ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1489
Service Stop
MalwareOlympic Destroyer

Olympic Destroyer uses the API call ChangeServiceConfigW to disable all services on the affected system.

T1489
Service Stop
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can terminate running services.

T1489
Service Stop
MalwareConti

Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of net stop.

T1489
Service Stop
MalwareMegazord

Megazord has the ability to terminate a list of services and processes.

T1489
Service Stop
MalwareDiavol

Diavol will terminate services using the Service Control Manager (SCM) API.

T1489
Service Stop
MalwareBlackCat

BlackCat has the ability to stop VM services on compromised networks.

T1489
Service Stop
MalwareRagnar Locker

Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted.

T1489
Service Stop
MalwareAvaddon

Avaddon looks for and attempts to stop database processes.

T1489
Service Stop
MalwareCheerscrypt

Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`.

T1489
Service Stop
MalwareBabuk

Babuk can stop specific services related to backups.

T1489
Service Stop
MalwareCuba

Cuba has a hardcoded list of services and processes to terminate.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1489
Service Stop
MalwareNetwalker

Netwalker can terminate system processes and services, some of which relate to backup software.

T1489
Service Stop
MalwareWannaCry

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1489
Service Stop
MalwarePay2Key

Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service.

T1489
Service Stop
MalwareRoyal

Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption.

T1489
Service Stop
MalwareEmbargo

Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted.

T1489
Service Stop
MalwareMegaCortex

MegaCortex can stop and disable services on the system.

T1489
Service Stop
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

T1489
Service Stop
MalwareRyuk

Ryuk has called kill.bat for stopping services, disabling services and killing processes.

T1489
Service Stop
MalwareHermeticWiper

HermeticWiper has the ability to stop the Volume Shadow Copy service.

T1489
Service Stop
MalwarePysa

Pysa can stop services and processes.

T1489
Service Stop
MalwareLockBit 2.0

LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes.

T1489
Service Stop
MalwareHotCroissant

HotCroissant has the ability to stop services on the infected host.

T1489
Service Stop
MalwareREvil

REvil has the capability to stop services and kill processes.

T1489
Service Stop
MalwareROADSWEEP

ROADSWEEP can disable critical services and processes.

T1489
Service Stop
MalwareLookBack

LookBack can kill processes and delete services.

T1489
Service Stop
MalwarePHASEJAM

PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances.

T1489
Service Stop
MalwareClop

Clop can kill several processes and services related to backups and security solutions.

T1489
Service Stop
MalwareMeteor

Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`.

T1489
Service Stop
MalwareMaze

Maze has stopped SQL services to ensure it can encrypt any database.

T1489
Service Stop
MalwareVIRTUALPITA

VIRTUALPITA can start and stop the `vmsyslogd` service.

T1489
Service Stop
MalwareKillDisk

KillDisk terminates various processes to get the user to reboot the victim machine.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1489
Service Stop
MalwareIndustroyer

Industroyer’s data wiper module writes zeros into the registry keys in SYSTEM\CurrentControlSet\Services to render a system inoperable.

T1489
Service Stop
MalwareDRYHOOK

DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file.

T1489
Service Stop
MalwareINC Ransomware

INC Ransomware can issue a command to kill a process on compromised hosts.

T1489
Service Stop
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to stop processes and services.

T1490
Inhibit System Recovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`.

T1490
Inhibit System Recovery
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

T1490
Inhibit System Recovery
GroupSandworm Team

Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

T1490
Inhibit System Recovery
GroupScattered Spider

Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.

T1490
Inhibit System Recovery
GroupStorm-0501

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`,
`Microsoft.Compute/restorePointCollections/delete`,
`Microsoft.Storage/storageAccounts/delete`, and
`Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
GroupWizard Spider

Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.

T1490
Inhibit System Recovery
GroupVOID MANTICORE

VOID MANTICORE has deleted virtual machines directly from the virtualization platform.

T1490
Inhibit System Recovery
MalwareEKANS

EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.

T1490
Inhibit System Recovery
MalwareRobbinHood

RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.

T1490
Inhibit System Recovery
MalwareRansomHub

RansomHub has used `vssadmin.exe` to delete volume shadow copies.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.