ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1480
Execution Guardrails
MalwareDarkGate

DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them.

T1480
Execution Guardrails
MalwareLockBit 3.0

LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list.

T1480
Execution Guardrails
MalwareLODEINFO

LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine.

T1480
Execution Guardrails
MalwareSagerunex

Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory.

T1480
Execution Guardrails
MalwareGlassWorm

GlassWorm has utilized logic to avoid executing on Russian based devices.

T1480
Execution Guardrails
MalwareRedLine Stealer

RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host.

T1480
Execution Guardrails
MalwareBPFDoor

BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time.

T1480
Execution Guardrails
MalwareAkira _v2

Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.

T1480
Execution Guardrails
MalwareBlackByte Ransomware

BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate.

T1480
Execution Guardrails
MalwareStrelaStealer

StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables.

T1480
Execution Guardrails
MalwareVaporRage

VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.

T1480
Execution Guardrails
MalwareHiddenFace

HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found.

T1480
Execution Guardrails
MalwareLockBit 2.0

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

T1480
Execution Guardrails
MalwareNativeZone

NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components.

T1480
Execution Guardrails
MalwareROADSWEEP

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1480
Execution Guardrails
MalwareSUNSPOT

SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values.

T1480
Execution Guardrails
MalwareBoomBox

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

T1480
Execution Guardrails
MalwareDEADEYE

DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain.

T1480
Execution Guardrails
MalwareStealBit

StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger.

T1480
Execution Guardrails
MalwareQilin

Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.

T1480
Execution Guardrails
MalwareLazyWiper

LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`.

T1480
Execution Guardrails
MalwareBitPaymer

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

T1480
Execution Guardrails
MalwareSmall Sieve

Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line.

T1480
Execution Guardrails
Toolevilginx2

evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure.

T1480
Execution Guardrails
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube.

T1480
Execution Guardrails
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel.

T1480
Execution Guardrails
MalwareCanisterWorm

CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran.

T1480.001
Environmental Keying
GroupAPT41

APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number.

T1480.001
Environmental Keying
GroupEquation

Equation has been observed utilizing environmental keying in payload delivery.

T1480.001
Environmental Keying
MalwareNinja

Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number.

T1480.001
Environmental Keying
MalwarePikabot

Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1480.001
Environmental Keying
MalwarePUBLOAD

PUBLOAD has utilized environmental keying in the payload to include the victim volume serial number, computer name, username, and machine’s tick count.

T1480.001
Environmental Keying
MalwareInvisiMole

InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer.

T1480.001
Environmental Keying
MalwareROKRAT

ROKRAT relies on a specific victim hostname to execute and decrypt important strings.

T1480.001
Environmental Keying
MalwareWinnti for Windows

The Winnti for Windows dropper component can verify the existence of a single command line parameter and either terminate if it is not found or later use it as a decryption key.

T1480.001
Environmental Keying
MalwarePowerPunch

PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload.

T1480.002
Mutual Exclusion
GroupAPT38

APT38 has created a mutex to avoid duplicate execution.

T1480.002
Mutual Exclusion
GroupKimsuky

Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication.

T1480.002
Mutual Exclusion
MalwareTONESHELL

TONESHELL has created a mutex to avoid duplicate execution.

T1480.002
Mutual Exclusion
MalwareCLAIMLOADER

CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running.

T1480.002
Mutual Exclusion
MalwarePlugX

PlugX has leveraged a mutex in its infection process.

T1480.002
Mutual Exclusion
MalwarePureCrypter

PureCrypter code contains a global mutex.

T1480.002
Mutual Exclusion
MalwareLockBit 3.0

LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance.

T1480.002
Mutual Exclusion
MalwareGazer

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareEmbargo

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1480.002
Mutual Exclusion
MalwareBPFDoor

When executed, BPFDoor attempts to create and lock a runtime file, `/var/run/initd.lock`, and exits if it fails using the specified file, resulting in a makeshift mutex.

T1480.002
Mutual Exclusion
MalwareBlack Basta

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

T1480.002
Mutual Exclusion
MalwareStrelaStealer

StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection.

T1480.002
Mutual Exclusion
MalwareHiddenFace

HiddenFace can create a mutex to ensure only one instance is running at a time.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.