ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1222.001
Windows Permissions
MalwareCaddyWiper

CaddyWiper can modify ACL entries to take ownership of files.

T1222.001
Windows Permissions
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1222.001
Windows Permissions
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1222.001
Windows Permissions
ToolDiskpart

Diskpart can be used to display, set, or clear attributes of a disk or volume.

T1222.002
Linux and Mac Permissions
MalwareCOATHANGER

COATHANGER will set the GID of `httpsd` to 90 when infected.

T1222.002
Linux and Mac Permissions
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to modify file permissions.

T1222.002
Linux and Mac Permissions
MalwareBundlore

Bundlore changes the permissions of a payload using the command chmod -R 755.

T1222.002
Linux and Mac Permissions
MalwareBlack Basta

The Black Basta binary can use `chmod` to gain full permissions to targeted files.

T1222.002
Linux and Mac Permissions
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via chmod.

T1222.002
Linux and Mac Permissions
MalwarePenquin

Penquin can add the executable flag to a downloaded file.

T1222.002
Linux and Mac Permissions
MalwareKinsing

Kinsing has used chmod to modify permissions on key files for use.

T1222.002
Linux and Mac Permissions
MalwareXCSSET

XCSSET uses the chmod +x command to grant executable permissions to the malicious file.

T1222.002
Linux and Mac Permissions
MalwareDRYHOOK

DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.

T1222.002
Linux and Mac Permissions
MalwareOSX/Shlayer

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1222.002
Linux and Mac Permissions
MalwareDok

Dok gives all users execute permissions for the application using the command chmod +x /Users/Shared/AppStore.app.

T1480
Execution Guardrails
MalwareTorisma

Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list.

T1480
Execution Guardrails
MalwareStuxnet

Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met.

T1480
Execution Guardrails
MalwareRansomHub

RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.

T1480
Execution Guardrails
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region.

T1480
Execution Guardrails
MalwareROAMINGHOUSE

ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected.

T1480
Execution Guardrails
MalwareTONESHELL

TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`.

T1480
Execution Guardrails
MalwareEnvyScout

EnvyScout can call window.location.pathname to ensure that embedded files are being executed from the C: drive, and will terminate if they are not.

T1480
Execution Guardrails
MalwareBOLDMOVE

BOLDMOVE verifies it is executing from a specific path during execution.

T1480
Execution Guardrails
MalwareSystemBC

SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not.

T1480
Execution Guardrails
MalwareShrinkLocker

ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria.

T1480
Execution Guardrails
MalwareApostle

Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function.

T1480
Execution Guardrails
MalwareRaspberry Robin

Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script.

T1480
Execution Guardrails
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.”

T1480
Execution Guardrails
MalwareLightSpy

On macOS, LightSpy checks the existence of a process identification number (PID) file, `/Users/Shared/irc.pid`, to verify if LightSpy is currently running.

T1480
Execution Guardrails
MalwareAnchor

Anchor can terminate itself if specific execution flags are not present.

T1480
Execution Guardrails
MalwareExbyte

Exbyte checks for the presence of a configuration file before completing execution.

T1480
Execution Guardrails
MalwareLunarLoader

LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets.

T1480
Execution Guardrails
MalwarePureCrypter

PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions.

T1480
Execution Guardrails
MalwareDarkGate

DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them.

T1480
Execution Guardrails
MalwareLockBit 3.0

LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list.

T1480
Execution Guardrails
MalwareLODEINFO

LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine.

T1480
Execution Guardrails
MalwareSagerunex

Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory.

T1480
Execution Guardrails
MalwareGlassWorm

GlassWorm has utilized logic to avoid executing on Russian based devices.

T1480
Execution Guardrails
MalwareRedLine Stealer

RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host.

T1480
Execution Guardrails
MalwareBPFDoor

BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time.

T1480
Execution Guardrails
MalwareAkira _v2

Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.

T1480
Execution Guardrails
MalwareBlackByte Ransomware

BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate.

T1480
Execution Guardrails
MalwareStrelaStealer

StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables.

T1480
Execution Guardrails
MalwareVaporRage

VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.

T1480
Execution Guardrails
MalwareHiddenFace

HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found.

T1480
Execution Guardrails
MalwareLockBit 2.0

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

T1480
Execution Guardrails
MalwareNativeZone

NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components.

T1480
Execution Guardrails
MalwareROADSWEEP

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1480
Execution Guardrails
MalwareSUNSPOT

SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values.

T1480
Execution Guardrails
MalwareBoomBox

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.