ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1573.002
Asymmetric Cryptography
MalwareHiddenFace

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCobalt Strike

Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.

T1573.002
Asymmetric Cryptography
MalwareServHelper

ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP.

T1573.002
Asymmetric Cryptography
MalwareREvil

REvil has encrypted C2 communications with the ECIES algorithm.

T1573.002
Asymmetric Cryptography
MalwareOilBooster

OilBooster can use the OpenSSL library to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCyclops Blink

Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.

T1573.002
Asymmetric Cryptography
MalwareCarbon

Carbon has used RSA encryption for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareBISCUIT

BISCUIT uses SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareLAMEHUG

LAMEHUG can use SSH to transfer information to C2.

T1573.002
Asymmetric Cryptography
MalwareMango

Mango can use TLS to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareGrimAgent

GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2.

T1573.002
Asymmetric Cryptography
MalwarePoetRAT

PoetRAT used TLS to encrypt command and control (C2) communications.

T1573.002
Asymmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with TLS.

T1573.002
Asymmetric Cryptography
MalwarePenquin

Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman.

T1573.002
Asymmetric Cryptography
MalwarePITSTOP

PITSTOP has the ability to communicate over TLS.

T1573.002
Asymmetric Cryptography
MalwareComRAT

ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.

T1573.002
Asymmetric Cryptography
MalwareLunarWeb

LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096.

T1573.002
Asymmetric Cryptography
MalwarePOWERSTATS

POWERSTATS has encrypted C2 traffic with RSA.

T1573.002
Asymmetric Cryptography
MalwareDridex

Dridex has encrypted traffic with RSA.

T1573.002
Asymmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with RSA.

T1573.002
Asymmetric Cryptography
MalwareSmall Sieve

Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.

T1573.002
Asymmetric Cryptography
ToolCovenant

Covenant can utilize SSL to encrypt command and control traffic.

T1573.002
Asymmetric Cryptography
ToolSliver

Sliver can use mutual TLS and RSA cryptography to exchange a session key.

T1573.002
Asymmetric Cryptography
ToolDCRAT

DCRAT can use certificate-based authentication for C2 servers.

T1573.002
Asymmetric Cryptography
ToolEmpire

Empire can use TLS to encrypt its C2 channel.

T1573.002
Asymmetric Cryptography
ToolFRP

FRP can be configured to only accept TLS connections.

T1573.002
Asymmetric Cryptography
ToolRemcos

Remcos can use TLS to encrypt C2 communication.

T1573.002
Asymmetric Cryptography
ToolKoadic

Koadic can use SSL and TLS for communications.

T1573.002
Asymmetric Cryptography
ToolPupy

Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES.

T1573.002
Asymmetric Cryptography
ToolMythic

Mythic supports SSL encrypted C2.

T1573.002
Asymmetric Cryptography
ToolTor

Tor encapsulates traffic in multiple layers of encryption, using TLS by default.

T1573.002
Asymmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`.

T1574
Hijack Execution Flow
MalwareCOATHANGER

COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`.

T1574
Hijack Execution Flow
MalwareRaspberry Robin

Raspberry Robin will drop a copy of itself to a subfolder in %Program Data% or %Program Data%\\Microsoft\\ to attempt privilege elevation and defense evasion if not running in Session 0.

T1574
Hijack Execution Flow
MalwareNightdoor

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

T1574
Hijack Execution Flow
MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

T1574
Hijack Execution Flow
MalwareDarkGate

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script. When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

T1574
Hijack Execution Flow
MalwareSaint Bot

Saint Bot will use the malicious file slideshow.mp4 if present to load the core API provided by ntdll.dll to avoid any hooks placed on calls to the original ntdll.dll file by endpoint detection and response or antimalware software.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1574
Hijack Execution Flow
MalwareDenis

Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe.

T1574
Hijack Execution Flow
MalwareDtrack

One of Dtrack can replace the normal flow of a program execution with malicious code.

T1574.001
DLL
MalwareNinja

Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player.

T1574.001
DLL
MalwareRCSession

RCSession can be installed via DLL side-loading.

T1574.001
DLL
MalwareIronWind

IronWind has used DLL sideloading for execution.

T1574.001
DLL
MalwareDowndelph

Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges.

T1574.001
DLL
MalwareChinoxy

Chinoxy can use a digitally signed binary ("Logitech Bluetooth Wizard Host Process") to load its dll into memory.

T1574.001
DLL
MalwarePAKLOG

PAKLOG has leveraged legitimate binaries to conduct DLL side-loading.

T1574.001
DLL
MalwareRedLeaves

RedLeaves is launched through use of DLL search order hijacking to load a malicious dll.

T1574.001
DLL
MalwareHavoc

Havoc has leveraged legitimate executables to side-load malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.