ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1539
Steal Web Session Cookie
MalwareBLUELIGHT

BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1539
Steal Web Session Cookie
MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

T1539
Steal Web Session Cookie
MalwareXLoader

XLoader can capture web session cookies and session information from victim browsers.

T1539
Steal Web Session Cookie
MalwareMgBot

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

T1539
Steal Web Session Cookie
MalwareTajMahal

TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications.

T1539
Steal Web Session Cookie
MalwareRaccoon Stealer

Raccoon Stealer attempts to steal cookies and related information in browser history.

T1539
Steal Web Session Cookie
MalwareXCSSET

XCSSET uses scp to access the ~/Library/Cookies/Cookies.binarycookies file.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1539
Steal Web Session Cookie
MalwareCookieMiner

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

T1539
Steal Web Session Cookie
Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

T1539
Steal Web Session Cookie
MalwareKali365

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

T1542.001
System Firmware
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

T1542.001
System Firmware
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1542.001
System Firmware
MalwareTrojan.Mebromi

Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal.

T1542.002
Component Firmware
MalwareCyclops Blink

Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices.

T1542.003
Bootkit
MalwareTrickBot

TrickBot can implant malicious code into a compromised device's firmware.

T1542.003
Bootkit
MalwareWhisperGate

WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots.

T1542.003
Bootkit
MalwareFinFisher

Some FinFisher variants incorporate an MBR rootkit.

T1542.003
Bootkit
MalwareCarberp

Carberp has installed a bootkit on the system to maintain persistence.

T1542.003
Bootkit
MalwareROCKBOOT

ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence.

T1542.003
Bootkit
MalwareBOOTRASH

BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence.

T1543
Create or Modify System Process
MalwareBRICKSTORM

BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state.

T1543
Create or Modify System Process
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root.

T1543
Create or Modify System Process
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background.

T1543
Create or Modify System Process
MalwareIMAPLoader

IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification.

T1543
Create or Modify System Process
MalwareBOLDMOVE

BOLDMOVE can free all resources and terminate itself on victim machines.

T1543
Create or Modify System Process
MalwareAkira _v2

Akira _v2 can create a child process for encryption.

T1543
Create or Modify System Process
MalwareLunarMail

LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory.

T1543
Create or Modify System Process
MalwareCanisterWorm

CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens.

T1543.001
Launch Agent
MalwareInvisibleFerret

InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”.

T1543.001
Launch Agent
MalwaremacOS.OSAMiner

macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder.

T1543.001
Launch Agent
MalwareNETWIRE

NETWIRE can use launch agents for persistence.

T1543.001
Launch Agent
MalwareDacls

Dacls can establish persistence via a LaunchAgent.

T1543.001
Launch Agent
MalwareCuckoo Stealer

Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.

T1543.001
Launch Agent
MalwareFruitFly

FruitFly persists via a Launch Agent.

T1543.001
Launch Agent
MalwareKeydnap

Keydnap uses a Launch Agent to persist.

T1543.001
Launch Agent
MalwareGreen Lambert

Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to true, ensuring the `com.apple.GrowlHelper.plist` file runs every time a user logs in.

T1543.001
Launch Agent
MalwareThiefQuest

ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the ~/Library/LaunchAgents/ folder and configured with the path to the persistent binary located in the ~/Library/ folder.

T1543.001
Launch Agent
MalwareBundlore

Bundlore can persist via a LaunchAgent.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1543.001
Launch Agent
MalwareCrossRAT

CrossRAT creates a Launch Agent on macOS.

T1543.001
Launch Agent
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchAgents.

T1543.001
Launch Agent
MalwareCalisto

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

T1543.001
Launch Agent
MalwareProton

Proton persists via Launch Agent.

T1543.001
Launch Agent
MalwareCoinTicker

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

T1543.001
Launch Agent
MalwareCookieMiner

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

T1543.001
Launch Agent
MalwareKomplex

The Komplex trojan creates a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist with launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist.

T1543.001
Launch Agent
MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.