ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1569.002×

51 examples

TechniqueUsed byProcedure example
T1569.002
Service Execution
MalwareProxysvc

Proxysvc registers itself as a service on the victim’s machine to run as a standalone process.

T1569.002
Service Execution
MalwareStrongPity

StrongPity can install a service to execute itself as a service.

T1569.002
Service Execution
MalwareTinyTurla

TinyTurla can install itself as a service on compromised machines.

T1569.002
Service Execution
MalwareBad Rabbit

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

T1569.002
Service Execution
MalwareOlympic Destroyer

Olympic Destroyer utilizes PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareMafalda

Mafalda can create a remote service, let it run once, and then delete it.

T1569.002
Service Execution
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware executes as a service when deployed.

T1569.002
Service Execution
MalwareHOPLIGHT

HOPLIGHT has used svchost.exe to execute a malicious DLL .

T1569.002
Service Execution
MalwareWastedLocker

WastedLocker can execute itself as a service.

T1569.002
Service Execution
MalwareInvisiMole

InvisiMole has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1569.002
Service Execution
MalwareOkrum

Okrum's loader can create a new service named NtmsSvc to execute the payload.

T1569.002
Service Execution
MalwareRemoteCMD

RemoteCMD can execute commands remotely by creating a new service on the remote system.

T1569.002
Service Execution
MalwareRagnar Locker

Ragnar Locker has used sc.exe to execute a service that it creates.

T1569.002
Service Execution
MalwareNotPetya

NotPetya can use PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareHyperBro

HyperBro has the ability to start and stop a specified service.

T1569.002
Service Execution
MalwareAnchor

Anchor can create and execute services to load its payload.

T1569.002
Service Execution
MalwareBBSRAT

BBSRAT can start, stop, or delete services.

T1569.002
Service Execution
MalwareClambling

Clambling can create and start services on a compromised host.

T1569.002
Service Execution
MalwareDarkGate

DarkGate tries to elevate privileges to SYSTEM using PsExec to locally execute as a service, such as cmd /c c:\temp\PsExec.exe -accepteula -j -d -s [Target Binary].

T1569.002
Service Execution
MalwareLockBit 3.0

LockBit 3.0 can use PsExec to execute commands and payloads.

T1569.002
Service Execution
MalwareHydraq

Hydraq uses svchost.exe to execute a malicious DLL included in a new service group.

T1569.002
Service Execution
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1569.002
Service Execution
MalwareEmbargo

Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode.

T1569.002
Service Execution
Malwaregh0st RAT

gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service.

T1569.002
Service Execution
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec.

T1569.002
Service Execution
MalwareAttor

Attor's dispatcher can be executed as a service.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1569.002
Service Execution
MalwarePysa

Pysa has used PsExec to copy and execute the ransomware.

T1569.002
Service Execution
MalwarePandora

Pandora has the ability to install itself as a Windows service.

T1569.002
Service Execution
MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

T1569.002
Service Execution
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1569.002
Service Execution
MalwareIPsec Helper

IPsec Helper is run as a Windows service in victim environments.

T1569.002
Service Execution
MalwareSysUpdate

SysUpdate can manage services and processes.

T1569.002
Service Execution
MalwareZxShell

ZxShell can create a new service for execution.

T1569.002
Service Execution
MalwareWinnti for Windows

Winnti for Windows can run as a service using svchost.exe.

T1569.002
Service Execution
MalwareDEADWOOD

DEADWOOD can be executed as a service using various names, such as ScDeviceEnums.

T1569.002
Service Execution
MalwareLoudMiner

LoudMiner started the cryptomining virtual machine as a service on the infected machine.

T1569.002
Service Execution
MalwareNet Crawler

Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement.

T1569.002
Service Execution
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to start services.

T1569.002
Service Execution
MalwareHermeticWizard

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1569.002
Service Execution
ToolNet

The net start and net stop commands can be used in Net to execute or stop Windows services.

T1569.002
Service Execution
ToolImpacket

Impacket contains various modules emulating other service execution tools such as PsExec.

T1569.002
Service Execution
ToolEmpire

Empire can use PsExec to execute a payload on a remote host.

T1569.002
Service Execution
ToolPoshC2

PoshC2 contains an implementation of PsExec for remote execution.

T1569.002
Service Execution
ToolxCmd

xCmd can be used to execute binaries on remote systems by creating and starting a service.

T1569.002
Service Execution
ToolBrute Ratel C4

Brute Ratel C4 can create Windows system services for execution.

T1569.002
Service Execution
ToolWinexe

Winexe installs a service on the remote system, executes the command, then uninstalls the service.

T1569.002
Service Execution
ToolKoadic

Koadic can run a command on another machine using PsExec.

T1569.002
Service Execution
ToolPupy

Pupy uses PsExec to execute a payload or commands on a remote host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.