CK tactics.
- ▸Persistence: Registry Run Keys (T1547.001) is consistently documented.
- ▸Credential Access: input capture (T1056) and browser credentials (T1555.003).
- ▸Defense Evasion: sandbox evasion (T1497), masquerading (T1036), obfuscated config (T1027).
- ▸Mappings can differ between researchers; confidence is stated per technique.

