ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1129
Shared Modules
MalwareStuxnet

Stuxnet calls LoadLibrary then executes exports from a DLL.

T1129
Shared Modules
MalwareRotaJakiro

RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`.

T1129
Shared Modules
MalwareVersaMem

VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory.

T1129
Shared Modules
MalwareBOOSTWRITE

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

T1129
Shared Modules
MalwareLightSpy

LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class.

T1129
Shared Modules
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1129
Shared Modules
MalwareDarkWatchman

DarkWatchman can load DLLs.

T1129
Shared Modules
MalwareFoggyWeb

FoggyWeb's loader can call the load() function to load the FoggyWeb dll into an Application Domain on a compromised AD FS server.

T1129
Shared Modules
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1129
Shared Modules
MalwareMetamorfo

Metamorfo had used AutoIt to load and execute the DLL payload.

T1129
Shared Modules
MalwarePipeMon

PipeMon has used call to LoadLibrary to load its installer. PipeMon loads its modules using reflective loading or custom shellcode.

T1129
Shared Modules
Malwaregh0st RAT

gh0st RAT can load DLLs into memory.

T1129
Shared Modules
MalwareAttor

Attor's dispatcher can execute additional plugins by loading the respective DLLs.

T1129
Shared Modules
MalwareOSX_OCEANLOTUS.D

For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`.

T1129
Shared Modules
MalwareTajMahal

TajMahal has the ability to inject the LoadLibrary call template DLL into running processes.

T1129
Shared Modules
MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1129
Shared Modules
MalwareKillDisk

KillDisk loads and executes functions from a DLL.

T1129
Shared Modules
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

T1129
Shared Modules
MalwareDtrack

Dtrack contains a function that calls LoadLibrary and GetProcAddress.

T1132
Data Encoding
MalwareLinux Rabbit

Linux Rabbit sends the payload from the C2 server as an encoded URL parameter.

T1132
Data Encoding
MalwareUrsnif

Ursnif has used encoded data in HTTP URLs for C2.

T1132
Data Encoding
MalwareLAMEHUG

LAMEHUG can encode queries sent to LLMs.

T1132
Data Encoding
MalwareBADNEWS

After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64.

T1132
Data Encoding
MalwareH1N1

H1N1 obfuscates C2 traffic with an altered version of base64.

T1132
Data Encoding
Toolevilginx2

evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection.

T1132
Data Encoding
ToolMythic

Mythic provides various transform functions to encode and/or randomize C2 data.

T1132.001
Standard Encoding
MalwareTrickBot

TrickBot can Base64-encode C2 commands.

T1132.001
Standard Encoding
MalwareBLINDINGCAN

BLINDINGCAN has encoded its C2 traffic with Base64.

T1132.001
Standard Encoding
MalwarePikabot

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1132.001
Standard Encoding
MalwareSpark

Spark has encoded communications with the C2 server with base64.

T1132.001
Standard Encoding
MalwareBumblebee

Bumblebee has the ability to base64 encode C2 server responses.

T1132.001
Standard Encoding
MalwareBRICKSTORM

BRICKSTORM has leveraged Base64 to encode C2 communications.

T1132.001
Standard Encoding
MalwareTorisma

Torisma has encoded C2 communications with Base64.

T1132.001
Standard Encoding
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1132.001
Standard Encoding
MalwareStuxnet

Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.

T1132.001
Standard Encoding
MalwareRotaJakiro

RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet.

T1132.001
Standard Encoding
MalwarePOWRUNER

POWRUNER can use base64 encoded C2 communications.

T1132.001
Standard Encoding
MalwareSardonic

Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server.

T1132.001
Standard Encoding
MalwareMisdat

Misdat network traffic is Base64-encoded plaintext.

T1132.001
Standard Encoding
MalwareTAMECAT

TAMECAT has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareFelismus

Some Felismus samples use a custom method for C2 traffic that utilizes Base64.

T1132.001
Standard Encoding
MalwarexCaon

xCaon has used Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareGomir

Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEmotet

Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server.

T1132.001
Standard Encoding
MalwareMachete

Machete has used base64 encoding.

T1132.001
Standard Encoding
MalwarePrikormka

Prikormka encodes C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareGootloader

Gootloader can retrieve a Base64 encoded stager from C2.

T1132.001
Standard Encoding
MalwarePingPull

PingPull can encode C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareWellMess

WellMess has used Base64 encoding to uniquely identify communication to and from the C2.

T1132.001
Standard Encoding
MalwareMafalda

Mafalda can encode data using Base64 prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.