ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1543.003
Windows Service
MalwareDCSrv

DCSrv has created new services for persistence by modifying the Registry.

T1543.003
Windows Service
MalwareShimRat

ShimRat has installed a Windows service to maintain persistence on victim machines.

T1543.003
Windows Service
MalwareConficker

Conficker copies itself into the %systemroot%\system32 directory and registers as a service.

T1543.003
Windows Service
MalwareKeyBoy

KeyBoy installs a service pointing to a malicious DLL dropped to disk.

T1543.003
Windows Service
MalwareAnchor

Anchor can establish persistence by creating a service.

T1543.003
Windows Service
MalwareSplatDropper

SplatDropper has created a service to execute a payload.

T1543.003
Windows Service
MalwareDyre

Dyre registers itself as a service by adding several Registry keys.

T1543.003
Windows Service
MalwareBBSRAT

BBSRAT can modify service configurations.

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1543.003
Windows Service
MalwareReaver

Reaver installs itself as a new service.

T1543.003
Windows Service
MalwareBisonal

Bisonal has been modified to be used as a Windows service.

T1543.003
Windows Service
MalwareCuba

Cuba can modify services by using the OpenService and ChangeServiceConfig functions.

T1543.003
Windows Service
MalwareClambling

Clambling can register itself as a system service to gain persistence.

T1543.003
Windows Service
MalwareLockBit 3.0

LockBit 3.0 can install system services for persistence.

T1543.003
Windows Service
MalwareHydraq

Hydraq creates new services to establish persistence.

T1543.003
Windows Service
MalwareElise

Elise configures itself as a service.

T1543.003
Windows Service
MalwareWannaCry

WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service."

T1543.003
Windows Service
MalwareBriba

Briba installs a service pointing to a malicious DLL dropped to disk.

T1543.003
Windows Service
MalwareTYPEFRAME

TYPEFRAME variants can add malicious DLL modules as new services.TYPEFRAME can also delete services from the victim’s machine.

T1543.003
Windows Service
MalwareUroburos

Uroburos has registered a service, typically named `WerFaultSvc`, to decrypt and find a kernel driver and kernel driver loader to maintain persistence.

T1543.003
Windows Service
MalwareEmbargo

Embargo has created persistence through the DLL variant of the MDeployer toolkit by creating a service called irnagentd that launches after the system is rebooted in Safe Mode.

T1543.003
Windows Service
MalwarePipeMon

PipeMon can establish persistence by registering a malicious DLL as an alternative Print Processor which is loaded when the print spooler service starts.

T1543.003
Windows Service
MalwareKONNI

KONNI has registered itself as a service using its export function.

T1543.003
Windows Service
Malwaregh0st RAT

gh0st RAT can create a new service to establish persistence.

T1543.003
Windows Service
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Newer versions create the "MaintenaceSrv" and "hdv_725x" services.

T1543.003
Windows Service
MalwareJHUHUGIT

JHUHUGIT has registered itself as a service to establish persistence.

T1543.003
Windows Service
MalwareBlack Basta

Black Basta can create a new service to establish persistence.

T1543.003
Windows Service
MalwareCatchamas

Catchamas adds a new service named NetAdapter to establish persistence.

T1543.003
Windows Service
MalwareAttor

Attor's dispatcher can establish persistence by registering a new service.

T1543.003
Windows Service
MalwareStreamEx

StreamEx establishes persistence by installing a new service pointing to its DLL and setting the service to auto-start.

T1543.003
Windows Service
MalwareNightClub

NightClub has created a Windows service named `WmdmPmSp` to establish persistence.

T1543.003
Windows Service
MalwareSakula

Some Sakula samples install themselves as services for persistence by calling WinExec with the net start argument.

T1543.003
Windows Service
MalwareRawPOS

RawPOS installs itself as a service to maintain persistence.

T1543.003
Windows Service
MalwarehcdLoader

hcdLoader installs itself as a service for persistence.

T1543.003
Windows Service
MalwareNidiran

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager).

T1543.003
Windows Service
MalwareMoonWind

MoonWind installs itself as a new service with automatic startup to establish persistence. The service checks every 60 seconds to determine if the malware is running; if not, it will spawn a new instance.

T1543.003
Windows Service
MalwareCorKLOG

CorKLOG has created a service to establish persistence.

T1543.003
Windows Service
MalwareHermeticWiper

HermeticWiper can load drivers by creating a new service using the `CreateServiceW` API.

T1543.003
Windows Service
MalwarePandora

Pandora has the ability to gain system privileges through Windows services.

T1543.003
Windows Service
MalwareFinFisher

FinFisher creates a new Windows service with the malicious executable for persistence.

T1543.003
Windows Service
MalwareCobalt Strike

Cobalt Strike can install a new service.

T1543.003
Windows Service
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1543.003
Windows Service
MalwareSamurai

Samurai can create a service at `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost` to trigger execution and maintain persistence.

T1543.003
Windows Service
MalwarePoisonIvy

PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk.

T1543.003
Windows Service
MalwareSeasalt

Seasalt is capable of installing itself as a service.

T1543.003
Windows Service
MalwareCarbon

Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine.

T1543.003
Windows Service
MalwareGoldenSpy

GoldenSpy has established persistence by running in the background as an autostart service.

T1543.003
Windows Service
MalwareFunnyDream

FunnyDream has established persistence by running `sc.exe` and by setting the `WSearch` service to run automatically.

T1543.003
Windows Service
MalwareSysUpdate

SysUpdate can create a service to establish persistence.

T1543.003
Windows Service
MalwareTinyZBot

TinyZBot can install as a Windows service for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.