Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1489 Service Stop |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services. |
| T1489 Service Stop |
MalwareOlympic Destroyer | Olympic Destroyer uses the API call |
| T1489 Service Stop |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can terminate running services. |
| T1489 Service Stop |
MalwareConti | Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of |
| T1489 Service Stop |
MalwareMegazord | Megazord has the ability to terminate a list of services and processes. |
| T1489 Service Stop |
MalwareDiavol | Diavol will terminate services using the Service Control Manager (SCM) API. |
| T1489 Service Stop |
MalwareBlackCat | BlackCat has the ability to stop VM services on compromised networks. |
| T1489 Service Stop |
MalwareRagnar Locker | Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted. |
| T1489 Service Stop |
MalwareAvaddon | Avaddon looks for and attempts to stop database processes. |
| T1489 Service Stop |
MalwareCheerscrypt | Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`. |
| T1489 Service Stop |
MalwareBabuk | Babuk can stop specific services related to backups. |
| T1489 Service Stop |
MalwareCuba | Cuba has a hardcoded list of services and processes to terminate. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1489 Service Stop |
MalwareNetwalker | Netwalker can terminate system processes and services, some of which relate to backup software. |
| T1489 Service Stop |
MalwareWannaCry | WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores. |
| T1489 Service Stop |
MalwarePay2Key | Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service. |
| T1489 Service Stop |
MalwareRoyal | Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption. |
| T1489 Service Stop |
MalwareEmbargo | Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted. |
| T1489 Service Stop |
MalwareMegaCortex | MegaCortex can stop and disable services on the system. |
| T1489 Service Stop |
MalwareAkira _v2 | Akira _v2 can stop running virtual machines. |
| T1489 Service Stop |
MalwareRyuk | Ryuk has called |
| T1489 Service Stop |
MalwareHermeticWiper | HermeticWiper has the ability to stop the Volume Shadow Copy service. |
| T1489 Service Stop |
MalwarePysa | Pysa can stop services and processes. |
| T1489 Service Stop |
MalwareLockBit 2.0 | LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes. |
| T1489 Service Stop |
MalwareHotCroissant | HotCroissant has the ability to stop services on the infected host. |
| T1489 Service Stop |
MalwareREvil | REvil has the capability to stop services and kill processes. |
| T1489 Service Stop |
MalwareROADSWEEP | ROADSWEEP can disable critical services and processes. |
| T1489 Service Stop |
MalwareLookBack | LookBack can kill processes and delete services. |
| T1489 Service Stop |
MalwarePHASEJAM | PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances. |
| T1489 Service Stop |
MalwareClop | Clop can kill several processes and services related to backups and security solutions. |
| T1489 Service Stop |
MalwareMeteor | Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`. |
| T1489 Service Stop |
MalwareMaze | Maze has stopped SQL services to ensure it can encrypt any database. |
| T1489 Service Stop |
MalwareVIRTUALPITA | VIRTUALPITA can start and stop the `vmsyslogd` service. |
| T1489 Service Stop |
MalwareKillDisk | KillDisk terminates various processes to get the user to reboot the victim machine. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1489 Service Stop |
MalwareIndustroyer | Industroyer’s data wiper module writes zeros into the registry keys in |
| T1489 Service Stop |
MalwareDRYHOOK | DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file. |
| T1489 Service Stop |
MalwareINC Ransomware | INC Ransomware can issue a command to kill a process on compromised hosts. |
| T1489 Service Stop |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to stop processes and services. |
| T1490 Inhibit System Recovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`. |
| T1490 Inhibit System Recovery |
GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| T1490 Inhibit System Recovery |
GroupSandworm Team | Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| T1490 Inhibit System Recovery |
GroupScattered Spider | Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts. |
| T1490 Inhibit System Recovery |
GroupStorm-0501 | Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
GroupWizard Spider | Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin. |
| T1490 Inhibit System Recovery |
GroupVOID MANTICORE | VOID MANTICORE has deleted virtual machines directly from the virtualization platform. |
| T1490 Inhibit System Recovery |
MalwareEKANS | EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities. |
| T1490 Inhibit System Recovery |
MalwareRobbinHood | RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily. |
| T1490 Inhibit System Recovery |
MalwareRansomHub | RansomHub has used `vssadmin.exe` to delete volume shadow copies. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.