Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1222.001 Windows Permissions |
GroupStorm-1811 | Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments. |
| T1222.001 Windows Permissions |
GroupWizard Spider | Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders. |
| T1222.001 Windows Permissions |
MalwareWastedLocker | WastedLocker has a command to take ownership of a file and reset the ACL permissions using the |
| T1222.001 Windows Permissions |
MalwareBlackCat | BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks. |
| T1222.001 Windows Permissions |
MalwareWannaCry | WannaCry uses |
| T1222.001 Windows Permissions |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| T1222.001 Windows Permissions |
MalwareGrandoreiro | Grandoreiro can modify the binary ACL to prevent security tools from running. |
| T1222.001 Windows Permissions |
MalwareRyuk | Ryuk can launch |
| T1222.001 Windows Permissions |
MalwareCaddyWiper | CaddyWiper can modify ACL entries to take ownership of files. |
| T1222.001 Windows Permissions |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1222.001 Windows Permissions |
MalwareBitPaymer | BitPaymer can use |
| T1222.001 Windows Permissions |
ToolDiskpart | Diskpart can be used to display, set, or clear attributes of a disk or volume. |
| T1222.002 Linux and Mac Permissions |
CampaignKV Botnet Activity | KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines. |
| T1222.002 Linux and Mac Permissions |
GroupAPT32 | APT32's macOS backdoor changes the permission of the file it wants to execute to 755. |
| T1222.002 Linux and Mac Permissions |
GroupTeamTNT | TeamTNT has modified the permissions on binaries with |
| T1222.002 Linux and Mac Permissions |
GroupRocke | Rocke has changed file permissions of files so they could not be modified. |
| T1222.002 Linux and Mac Permissions |
MalwareCOATHANGER | COATHANGER will set the GID of `httpsd` to 90 when infected. |
| T1222.002 Linux and Mac Permissions |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to modify file permissions. |
| T1222.002 Linux and Mac Permissions |
MalwareBundlore | Bundlore changes the permissions of a payload using the command |
| T1222.002 Linux and Mac Permissions |
MalwareBlack Basta | The Black Basta binary can use `chmod` to gain full permissions to targeted files. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via |
| T1222.002 Linux and Mac Permissions |
MalwarePenquin | Penquin can add the executable flag to a downloaded file. |
| T1222.002 Linux and Mac Permissions |
MalwareKinsing | Kinsing has used chmod to modify permissions on key files for use. |
| T1222.002 Linux and Mac Permissions |
MalwareXCSSET | XCSSET uses the |
| T1222.002 Linux and Mac Permissions |
MalwareDRYHOOK | DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1222.002 Linux and Mac Permissions |
MalwareDok | Dok gives all users execute permissions for the application using the command |
| T1480 Execution Guardrails |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations. |
| T1480 Execution Guardrails |
GroupBlackByte | BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute. |
| T1480 Execution Guardrails |
GroupGamaredon Group | Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations. |
| T1480 Execution Guardrails |
GroupContagious Interview | Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads. |
| T1480 Execution Guardrails |
GroupAPT-C-36 | APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites. |
| T1480 Execution Guardrails |
MalwareTorisma | Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list. |
| T1480 Execution Guardrails |
MalwareStuxnet | Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met. |
| T1480 Execution Guardrails |
MalwareRansomHub | RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration. |
| T1480 Execution Guardrails |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region. |
| T1480 Execution Guardrails |
MalwareROAMINGHOUSE | ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected. |
| T1480 Execution Guardrails |
MalwareTONESHELL | TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`. |
| T1480 Execution Guardrails |
MalwareEnvyScout | EnvyScout can call |
| T1480 Execution Guardrails |
MalwareBOLDMOVE | BOLDMOVE verifies it is executing from a specific path during execution. |
| T1480 Execution Guardrails |
MalwareSystemBC | SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not. |
| T1480 Execution Guardrails |
MalwareShrinkLocker | ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1480 Execution Guardrails |
MalwareApostle | Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| T1480 Execution Guardrails |
MalwareRaspberry Robin | Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script. |
| T1480 Execution Guardrails |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.” |
| T1480 Execution Guardrails |
MalwareLightSpy | On macOS, LightSpy checks the existence of a process identification number (PID) file, `/Users/Shared/irc.pid`, to verify if LightSpy is currently running. |
| T1480 Execution Guardrails |
MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| T1480 Execution Guardrails |
MalwareExbyte | Exbyte checks for the presence of a configuration file before completing execution. |
| T1480 Execution Guardrails |
MalwareLunarLoader | LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets. |
| T1480 Execution Guardrails |
MalwarePureCrypter | PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.