ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1564.006
Run Virtual Instance
MalwareLoudMiner

LoudMiner has used QEMU and VirtualBox to run a Tiny Core Linux virtual machine, which runs XMRig and makes connections to the C2 server for updates.

T1564.008
Email Hiding Rules
MalwareKali365

Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them.

T1564.009
Resource Forking
MalwareKeydnap

Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system.

T1564.009
Resource Forking
MalwareOSX/Shlayer

OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners.

T1564.010
Process Argument Spoofing
MalwareSombRAT

SombRAT has the ability to modify its process memory to hide process command-line arguments.

T1564.010
Process Argument Spoofing
MalwareCobalt Strike

Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands.

T1564.011
Ignore Process Interrupts
MalwareBOLDMOVE

BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic.

T1564.011
Ignore Process Interrupts
MalwareGoldMax

The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated.

T1564.011
Ignore Process Interrupts
MalwareBPFDoor

BPFDoor sets its process to ignore the following signals; `SIGHUP`, `SIGINT`, `SIGQUIT`, `SIGPIPE`, `SIGCHLD`, `SIGTTIN`, and `SIGTTOU`.

T1564.011
Ignore Process Interrupts
MalwareShai-Hulud

Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`.

T1564.011
Ignore Process Interrupts
MalwareOSX/Shlayer

OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals.

T1564.011
Ignore Process Interrupts
MalwareMini Shai-Hulud

Mini Shai-Hulud has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values.

T1565
Data Manipulation
MalwarePHASEJAM

PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version.

T1565.001
Stored Data Manipulation
MalwareMultiLayer Wiper

MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.

T1565.001
Stored Data Manipulation
MalwareSUNSPOT

SUNSPOT created a copy of the SolarWinds Orion software source file with a .bk extension to backup the original content, wrote SUNBURST using the same filename but with a .tmp extension, and then moved SUNBURST using MoveFileEx to the original filename with a .cs extension so it could be compiled within Orion software.

T1565.002
Transmitted Data Manipulation
MalwareLightNeuron

LightNeuron is capable of modifying email content, headers, and attachments during transit.

T1565.002
Transmitted Data Manipulation
MalwareGlassWorm

GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing.

T1565.002
Transmitted Data Manipulation
MalwareMetamorfo

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.

T1565.002
Transmitted Data Manipulation
MalwareMelcoz

Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary.

T1566
Phishing
MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

T1566
Phishing
MalwareHikit

Hikit has been spread through spear phishing.

T1566
Phishing
MalwareINC Ransomware

INC Ransomware campaigns have used spearphishing emails for initial access.

T1566.001
Spearphishing Attachment
MalwareTrickBot

TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware

T1566.001
Spearphishing Attachment
MalwareBLINDINGCAN

BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1566.001
Spearphishing Attachment
MalwareKOPILUWAK

KOPILUWAK has been delivered to victims as a malicious email attachment.

T1566.001
Spearphishing Attachment
MalwareThreatNeedle

ThreatNeedle has been distributed via a malicious Word document within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwarePony

Pony has been delivered via spearphishing attachments.

T1566.001
Spearphishing Attachment
MalwareOceanSalt

OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments.

T1566.001
Spearphishing Attachment
MalwareAppleSeed

AppleSeed has been distributed to victims through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.

T1566.001
Spearphishing Attachment
MalwareEnvyScout

EnvyScout has been distributed via spearphishing as an email attachment.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1566.001
Spearphishing Attachment
MalwareWoody RAT

Woody RAT has been delivered via malicious Word documents and archive files.

T1566.001
Spearphishing Attachment
MalwareSquirrelwaffle

Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails.

T1566.001
Spearphishing Attachment
MalwareSnip3

Snip3 has been delivered to victims through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareRifdoor

Rifdoor has been distributed in e-mails with malicious Excel or Word documents.

T1566.001
Spearphishing Attachment
MalwareRustyWater

RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage.

T1566.001
Spearphishing Attachment
MalwareIcedID

IcedID has been delivered via phishing e-mails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareFlagpro

Flagpro has been distributed via spearphishing as an email attachment.

T1566.001
Spearphishing Attachment
MalwareDarkTortilla

DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents.

T1566.001
Spearphishing Attachment
MalwareROKRAT

ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document.

T1566.001
Spearphishing Attachment
MalwareDarkWatchman

DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file.

T1566.001
Spearphishing Attachment
MalwareJavali

Javali has been delivered as malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareBisonal

Bisonal has been delivered as malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareClambling

Clambling has been delivered to victim's machines through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareDarkGate

DarkGate can be distributed through emails with malicious attachments from a spoofed email address.

T1566.001
Spearphishing Attachment
MalwareSVCReady

SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents.

T1566.001
Spearphishing Attachment
MalwareLatrodectus

Latrodectus has been distributed through reply-chain phishing emails with malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.