ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1528
Steal Application Access Token
ToolAADInternals

AADInternals can steal users’ access tokens via phishing emails containing malicious links.

T1528
Steal Application Access Token
ToolTruffleHog

TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories.

T1528
Steal Application Access Token
ToolPeirates

Peirates gathers Kubernetes service account tokens using a variety of techniques.

T1528
Steal Application Access Token
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens.

T1528
Steal Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD.

T1528
Steal Application Access Token
MalwareCanisterWorm

CanisterWorm has gathered cloud access tokens.

T1528
Steal Application Access Token
MalwareKali365

Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure.

T1529
System Shutdown/Reboot
MalwareAcidRain

AcidRain reboots the target system once the various wiping processes are complete.

T1529
System Shutdown/Reboot
MalwareAvosLocker

AvosLocker’s Linux variant has terminated ESXi virtual machines.

T1529
System Shutdown/Reboot
MalwareOlympic Destroyer

Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings.

T1529
System Shutdown/Reboot
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system.

T1529
System Shutdown/Reboot
MalwareShrinkLocker

ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users.

T1529
System Shutdown/Reboot
MalwareApostle

Apostle reboots the victim machine following wiping and related activity.

T1529
System Shutdown/Reboot
MalwareWhisperGate

WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag.

T1529
System Shutdown/Reboot
MalwareAcidPour

AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain.

T1529
System Shutdown/Reboot
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

T1529
System Shutdown/Reboot
MalwareDCSrv

DCSrv has a function to sleep for two hours before rebooting the system.

T1529
System Shutdown/Reboot
MalwareNotPetya

NotPetya will reboot the system one hour after infection.

T1529
System Shutdown/Reboot
MalwareLockerGoga

LockerGoga has been observed shutting down infected systems.

T1529
System Shutdown/Reboot
MalwareMultiLayer Wiper

MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery.

T1529
System Shutdown/Reboot
MalwareDarkGate

DarkGate has used the `shutdown`command to shut down and/or restart the victim system.

T1529
System Shutdown/Reboot
MalwareLatrodectus

Latrodectus has the ability to restart compromised hosts.

T1529
System Shutdown/Reboot
MalwareShamoon

Shamoon will reboot the infected system once the wiping functionality has been completed.

T1529
System Shutdown/Reboot
MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

T1529
System Shutdown/Reboot
MalwareXLoader

XLoader can initiate a system reboot or shutdown.

T1529
System Shutdown/Reboot
MalwareHermeticWiper

HermeticWiper can initiate a system shutdown.

T1529
System Shutdown/Reboot
MalwareLookBack

LookBack can shutdown and reboot the victim machine.

T1529
System Shutdown/Reboot
MalwareBFG Agonizer

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

T1529
System Shutdown/Reboot
MalwareMaze

Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM.

T1529
System Shutdown/Reboot
MalwareKillDisk

KillDisk attempts to reboot the machine by terminating specific processes.

T1529
System Shutdown/Reboot
MalwareQilin

Qilin can initiate a reboot of the backup server to hinder recovery.

T1529
System Shutdown/Reboot
ToolRemcos

Remcos can shutdown and restart remote devices.

T1529
System Shutdown/Reboot
MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

T1530
Data from Cloud Storage
ToolPacu

Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets.

T1530
Data from Cloud Storage
ToolAADInternals

AADInternals can collect files from a user’s OneDrive.

T1530
Data from Cloud Storage
ToolTruffleHog

TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage.

T1530
Data from Cloud Storage
ToolPeirates

Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3.

T1531
Account Access Removal
MalwareLockerGoga

LockerGoga has been observed changing account passwords and logging off current users.

T1531
Account Access Removal
MalwareMegaCortex

MegaCortex has changed user account passwords and logged users off the system.

T1531
Account Access Removal
MalwareMeteor

Meteor has the ability to change the password of local users on compromised hosts and can log off users.

T1531
Account Access Removal
MalwareDEADWOOD

DEADWOOD changes the password for local and domain users via net.exe to a random 32 character string to prevent these accounts from logging on. Additionally, DEADWOOD will terminate the winlogon.exe process to prevent attempts to log on to the infected system.

T1534
Internal Spearphishing
MalwareSameCoin

SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization.

T1539
Steal Web Session Cookie
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.

T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1539
Steal Web Session Cookie
MalwareDarkGate

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.

T1539
Steal Web Session Cookie
MalwareChaes

Chaes has used a script that extracts the web session cookie and sends it to the C2 server.

T1539
Steal Web Session Cookie
MalwareLODEINFO

LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies.

T1539
Steal Web Session Cookie
MalwareEVILNUM

EVILNUM can harvest cookies and upload them to the C2 server.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1539
Steal Web Session Cookie
MalwareSpica

Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.