ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1553.002×

53 examples

TechniqueUsed byProcedure example
T1553.002
Code Signing
MalwareTrickBot

TrickBot has come with a signed downloader component.

T1553.002
Code Signing
MalwareBLINDINGCAN

BLINDINGCAN has been signed with code-signing certificates such as CodeRipper.

T1553.002
Code Signing
MalwareStuxnet

Stuxnet used a digitally signed driver with a compromised Realtek certificate.

T1553.002
Code Signing
MalwarePAKLOG

PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading.

T1553.002
Code Signing
MalwareStrongPity

StrongPity has been signed with self-signed certificates.

T1553.002
Code Signing
MalwareJanicab

Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions.

T1553.002
Code Signing
MalwareTONESHELL

TONESHELL has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
MalwareEcipekac

Ecipekac has used a valid, legitimate digital signature to evade detection.

T1553.002
Code Signing
MalwareBOOKWORM

BOOKWORM has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
MalwareSTATICPLUGIN

STATICPLUGIN has been signed with a valid Certificate Authority(CA) to circumvent endpoint defenses.

T1553.002
Code Signing
MalwareGreyEnergy

GreyEnergy digitally signs the malware with a code-signing certificate.

T1553.002
Code Signing
MalwarePUBLOAD

PUBLOAD has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate.

T1553.002
Code Signing
MalwareBOOSTWRITE

BOOSTWRITE has been signed by a valid CA.

T1553.002
Code Signing
MalwareSpicyOmelette

SpicyOmelette has been signed with valid digital certificates.

T1553.002
Code Signing
MalwareLockerGoga

LockerGoga has been signed with stolen certificates in order to make it look more legitimate.

T1553.002
Code Signing
MalwareAnchor

Anchor has been signed with valid certificates to evade detection by security tools.

T1553.002
Code Signing
MalwareSplatDropper

SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1553.002
Code Signing
MalwareLumma Stealer

Lumma Stealer has used valid code signing digital certificates from ConsolHQ LTD and Verandah Green Limited to appear legitimate.

T1553.002
Code Signing
MalwareEpic

Turla has used valid digital certificates from Sysprint AG to sign its Epic dropper.

T1553.002
Code Signing
MalwareGazer

Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd."

T1553.002
Code Signing
MalwareMetamorfo

Metamorfo has digitally signed executables using AVAST Software certificates.

T1553.002
Code Signing
MalwareBandook

Bandook was signed with valid Certum certificates.

T1553.002
Code Signing
MalwarePipeMon

PipeMon, its installer, and tools are signed with stolen code-signing certificates.

T1553.002
Code Signing
MalwareRedLine Stealer

RedLine Stealer has used both valid certificates and self-signed digital certificates to appear legitimate.

T1553.002
Code Signing
MalwareBlack Basta

The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives.

T1553.002
Code Signing
MalwareRTM

RTM samples have been signed with a code-signing certificates.

T1553.002
Code Signing
MalwareStrelaStealer

StrelaStealer variants have used valid code signing certificates.

T1553.002
Code Signing
MalwareGoBear

GoBear uses stolen legitimate code signing certificates for defense evasion.

T1553.002
Code Signing
MalwareBazar

Bazar has been signed with fake certificates including those appearing to be from VB CORPORATE PTY. LTD.

T1553.002
Code Signing
MalwareCorKLOG

CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1553.002
Code Signing
MalwareHermeticWiper

The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd.

T1553.002
Code Signing
MalwareCobalt Strike

Cobalt Strike can use self signed Java applets to execute signed applet attacks.

T1553.002
Code Signing
MalwareSUNBURST

SUNBURST was digitally signed by SolarWinds from March - May 2020.

T1553.002
Code Signing
MalwareDaserf

Some Daserf samples were signed with a stolen digital certificate.

T1553.002
Code Signing
MalwareMacMa

MacMa has been delivered using ad hoc Apple Developer code signing certificates.

T1553.002
Code Signing
MalwareROADSWEEP

ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC.

T1553.002
Code Signing
MalwareMore_eggs

More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell.

T1553.002
Code Signing
MalwareSysUpdate

SysUpdate has been signed with stolen digital certificates.

T1553.002
Code Signing
MalwareBackConfig

BackConfig has been signed with self signed digital certificates mimicking a legitimate software company.

T1553.002
Code Signing
MalwareNerex

Nerex drops a signed Microsoft DLL to disk.

T1553.002
Code Signing
MalwareClop

Clop can use code signing to evade detection.

T1553.002
Code Signing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate.

T1553.002
Code Signing
MalwareTroll Stealer

Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates.

T1553.002
Code Signing
MalwareEbury

Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems.

T1553.002
Code Signing
MalwareChChes

ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked.

T1553.002
Code Signing
MalwareAppleJeus

AppleJeus has used a valid digital signature from Sectigo to appear legitimate.

T1553.002
Code Signing
MalwareQakBot

QakBot can use signed loaders to evade detection.

T1553.002
Code Signing
MalwareHelminth

Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared.

T1553.002
Code Signing
MalwareHermeticWizard

HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.