Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1480 Execution Guardrails |
MalwareDarkGate | DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1480 Execution Guardrails |
MalwareLODEINFO | LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine. |
| T1480 Execution Guardrails |
MalwareSagerunex | Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory. |
| T1480 Execution Guardrails |
MalwareGlassWorm | GlassWorm has utilized logic to avoid executing on Russian based devices. |
| T1480 Execution Guardrails |
MalwareRedLine Stealer | RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host. |
| T1480 Execution Guardrails |
MalwareBPFDoor | BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time. |
| T1480 Execution Guardrails |
MalwareAkira _v2 | Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined. |
| T1480 Execution Guardrails |
MalwareBlackByte Ransomware | BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1480 Execution Guardrails |
MalwareVaporRage | VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found. |
| T1480 Execution Guardrails |
MalwareHiddenFace | HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found. |
| T1480 Execution Guardrails |
MalwareLockBit 2.0 | LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
| T1480 Execution Guardrails |
MalwareNativeZone | NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1480 Execution Guardrails |
MalwareSUNSPOT | SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values. |
| T1480 Execution Guardrails |
MalwareBoomBox | BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found. |
| T1480 Execution Guardrails |
MalwareDEADEYE | DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain. |
| T1480 Execution Guardrails |
MalwareStealBit | StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger. |
| T1480 Execution Guardrails |
MalwareQilin | Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution. |
| T1480 Execution Guardrails |
MalwareLazyWiper | LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`. |
| T1480 Execution Guardrails |
MalwareBitPaymer | BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| T1480 Execution Guardrails |
MalwareSmall Sieve | Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line. |
| T1480 Execution Guardrails |
Toolevilginx2 | evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure. |
| T1480 Execution Guardrails |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube. |
| T1480 Execution Guardrails |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel. |
| T1480 Execution Guardrails |
MalwareCanisterWorm | CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran. |
| T1480.001 Environmental Keying |
GroupAPT41 | APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number. |
| T1480.001 Environmental Keying |
GroupEquation | Equation has been observed utilizing environmental keying in payload delivery. |
| T1480.001 Environmental Keying |
MalwareNinja | Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number. |
| T1480.001 Environmental Keying |
MalwarePikabot | Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian. |
| T1480.001 Environmental Keying |
MalwareTONESHELL | TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2. |
| T1480.001 Environmental Keying |
MalwarePUBLOAD | PUBLOAD has utilized environmental keying in the payload to include the victim volume serial number, computer name, username, and machine’s tick count. |
| T1480.001 Environmental Keying |
MalwareInvisiMole | InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer. |
| T1480.001 Environmental Keying |
MalwareROKRAT | ROKRAT relies on a specific victim hostname to execute and decrypt important strings. |
| T1480.001 Environmental Keying |
MalwareWinnti for Windows | The Winnti for Windows dropper component can verify the existence of a single command line parameter and either terminate if it is not found or later use it as a decryption key. |
| T1480.001 Environmental Keying |
MalwarePowerPunch | PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload. |
| T1480.002 Mutual Exclusion |
GroupAPT38 | APT38 has created a mutex to avoid duplicate execution. |
| T1480.002 Mutual Exclusion |
GroupKimsuky | Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication. |
| T1480.002 Mutual Exclusion |
MalwareTONESHELL | TONESHELL has created a mutex to avoid duplicate execution. |
| T1480.002 Mutual Exclusion |
MalwareCLAIMLOADER | CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running. |
| T1480.002 Mutual Exclusion |
MalwarePlugX | PlugX has leveraged a mutex in its infection process. |
| T1480.002 Mutual Exclusion |
MalwarePureCrypter | PureCrypter code contains a global mutex. |
| T1480.002 Mutual Exclusion |
MalwareLockBit 3.0 | LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance. |
| T1480.002 Mutual Exclusion |
MalwareGazer | Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running. |
| T1480.002 Mutual Exclusion |
MalwareEmbargo | Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip." |
| T1480.002 Mutual Exclusion |
MalwareBPFDoor | When executed, BPFDoor attempts to create and lock a runtime file, `/var/run/initd.lock`, and exits if it fails using the specified file, resulting in a makeshift mutex. |
| T1480.002 Mutual Exclusion |
MalwareBlack Basta | Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing. |
| T1480.002 Mutual Exclusion |
MalwareStrelaStealer | StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection. |
| T1480.002 Mutual Exclusion |
MalwareHiddenFace | HiddenFace can create a mutex to ensure only one instance is running at a time. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.