ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1543.001
Launch Agent
MalwareMacSpy

MacSpy persists via a Launch Agent.

T1543.001
Launch Agent
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds.

T1543.002
Systemd Service
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

T1543.002
Systemd Service
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1543.002
Systemd Service
MalwareGomir

Gomir creates a systemd service named `syslogd` for persistence.

T1543.002
Systemd Service
MalwareHildegard

Hildegard has started a monero service.

T1543.002
Systemd Service
MalwareFysbis

Fysbis has established persistence using a systemd service.

T1543.002
Systemd Service
MalwareSysUpdate

SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges.

T1543.002
Systemd Service
MalwareRIFLESPINE

RIFLESPINE can create a systemd service file for execution.

T1543.002
Systemd Service
MalwareShai-Hulud

Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls.

T1543.002
Systemd Service
ToolPupy

Pupy can be used to establish persistence using a systemd service.

T1543.002
Systemd Service
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence.

T1543.002
Systemd Service
MalwareMini Shai-Hulud

Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence.

T1543.003
Windows Service
MalwareTrickBot

TrickBot establishes persistence by creating an autostart service that allows it to run whenever the machine boots.

T1543.003
Windows Service
MalwareNinja

Ninja can create the services `httpsvc` and `w3esvc` for persistence .

T1543.003
Windows Service
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can create a service.

T1543.003
Windows Service
MalwareExaramel for Windows

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.”

T1543.003
Windows Service
MalwareStuxnet

Stuxnet uses a driver registered as a boot start service as the main load-point.

T1543.003
Windows Service
MalwareTDTESS

If running as administrator, TDTESS installs itself as a new service named bmwappushservice to establish persistence.

T1543.003
Windows Service
MalwareEmissary

Emissary is capable of configuring itself as a service.

T1543.003
Windows Service
MalwareUrsnif

Ursnif has registered itself as a system service in the Registry for automatic execution at system startup.

T1543.003
Windows Service
MalwareThreatNeedle

ThreatNeedle can run in memory and register its payload as a Windows service.

T1543.003
Windows Service
MalwareZLib

ZLib creates Registry keys to allow itself to run as various services.

T1543.003
Windows Service
MalwareBankshot

Bankshot can terminate a specific process by its process id.

T1543.003
Windows Service
MalwareStrongPity

StrongPity has created new services and modified existing services for persistence.

T1543.003
Windows Service
MalwareNebulae

Nebulae can create a service to establish persistence.

T1543.003
Windows Service
MalwareAuditCred

AuditCred is installed as a new service on the system.

T1543.003
Windows Service
MalwareTONESHELL

TONESHELL has created a malicious service DISMsrv to maintain persistence.

T1543.003
Windows Service
MalwareHannotog

Hannotog creates a new service for persistence.

T1543.003
Windows Service
MalwareMedusa Ransomware

Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API.

T1543.003
Windows Service
MalwareRainyDay

RainyDay can use services to establish persistence.

T1543.003
Windows Service
MalwareBOOKWORM

BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence.

T1543.003
Windows Service
MalwareCosmicDuke

CosmicDuke uses Windows services typically named "javamtsup" for persistence.

T1543.003
Windows Service
MalwareGreyEnergy

GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.

T1543.003
Windows Service
MalwareEmotet

Emotet has been observed creating new services to maintain persistence.

T1543.003
Windows Service
MalwareTEARDROP

TEARDROP ran as a Windows service from the c:\windows\syswow64 folder.

T1543.003
Windows Service
MalwareDUSTPAN

DUSTPAN can persist as a Windows Service in operations.

T1543.003
Windows Service
MalwarePingPull

PingPull has the ability to install itself as a service.

T1543.003
Windows Service
MalwareSUGARUSH

SUGARUSH has created a service named `Service1` for persistence.

T1543.003
Windows Service
MalwareWastedLocker

WastedLocker created and established a service that runs until the encryption process is complete.

T1543.003
Windows Service
MalwareInvisiMole

InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence.

T1543.003
Windows Service
MalwareNaid

Naid creates a new service to establish.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

T1543.003
Windows Service
MalwareZeroT

ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system.

T1543.003
Windows Service
MalwareRDAT

RDAT has created a service when it is installed on the victim machine.

T1543.003
Windows Service
MalwareOkrum

To establish persistence, Okrum can install itself as a new service named NtmSsvc.

T1543.003
Windows Service
MalwareKazuar

Kazuar can install itself as a new service.

T1543.003
Windows Service
MalwareRagnar Locker

Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver.

T1543.003
Windows Service
MalwareBlackEnergy

One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name.

T1543.003
Windows Service
MalwarezwShell

zwShell has established persistence by adding itself as a new service.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.