Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1222.001 Windows Permissions |
MalwareCaddyWiper | CaddyWiper can modify ACL entries to take ownership of files. |
| T1222.001 Windows Permissions |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1222.001 Windows Permissions |
MalwareBitPaymer | BitPaymer can use |
| T1222.001 Windows Permissions |
ToolDiskpart | Diskpart can be used to display, set, or clear attributes of a disk or volume. |
| T1222.002 Linux and Mac Permissions |
MalwareCOATHANGER | COATHANGER will set the GID of `httpsd` to 90 when infected. |
| T1222.002 Linux and Mac Permissions |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to modify file permissions. |
| T1222.002 Linux and Mac Permissions |
MalwareBundlore | Bundlore changes the permissions of a payload using the command |
| T1222.002 Linux and Mac Permissions |
MalwareBlack Basta | The Black Basta binary can use `chmod` to gain full permissions to targeted files. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via |
| T1222.002 Linux and Mac Permissions |
MalwarePenquin | Penquin can add the executable flag to a downloaded file. |
| T1222.002 Linux and Mac Permissions |
MalwareKinsing | Kinsing has used chmod to modify permissions on key files for use. |
| T1222.002 Linux and Mac Permissions |
MalwareXCSSET | XCSSET uses the |
| T1222.002 Linux and Mac Permissions |
MalwareDRYHOOK | DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1222.002 Linux and Mac Permissions |
MalwareDok | Dok gives all users execute permissions for the application using the command |
| T1480 Execution Guardrails |
MalwareTorisma | Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list. |
| T1480 Execution Guardrails |
MalwareStuxnet | Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met. |
| T1480 Execution Guardrails |
MalwareRansomHub | RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration. |
| T1480 Execution Guardrails |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region. |
| T1480 Execution Guardrails |
MalwareROAMINGHOUSE | ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected. |
| T1480 Execution Guardrails |
MalwareTONESHELL | TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`. |
| T1480 Execution Guardrails |
MalwareEnvyScout | EnvyScout can call |
| T1480 Execution Guardrails |
MalwareBOLDMOVE | BOLDMOVE verifies it is executing from a specific path during execution. |
| T1480 Execution Guardrails |
MalwareSystemBC | SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not. |
| T1480 Execution Guardrails |
MalwareShrinkLocker | ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1480 Execution Guardrails |
MalwareApostle | Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| T1480 Execution Guardrails |
MalwareRaspberry Robin | Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script. |
| T1480 Execution Guardrails |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.” |
| T1480 Execution Guardrails |
MalwareLightSpy | On macOS, LightSpy checks the existence of a process identification number (PID) file, `/Users/Shared/irc.pid`, to verify if LightSpy is currently running. |
| T1480 Execution Guardrails |
MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| T1480 Execution Guardrails |
MalwareExbyte | Exbyte checks for the presence of a configuration file before completing execution. |
| T1480 Execution Guardrails |
MalwareLunarLoader | LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets. |
| T1480 Execution Guardrails |
MalwarePureCrypter | PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions. |
| T1480 Execution Guardrails |
MalwareDarkGate | DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1480 Execution Guardrails |
MalwareLODEINFO | LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine. |
| T1480 Execution Guardrails |
MalwareSagerunex | Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory. |
| T1480 Execution Guardrails |
MalwareGlassWorm | GlassWorm has utilized logic to avoid executing on Russian based devices. |
| T1480 Execution Guardrails |
MalwareRedLine Stealer | RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host. |
| T1480 Execution Guardrails |
MalwareBPFDoor | BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time. |
| T1480 Execution Guardrails |
MalwareAkira _v2 | Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined. |
| T1480 Execution Guardrails |
MalwareBlackByte Ransomware | BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1480 Execution Guardrails |
MalwareVaporRage | VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found. |
| T1480 Execution Guardrails |
MalwareHiddenFace | HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found. |
| T1480 Execution Guardrails |
MalwareLockBit 2.0 | LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
| T1480 Execution Guardrails |
MalwareNativeZone | NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1480 Execution Guardrails |
MalwareSUNSPOT | SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values. |
| T1480 Execution Guardrails |
MalwareBoomBox | BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.