ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0260×

73 examples

TechniqueUsed byProcedure example
T1210
Exploitation of Remote Services
MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

T1218.002
Control Panel
MalwareInvisiMole

InvisiMole can register itself for execution and persistence via the Control Panel.

T1218.011
Rundll32
MalwareInvisiMole

InvisiMole has used rundll32.exe for execution.

T1480.001
Environmental Keying
MalwareInvisiMole

InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer.

T1490
Inhibit System Recovery
MalwareInvisiMole

InvisiMole can can remove all system restore points.

T1497.001
System Checks
MalwareInvisiMole

InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected.

T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1518.001
Security Software Discovery
MalwareInvisiMole

InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall.

T1543.003
Windows Service
MalwareInvisiMole

InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisiMole

InvisiMole can place a lnk file in the Startup Folder to achieve persistence.

T1547.009
Shortcut Modification
MalwareInvisiMole

InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence.

T1548.002
Bypass User Account Control
MalwareInvisiMole

InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges.

T1559.001
Component Object Model
MalwareInvisiMole

InvisiMole can use the ITaskService, ITaskDefinition and ITaskSettings COM interfaces to schedule a task.

T1560.001
Archive via Utility
MalwareInvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.

T1560.002
Archive via Library
MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

T1560.003
Archive via Custom Method
MalwareInvisiMole

InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration.

T1564.001
Hidden Files and Directories
MalwareInvisiMole

InvisiMole can create hidden system directories.

T1564.003
Hidden Window
MalwareInvisiMole

InvisiMole has executed legitimate tools in hidden windows.

T1569.002
Service Execution
MalwareInvisiMole

InvisiMole has used Windows services as a way to execute its malicious payload.

T1573.001
Symmetric Cryptography
MalwareInvisiMole

InvisiMole uses variations of a simple XOR encryption routine for C&C communications.

T1574.001
DLL
MalwareInvisiMole

InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library.

T1680
Local Storage Discovery
MalwareInvisiMole

InvisiMole can gather information on the mapped drives and system volume serial number.

T1686
Disable or Modify System Firewall
MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.