ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1195.001
Compromise Software Dependencies and Development Tools
MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareShai-Hulud

Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareXCSSET

XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods target_integrator.rb files under the /Library/Ruby/Gems folder or enumerates all .xcodeproj folders under a given directory. XCSSET then downloads a script and Mach-O file into the Xcode project folder.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareMini Shai-Hulud

Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareCanisterWorm

CanisterWorm has spread through an automated process that infects and publishes npm packages.

T1195.002
Compromise Software Supply Chain
MalwareCCBkdr

CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site.

T1195.002
Compromise Software Supply Chain
MalwareGoldenSpy

GoldenSpy has been packaged with a legitimate tax preparation software.

T1195.002
Compromise Software Supply Chain
MalwareSUNSPOT

SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product.

T1197
BITS Jobs
MalwareProLock

ProLock can use BITS jobs to download its malicious payload.

T1197
BITS Jobs
MalwareUBoatRAT

UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence.

T1197
BITS Jobs
MalwareMarkiRAT

MarkiRAT can use BITS Utility to connect with the C2 server.

T1197
BITS Jobs
MalwareBazar

Bazar has been downloaded via Windows BITS functionality.

T1197
BITS Jobs
MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

T1197
BITS Jobs
MalwareEgregor

Egregor has used BITSadmin to download and execute malicious DLLs.

T1197
BITS Jobs
MalwareJPIN

A JPIN variant downloads the backdoor payload via the BITS service.

T1197
BITS Jobs
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to launch a malicious process.

T1201
Password Policy Discovery
MalwareKwampirs

Kwampirs collects password policy information with the command net accounts.

T1201
Password Policy Discovery
ToolNet

The net accounts and net accounts /domain commands with Net can be used to obtain password policy information.

T1201
Password Policy Discovery
ToolPoshC2

PoshC2 can use Get-PassPol to enumerate the domain password policy.

T1201
Password Policy Discovery
ToolCrackMapExec

CrackMapExec can discover the password policies applied to the target system.

T1202
Indirect Command Execution
MalwareRevenge RAT

Revenge RAT uses the Forfiles utility to execute commands on the system.

T1202
Indirect Command Execution
ToolForfiles

Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd.

T1203
Exploitation for Client Execution
MalwareVersaMem

VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers.

T1203
Exploitation for Client Execution
MalwareHAWKBALL

HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload.

T1203
Exploitation for Client Execution
MalwareBankshot

Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines.

T1203
Exploitation for Client Execution
MalwareWoody RAT

Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery.

T1203
Exploitation for Client Execution
MalwareInvisiMole

InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution.

T1203
Exploitation for Client Execution
MalwareXbash

Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution.

T1203
Exploitation for Client Execution
MalwareDealersChoice

DealersChoice leverages vulnerable versions of Flash to perform execution.

T1203
Exploitation for Client Execution
MalwareXLoader

XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798.

T1203
Exploitation for Client Execution
MalwareSpeakUp

SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager.

T1203
Exploitation for Client Execution
MalwareCobalt Strike

Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460.

T1203
Exploitation for Client Execution
MalwareEvilBunny

EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader.

T1203
Exploitation for Client Execution
MalwareSUPERNOVA

SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148).

T1203
Exploitation for Client Execution
MalwareRamsay

Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570.

T1203
Exploitation for Client Execution
MalwareAgent Tesla

Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.

T1204
User Execution
MalwareRaspberry Robin

Raspberry Robin execution can rely on users directly interacting with malicious LNK files.

T1204
User Execution
MalwareLumma Stealer

Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell.

T1204.001
Malicious Link
MalwareBumblebee

Bumblebee has relied upon a user downloading a file from a OneDrive link for execution.

T1204.001
Malicious Link
MalwarePony

Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks.

T1204.001
Malicious Link
MalwareROAMINGHOUSE

ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files.

T1204.001
Malicious Link
MalwareNETWIRE

NETWIRE has been executed through convincing victims into clicking malicious links.

T1204.001
Malicious Link
MalwareEmotet

Emotet has relied upon users clicking on a malicious link delivered through spearphishing.

T1204.001
Malicious Link
MalwareGootloader

Gootloader has been executed through malicious links presented to users as internet search results.

T1204.001
Malicious Link
MalwareSquirrelwaffle

Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns.

T1204.001
Malicious Link
MalwareSnip3

Snip3 has been executed through luring victims into clicking malicious links.

T1204.001
Malicious Link
MalwareGuLoader

GuLoader has relied upon users clicking on links to malicious documents.

T1204.001
Malicious Link
MalwareObliqueRAT

ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.

T1204.001
Malicious Link
MalwareSocGholish

SocGholish has lured victims into interacting with malicious links on compromised websites for execution.

T1204.001
Malicious Link
MalwareSpicyOmelette

SpicyOmelette has been executed through malicious links within spearphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.