ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1491.001
Internal Defacement
MalwareSameCoin

SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing.

T1491.001
Internal Defacement
MalwareDiavol

After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt".

T1491.001
Internal Defacement
MalwareBlackCat

BlackCat can change the desktop wallpaper on compromised hosts.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1491.001
Internal Defacement
MalwareROADSWEEP

ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files.

T1491.001
Internal Defacement
MalwareMeteor

Meteor can change both the desktop wallpaper and the lock screen image to a custom image.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1491.001
Internal Defacement
MalwareINC Ransomware

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

T1491.001
Internal Defacement
ToolRemcos

Remcos has the ability to modify the desktop wallpaper.

T1491.001
Internal Defacement
GroupShinyHunters

ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

T1491.002
External Defacement
GroupSandworm Team

Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019.

T1491.002
External Defacement
GroupEmber Bear

Ember Bear is linked to the defacement of several Ukrainian organization websites.

T1495
Firmware Corruption
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations.

T1495
Firmware Corruption
MalwareTrickBot

TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device.

T1495
Firmware Corruption
MalwareBad Rabbit

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.

T1496.001
Compute Hijacking
CampaignShadowRay

During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining.

T1496.001
Compute Hijacking
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

T1496.001
Compute Hijacking
GroupTeamTNT

TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency.

T1496.001
Compute Hijacking
GroupRocke

Rocke has distributed cryptomining malware.

T1496.001
Compute Hijacking
GroupBlue Mockingbird

Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.

T1496.001
Compute Hijacking
MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

T1496.001
Compute Hijacking
MalwareSkidmap

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

T1496.001
Compute Hijacking
MalwareBonadan

Bonadan can download an additional module which has a cryptocurrency mining extension.

T1496.001
Compute Hijacking
MalwareLucifer

Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.

T1496.001
Compute Hijacking
MalwareDarkGate

DarkGate can deploy follow-on cryptocurrency mining payloads.

T1496.001
Compute Hijacking
MalwareKinsing

Kinsing has created and run a Bitcoin cryptocurrency miner.

T1496.001
Compute Hijacking
MalwareCookieMiner

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

T1496.001
Compute Hijacking
MalwareLoudMiner

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

T1496.001
Compute Hijacking
ToolImminent Monitor

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

T1497
Virtualization/Sandbox Evasion
CampaignOperation Spalax

During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host.

T1497
Virtualization/Sandbox Evasion
GroupContagious Interview

Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection.

T1497
Virtualization/Sandbox Evasion
GroupSaint Bear

Saint Bear contains several anti-analysis and anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
GroupDarkhotel

Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection.

T1497
Virtualization/Sandbox Evasion
MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareSquirrelwaffle

Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.

T1497
Virtualization/Sandbox Evasion
MalwareRaspberry Robin

Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment.

T1497
Virtualization/Sandbox Evasion
MalwareIcedID

IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic.

T1497
Virtualization/Sandbox Evasion
MalwarePteranodon

Pteranodon has the ability to use anti-detection functions to identify sandbox environments.

T1497
Virtualization/Sandbox Evasion
MalwareBisonal

Bisonal can check to determine if the compromised system is running on VMware.

T1497
Virtualization/Sandbox Evasion
MalwareMetamorfo

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.

T1497
Virtualization/Sandbox Evasion
MalwareRedLine Stealer

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1497
Virtualization/Sandbox Evasion
MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

T1497
Virtualization/Sandbox Evasion
MalwareStoneDrill

StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareRTM

RTM can detect if it is running within a sandbox or other virtualized analysis environment.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

T1497
Virtualization/Sandbox Evasion
MalwareBazar

Bazar can attempt to overload sandbox analysis by sending 1550 calls to printf.

T1497
Virtualization/Sandbox Evasion
MalwareXLoader

XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis.

T1497
Virtualization/Sandbox Evasion
MalwareCarberp

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareCHOPSTICK

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.