ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1548.002×

51 examples

TechniqueUsed byProcedure example
T1548.002
Bypass User Account Control
MalwareRCSession

RCSession can bypass UAC to escalate privileges.

T1548.002
Bypass User Account Control
MalwareBumblebee

Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges.

T1548.002
Bypass User Account Control
MalwareDowndelph

Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database.

T1548.002
Bypass User Account Control
MalwarePLAINTEE

An older variant of PLAINTEE performs UAC bypass.

T1548.002
Bypass User Account Control
MalwareBad Rabbit

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.

T1548.002
Bypass User Account Control
MalwareBADHATCH

BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWastedLocker

WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later.

T1548.002
Bypass User Account Control
MalwareInvisiMole

InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges.

T1548.002
Bypass User Account Control
MalwareZeroT

Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file.

T1548.002
Bypass User Account Control
MalwareRaspberry Robin

Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt.

T1548.002
Bypass User Account Control
MalwareBlackCat

BlackCat can bypass UAC to escalate privileges.

T1548.002
Bypass User Account Control
MalwareHTTPTroy

HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command.

T1548.002
Bypass User Account Control
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges.

T1548.002
Bypass User Account Control
MalwareBlackEnergy

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.

T1548.002
Bypass User Account Control
MalwareShimRat

ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing.

T1548.002
Bypass User Account Control
MalwareAvaddon

Avaddon bypasses UAC using the CMSTPLUA COM interface.

T1548.002
Bypass User Account Control
MalwareClambling

Clambling has the ability to bypass UAC using a `passuac.dll` file.

T1548.002
Bypass User Account Control
MalwareDarkGate

DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges.

T1548.002
Bypass User Account Control
MalwareLockBit 3.0

LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface.

T1548.002
Bypass User Account Control
MalwareSaint Bot

Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges.

T1548.002
Bypass User Account Control
MalwarePipeMon

PipeMon installer can use UAC bypass techniques to install the payload.

T1548.002
Bypass User Account Control
MalwareKONNI

KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify".

T1548.002
Bypass User Account Control
MalwareShamoon

Shamoon attempts to disable UAC remote restrictions by modifying the Registry.

T1548.002
Bypass User Account Control
MalwareRTM

RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges.

T1548.002
Bypass User Account Control
MalwareGrandoreiro

Grandoreiro can bypass UAC by registering as the default handler for .MSC files.

T1548.002
Bypass User Account Control
MalwareSakula

Sakula contains UAC bypass code for both 32- and 64-bit systems.

T1548.002
Bypass User Account Control
MalwareLockBit 2.0

LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`.

T1548.002
Bypass User Account Control
MalwareFinFisher

FinFisher performs UAC bypass.

T1548.002
Bypass User Account Control
MalwareCobalt Strike

Cobalt Strike can use a number of known techniques to bypass Windows UAC.

T1548.002
Bypass User Account Control
MalwareRamsay

Ramsay can use UACMe for privilege escalation.

T1548.002
Bypass User Account Control
MalwareLokibot

Lokibot has utilized multiple techniques to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWinnti for Windows

Winnti for Windows can use a variant of the sysprep UAC bypass.

T1548.002
Bypass User Account Control
MalwareKOCTOPUS

KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe.

T1548.002
Bypass User Account Control
MalwareQilin

Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.

T1548.002
Bypass User Account Control
MalwareAppleJeus

AppleJeus has presented the user with a UAC prompt to elevate privileges while installing.

T1548.002
Bypass User Account Control
MalwareGelsemium

Gelsemium can bypass UAC to elevate process privileges on a compromised host.

T1548.002
Bypass User Account Control
MalwareAutoIt backdoor

AutoIt backdoor attempts to escalate privileges by bypassing User Access Control.

T1548.002
Bypass User Account Control
MalwareH1N1

H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe).

T1548.002
Bypass User Account Control
MalwareBitPaymer

BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.

T1548.002
Bypass User Account Control
MalwareUPPERCUT

UPPERCUT contains functionality to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWarzoneRAT

WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module.

T1548.002
Bypass User Account Control
ToolUACMe

UACMe contains many methods for bypassing Windows User Account Control on multiple versions of the operating system.

T1548.002
Bypass User Account Control
ToolSliver

Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems.

T1548.002
Bypass User Account Control
ToolSILENTTRINITY

SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension.

T1548.002
Bypass User Account Control
ToolEmpire

Empire includes various modules to attempt to bypass UAC for escalation of privileges.

T1548.002
Bypass User Account Control
ToolPoshC2

PoshC2 can utilize multiple methods to bypass UAC.

T1548.002
Bypass User Account Control
ToolCSPY Downloader

CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.

T1548.002
Bypass User Account Control
ToolRemcos

Remcos has a command for UAC bypassing.

T1548.002
Bypass User Account Control
ToolKoadic

Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`.

T1548.002
Bypass User Account Control
ToolPupy

Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.