ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1560.003
Archive via Custom Method
MalwareFunnyDream

FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content.

T1560.003
Archive via Custom Method
MalwaremetaMain

metaMain has used XOR-based encryption for collected files before exfiltration.

T1560.003
Archive via Custom Method
MalwareADVSTORESHELL

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.

T1560.003
Archive via Custom Method
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

T1561.001
Disk Content Wipe
MalwareAcidRain

AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it.

T1561.001
Disk Content Wipe
MalwareApostle

Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity.

T1561.001
Disk Content Wipe
MalwareWhisperGate

WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets.

T1561.001
Disk Content Wipe
MalwareAcidPour

AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content.

T1561.001
Disk Content Wipe
MalwareBlackCat

BlackCat has the ability to wipe VM snapshots on compromised networks.

T1561.001
Disk Content Wipe
MalwareVPNFilter

VPNFilter has the capability to wipe a portion of an infected device's firmware.

T1561.001
Disk Content Wipe
MalwareDarkGate

DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`.

T1561.001
Disk Content Wipe
MalwareStoneDrill

StoneDrill can wipe the accessible physical or logical drives of the infected machine.

T1561.001
Disk Content Wipe
MalwareMegaCortex

MegaCortex can wipe deleted data from all drives using cipher.exe.

T1561.001
Disk Content Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data.

T1561.001
Disk Content Wipe
MalwareDEADWOOD

DEADWOOD deletes files following overwriting them with random data.

T1561.001
Disk Content Wipe
ToolRawDisk

RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.

T1561.001
Disk Content Wipe
Toolcipher.exe

cipher.exe can be used to overwrite deleted data in specified folders.

T1561.002
Disk Structure Wipe
MalwareShrinkLocker

ShrinkLocker has used Diskpart to format newly-created partitions.

T1561.002
Disk Structure Wipe
MalwareWhisperGate

WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader.

T1561.002
Disk Structure Wipe
MalwareMultiLayer Wiper

MultiLayer Wiper opens a handle to \\\\\\\\.\\\\PhysicalDrive0 and wipes the first 512 bytes of data from this location, removing the boot sector.

T1561.002
Disk Structure Wipe
MalwareShamoon

Shamoon has been seen overwriting features of disk structure such as the MBR.

T1561.002
Disk Structure Wipe
MalwareStoneDrill

StoneDrill can wipe the master boot record of an infected computer.

T1561.002
Disk Structure Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives.

T1561.002
Disk Structure Wipe
MalwareCaddyWiper

CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.

T1561.002
Disk Structure Wipe
MalwareBFG Agonizer

BFG Agonizer retrieves a device handle to \\\\.\\PhysicalDrive0 to wipe the boot sector of a given disk.

T1561.002
Disk Structure Wipe
MalwareKillDisk

KillDisk overwrites the first sector of the Master Boot Record with “0x00”.

T1561.002
Disk Structure Wipe
MalwareDEADWOOD

DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code IOCTL_DISK_DELETE_DRIVE_LAYOUT to ensure the MBR is removed from the drive.

T1561.002
Disk Structure Wipe
ToolDiskpart

Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk.

T1561.002
Disk Structure Wipe
ToolRawDisk

RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.

T1561.002
Disk Structure Wipe
MalwareZeroCleare

ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts.

T1563.001
SSH Hijacking
MalwareMEDUSA

MEDUSA can be configured to capture SSH credentials via SSH hijacking.

T1563.002
RDP Hijacking
MalwareWannaCry

WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session.

T1564
Hide Artifacts
MalwareDarkTortilla

DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry.

T1564
Hide Artifacts
MalwareNOOPLDR

NOOPLDR can hide services used to aid execution.

T1564
Hide Artifacts
MalwareBundlore

Bundlore uses the mktemp utility to make unique file and directory names for payloads, such as TMP_DIR=`mktemp -d -t x.

T1564
Hide Artifacts
MalwareTarrask

Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value.

T1564
Hide Artifacts
MalwareOSX/Shlayer

OSX/Shlayer has used the mktemp utility to make random and unique filenames for payloads, such as export tmpDir="$(mktemp -d /tmp/XXXXXXXXXXXX)" or mktemp -t Installer.

T1564
Hide Artifacts
MalwareWarzoneRAT

WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`.

T1564
Hide Artifacts
ToolRemcos

Remcos can modify file attributes to hide the file.

T1564.001
Hidden Files and Directories
MalwareCOATHANGER

COATHANGER creates and installs itself to a hidden installation directory.

T1564.001
Hidden Files and Directories
MalwareNETWIRE

NETWIRE can copy itself to and launch itself from hidden folders.

T1564.001
Hidden Files and Directories
MalwareiKitten

iKitten saves itself with a leading "." so that it's hidden from users by default.

T1564.001
Hidden Files and Directories
MalwareEnvyScout

EnvyScout can use hidden directories and files to hide malicious executables.

T1564.001
Hidden Files and Directories
MalwareMachete

Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive.

T1564.001
Hidden Files and Directories
MalwareDacls

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

T1564.001
Hidden Files and Directories
MalwareCuckoo Stealer

Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory.

T1564.001
Hidden Files and Directories
MalwareWastedLocker

WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.

T1564.001
Hidden Files and Directories
MalwareInvisiMole

InvisiMole can create hidden system directories.

T1564.001
Hidden Files and Directories
MalwareCLAIMLOADER

CLAIMLOADER has modified file attributes to remain hidden to a standard user.

T1564.001
Hidden Files and Directories
MalwareFruitFly

FruitFly saves itself with a leading "." to make it a hidden file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.