Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1497 Virtualization/Sandbox Evasion |
MalwareCozyCar | Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit. |
| T1497 Virtualization/Sandbox Evasion |
MalwareKevin | Kevin can sleep for a time interval between C2 communication attempts. |
| T1497 Virtualization/Sandbox Evasion |
MalwareAgent Tesla | Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareHancitor | Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads. |
| T1497 Virtualization/Sandbox Evasion |
MalwareGelsemium | Gelsemium can use junk code to generate random activity to obscure malware behavior. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target. |
| T1497.001 System Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services. |
| T1497.001 System Checks |
CampaignFrankenstein | During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution. |
| T1497.001 System Checks |
GroupKimsuky | Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`. |
| T1497.001 System Checks |
GroupVolt Typhoon | Volt Typhoon has run system checks to determine if they were operating in a virtualized environment. |
| T1497.001 System Checks |
GroupEvilnum | Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments. |
| T1497.001 System Checks |
GroupGamaredon Group | Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document. |
| T1497.001 System Checks |
GroupOilRig | OilRig has used macros to verify if a mouse is connected to a compromised machine. |
| T1497.001 System Checks |
GroupDarkhotel | Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with |
| T1497.001 System Checks |
GroupWIRTE | WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments. |
| T1497.001 System Checks |
MalwarePikabot | Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB). |
| T1497.001 System Checks |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1497.001 System Checks |
MalwareBumblebee | Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products. |
| T1497.001 System Checks |
Malwareyty | yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware. |
| T1497.001 System Checks |
MalwareSmoke Loader | Smoke Loader scans processes to perform anti-VM checks. |
| T1497.001 System Checks |
MalwareHeartCrypt | HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing. |
| T1497.001 System Checks |
MalwareGravityRAT | GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment. |
| T1497.001 System Checks |
MalwaremacOS.OSAMiner | macOS.OSAMiner can parse the output of the native `system_profiler` tool to determine if the machine is running with 4 cores. |
| T1497.001 System Checks |
MalwareDUSTTRAP | DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value. |
| T1497.001 System Checks |
MalwareSnip3 | Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string. |
| T1497.001 System Checks |
MalwareGuLoader | GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call |
| T1497.001 System Checks |
MalwareWastedLocker | WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique. |
| T1497.001 System Checks |
MalwareInvisiMole | InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected. |
| T1497.001 System Checks |
MalwareWhisperGate | WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools. |
| T1497.001 System Checks |
MalwareOkrum | Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total. |
| T1497.001 System Checks |
MalwareRaspberry Robin | Raspberry Robin performs a variety of system environment checks to determine if it is running in a virtualized or sandboxed environment, such as querying CPU temperature information and network card MAC address information. |
| T1497.001 System Checks |
MalwareMispadu | Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.” |
| T1497.001 System Checks |
MalwareUBoatRAT | UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine. |
| T1497.001 System Checks |
MalwareNightdoor | Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments. |
| T1497.001 System Checks |
MalwareLucifer | Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected. |
| T1497.001 System Checks |
MalwareObliqueRAT | ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools. |
| T1497.001 System Checks |
MalwareGoldMax | GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to |
| T1497.001 System Checks |
MalwareDarkTortilla | DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie. |
| T1497.001 System Checks |
MalwareROKRAT | ROKRAT can check for VMware-related files and DLLs related to sandboxes. |
| T1497.001 System Checks |
MalwareExbyte | Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis. |
| T1497.001 System Checks |
MalwareDyre | Dyre can detect sandbox analysis environments by inspecting the process list and Registry. |
| T1497.001 System Checks |
MalwarePlugX | PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd". |
| T1497.001 System Checks |
MalwareLumma Stealer | Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection. |
| T1497.001 System Checks |
MalwareDarkGate | DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment. |
| T1497.001 System Checks |
MalwareSVCReady | SVCReady has the ability to determine if its runtime environment is virtualized. |
| T1497.001 System Checks |
MalwareFerocious | Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1497.001 System Checks |
MalwareSaint Bot | Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers. |
| T1497.001 System Checks |
MalwareP8RAT | P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments. |
| T1497.001 System Checks |
MalwareTrojan.Karagany | Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.