Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1491.001 Internal Defacement |
MalwareSameCoin | SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing. |
| T1491.001 Internal Defacement |
MalwareDiavol | After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt". |
| T1491.001 Internal Defacement |
MalwareBlackCat | BlackCat can change the desktop wallpaper on compromised hosts. |
| T1491.001 Internal Defacement |
MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| T1491.001 Internal Defacement |
MalwareROADSWEEP | ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files. |
| T1491.001 Internal Defacement |
MalwareMeteor | Meteor can change both the desktop wallpaper and the lock screen image to a custom image. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1491.001 Internal Defacement |
MalwareINC Ransomware | INC Ransomware has the ability to change the background wallpaper image to display the ransom note. |
| T1491.001 Internal Defacement |
ToolRemcos | Remcos has the ability to modify the desktop wallpaper. |
| T1491.001 Internal Defacement |
GroupShinyHunters | ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. |
| T1491.002 External Defacement |
GroupSandworm Team | Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019. |
| T1491.002 External Defacement |
GroupEmber Bear | Ember Bear is linked to the defacement of several Ukrainian organization websites. |
| T1495 Firmware Corruption |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations. |
| T1495 Firmware Corruption |
MalwareTrickBot | TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device. |
| T1495 Firmware Corruption |
MalwareBad Rabbit | Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up. |
| T1496.001 Compute Hijacking |
CampaignShadowRay | During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining. |
| T1496.001 Compute Hijacking |
GroupAPT41 | APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment. |
| T1496.001 Compute Hijacking |
GroupTeamTNT | TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency. |
| T1496.001 Compute Hijacking |
GroupRocke | Rocke has distributed cryptomining malware. |
| T1496.001 Compute Hijacking |
GroupBlue Mockingbird | Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems. |
| T1496.001 Compute Hijacking |
MalwareHildegard | Hildegard has used xmrig to mine cryptocurrency. |
| T1496.001 Compute Hijacking |
MalwareSkidmap | Skidmap is a kernel-mode rootkit used for cryptocurrency mining. |
| T1496.001 Compute Hijacking |
MalwareBonadan | Bonadan can download an additional module which has a cryptocurrency mining extension. |
| T1496.001 Compute Hijacking |
MalwareLucifer | Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero. |
| T1496.001 Compute Hijacking |
MalwareDarkGate | DarkGate can deploy follow-on cryptocurrency mining payloads. |
| T1496.001 Compute Hijacking |
MalwareKinsing | Kinsing has created and run a Bitcoin cryptocurrency miner. |
| T1496.001 Compute Hijacking |
MalwareCookieMiner | CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency. |
| T1496.001 Compute Hijacking |
MalwareLoudMiner | LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero. |
| T1496.001 Compute Hijacking |
ToolImminent Monitor | Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine. |
| T1497 Virtualization/Sandbox Evasion |
CampaignOperation Spalax | During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host. |
| T1497 Virtualization/Sandbox Evasion |
GroupContagious Interview | Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection. |
| T1497 Virtualization/Sandbox Evasion |
GroupSaint Bear | Saint Bear contains several anti-analysis and anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
GroupDarkhotel | Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBumblebee | Bumblebee has the ability to perform anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareSquirrelwaffle | Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRaspberry Robin | Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareIcedID | IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic. |
| T1497 Virtualization/Sandbox Evasion |
MalwarePteranodon | Pteranodon has the ability to use anti-detection functions to identify sandbox environments. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBisonal | Bisonal can check to determine if the compromised system is running on VMware. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMetamorfo | Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRedLine Stealer | RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBlack Basta | Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStoneDrill | StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRTM | RTM can detect if it is running within a sandbox or other virtualized analysis environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStrelaStealer | StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBazar | Bazar can attempt to overload sandbox analysis by sending 1550 calls to |
| T1497 Virtualization/Sandbox Evasion |
MalwareXLoader | XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCarberp | Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCHOPSTICK | CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.