ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1589.002
Email Addresses
ToolAADInternals

AADInternals can check for the existence of user email addresses using public Microsoft APIs.

T1590.001
Domain Properties
ToolAADInternals

AADInternals can gather information about a tenant’s domains using public Microsoft APIs.

T1593.003
Code Repositories
MalwareShai-Hulud

Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string.

T1598.003
Spearphishing Link
MalwareSMOKEDHAM

SMOKEDHAM has been delivered via malicious links in phishing emails.

T1598.003
Spearphishing Link
Toolevilginx2

evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing.

T1598.003
Spearphishing Link
ToolAADInternals

AADInternals can send phishing emails containing malicious links designed to collect users’ credentials.

T1601
Modify System Image
MalwareDRYHOOK

DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code.

T1601.001
Patch System Image
MalwareSYNful Knock

SYNful Knock is malware that is inserted into a network device by patching the operating system image.

T1602.002
Network Device Configuration Dump
MalwareGlassWorm

GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`.

T1606.002
SAML Tokens
ToolAADInternals

AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate.

T1608.001
Upload Malware
MalwareShai-Hulud

Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts.

T1609
Container Administration Command
MalwareHildegard

Hildegard was executed through the kubelet API run command and by executing commands on running containers.

T1609
Container Administration Command
MalwareSiloscape

Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster.

T1609
Container Administration Command
MalwareKinsing

Kinsing was executed with an Ubuntu container entry point that runs shell scripts.

T1609
Container Administration Command
ToolPeirates

Peirates can use `kubectl` or the Kubernetes API to run commands.

T1609
Container Administration Command
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes.

T1609
Container Administration Command
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.

T1609
Container Administration Command
MalwareCanisterWorm

CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.

T1610
Deploy Container
MalwareKinsing

Kinsing was run through a deployed Ubuntu container.

T1610
Deploy Container
ToolPeirates

Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node.

T1610
Deploy Container
MalwareDoki

Doki was run through a deployed container.

T1611
Escape to Host
MalwareHildegard

Hildegard has used the BOtB tool that can break out of containers.

T1611
Escape to Host
MalwareDoki

Doki’s container was configured to bind the host root directory.

T1611
Escape to Host
MalwareSiloscape

Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of NtSetInformationSymbolicLink.

T1611
Escape to Host
ToolPeirates

Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath.

T1613
Container and Resource Discovery
MalwareHildegard

Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers.

T1613
Container and Resource Discovery
ToolPeirates

Peirates can enumerate Kubernetes pods in a given namespace.

T1613
Container and Resource Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials.

T1613
Container and Resource Discovery
MalwareCanisterWorm

CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `.

T1614
System Location Discovery
MalwareAmadey

Amadey does not run any tasks or install additional malware if the victim machine is based in Russia.

T1614
System Location Discovery
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine.

T1614
System Location Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”.

T1614
System Location Discovery
MalwareCrimson

Crimson can identify the geographical location of a victim host.

T1614
System Location Discovery
MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

T1614
System Location Discovery
MalwareHexEval Loader

HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions.

T1614
System Location Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can determine the geographical location of a victim host by checking the language.

T1614
System Location Discovery
MalwareSameCoin

SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location.

T1614
System Location Discovery
MalwareRagnar Locker

Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.

T1614
System Location Discovery
MalwareSocGholish

SocGholish can use IP-based geolocation to limit infections to victims in North America, Europe, and a small number of Asian-Pacific nations.

T1614
System Location Discovery
MalwareDarkWatchman

DarkWatchman can identity the OS locale of a compromised host.

T1614
System Location Discovery
MalwarePlugX

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.

T1614
System Location Discovery
MalwarePureCrypter

PureCrypter can use `kernel32!GetGeoInfo` to determine system location.

T1614
System Location Discovery
MalwareDarkGate

DarkGate queries system locale information during execution. Later versions of DarkGate query GetSystemDefaultLCID for locale information to determine if the malware is executing in Russian-speaking countries.

T1614
System Location Discovery
MalwareSaint Bot

Saint Bot has conducted system locale checks to see if the compromised host is in Russia, Ukraine, Belarus, Armenia, Kazakhstan, or Moldova.

T1614
System Location Discovery
MalwareGlassWorm

GlassWorm has leveraged geofencing logic to detect whether it is operating in a Russian associated time zone to determine whether it continues to execute.

T1614
System Location Discovery
MalwareRedLine Stealer

RedLine Stealer has gathered detailed information about victims’ systems, such as IP addresses, and geolocation. RedLine Stealer has also checked the IP from where it was being executed and leveraged an opensource geolocation IP-lookup service.

T1614
System Location Discovery
MalwareSDBbot

SDBbot can collected the country code of a compromised machine.

T1614
System Location Discovery
MalwareRaccoon Stealer

Raccoon Stealer collects the `Locale Name` of the infected device via `GetUserDefaultLocaleName` to determine whether the string `ru` is included, but in analyzed samples no action is taken if present.

T1614
System Location Discovery
MalwareAshTag

AshTag can check geolocation on targeted systems.

T1614
System Location Discovery
MalwareGrimAgent

GrimAgent can identify the country code on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.