ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1546.003
Windows Management Instrumentation Event Subscription
ToolPoshC2

PoshC2 has the ability to persist on a system using WMI events.

T1546.004
Unix Shell Configuration Modification
MalwareRotaJakiro

When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder.

T1546.004
Unix Shell Configuration Modification
MalwareLinux Rabbit

Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files.

T1546.004
Unix Shell Configuration Modification
MalwareGreen Lambert

Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells.

T1546.004
Unix Shell Configuration Modification
MalwarePHASEJAM

PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands.

T1546.004
Unix Shell Configuration Modification
MalwareXCSSET

Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file.

T1546.007
Netsh Helper DLL
Toolnetsh

netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed.

T1546.008
Accessibility Features
ToolEmpire

Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe.

T1546.009
AppCert DLLs
MalwarePUNCHBUGGY

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

T1546.010
AppInit DLLs
MalwareT9000

If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs – %APPDATA%\Intel\ResN32.dll and HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs – 0x1.

T1546.010
AppInit DLLs
MalwareCherry Picker

Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"

T1546.010
AppInit DLLs
MalwareRamsay

Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key.

T1546.011
Application Shimming
MalwareShimRat

ShimRat has installed shim databases in the AppPatch folder.

T1546.011
Application Shimming
MalwareSDBbot

SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe.

T1546.011
Application Shimming
MalwarePillowmint

Pillowmint has used a malicious shim database to maintain persistence.

T1546.012
Image File Execution Options Injection
MalwareSDBbot

SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7.

T1546.012
Image File Execution Options Injection
MalwareSUNBURST

SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process dllhost.exe to trigger the installation of Cobalt Strike.

T1546.015
Component Object Model Hijacking
MalwareBBSRAT

BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList {42aedc87-2188-41fd-b9a3-0c966feabec1} or Microsoft WBEM New Event Subsystem {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} depending on the system's CPU architecture.

T1546.015
Component Object Model Hijacking
MalwareSVCReady

SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence.

T1546.015
Component Object Model Hijacking
MalwareFerocious

Ferocious can use COM hijacking to establish persistence.

T1546.015
Component Object Model Hijacking
MalwareKONNI

KONNI has modified ComSysApp service to load the malicious DLL payload.

T1546.015
Component Object Model Hijacking
MalwareJHUHUGIT

JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}).

T1546.015
Component Object Model Hijacking
MalwareMosquito

Mosquito uses COM hijacking as a method of persistence.

T1546.015
Component Object Model Hijacking
MalwareComRAT

ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32.

T1546.015
Component Object Model Hijacking
MalwareADVSTORESHELL

Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object.

T1546.015
Component Object Model Hijacking
MalwareWarzoneRAT

WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter.

T1546.015
Component Object Model Hijacking
ToolSILENTTRINITY

SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`.

T1546.015
Component Object Model Hijacking
ToolPcShare

PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence.

T1546.016
Installer Packages
MalwareShai-Hulud

Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`.

T1546.016
Installer Packages
MalwareAppleJeus

During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions.

T1546.016
Installer Packages
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution.

T1546.017
Udev Rules
MalwareREPTILE

REPTILE has used udev for persistence.

T1546.018
Python Startup Hooks
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup.

T1546.018
Python Startup Hooks
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution.

T1547
Boot or Logon Autostart Execution
MalwareMisdat

Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`.

T1547
Boot or Logon Autostart Execution
MalwarexCaon

xCaon has added persistence via the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load which causes the malware to run each time any user logs in.

T1547
Boot or Logon Autostart Execution
MalwareBoxCaon

BoxCaon established persistence by setting the HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load registry key to point to its executable.

T1547
Boot or Logon Autostart Execution
MalwareMis-Type

Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`.

T1547
Boot or Logon Autostart Execution
MalwareDtrack

Dtrack’s RAT makes a persistent target file with auto execution on the host start.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrickBot

TrickBot establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerDuke

PowerDuke achieves persistence by using various Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePikabot

Pikabot maintains persistence following system checks through the Run key in the registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGRIFFON

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.

T1547.001
Registry Run Keys / Startup Folder
MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNOKKI

NOKKI has established persistence by writing the payload to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvosLocker

AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareChinoxy

Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSharpStage

SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.