ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1497
Virtualization/Sandbox Evasion
MalwareCozyCar

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

T1497
Virtualization/Sandbox Evasion
MalwareKevin

Kevin can sleep for a time interval between C2 communication attempts.

T1497
Virtualization/Sandbox Evasion
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareHancitor

Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads.

T1497
Virtualization/Sandbox Evasion
MalwareGelsemium

Gelsemium can use junk code to generate random activity to obscure malware behavior.

T1497
Virtualization/Sandbox Evasion
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target.

T1497.001
System Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services.

T1497.001
System Checks
CampaignFrankenstein

During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution.

T1497.001
System Checks
GroupKimsuky

Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`.

T1497.001
System Checks
GroupVolt Typhoon

Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.

T1497.001
System Checks
GroupEvilnum

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

T1497.001
System Checks
GroupGamaredon Group

Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document.

T1497.001
System Checks
GroupOilRig

OilRig has used macros to verify if a mouse is connected to a compromised machine.

T1497.001
System Checks
GroupDarkhotel

Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with .Md5.exe, and if the program is executed from the root of the C:\ drive, as well as checks for sandbox-related libraries.

T1497.001
System Checks
GroupWIRTE

WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments.

T1497.001
System Checks
MalwarePikabot

Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB).

T1497.001
System Checks
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1497.001
System Checks
MalwareBumblebee

Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products.

T1497.001
System Checks
Malwareyty

yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware.

T1497.001
System Checks
MalwareSmoke Loader

Smoke Loader scans processes to perform anti-VM checks.

T1497.001
System Checks
MalwareHeartCrypt

HeartCrypt will attempt to load non-existent DLLs in attempt to detect sandbox creation of a dummy DLL to prevent the program from crashing.

T1497.001
System Checks
MalwareGravityRAT

GravityRAT uses WMI to check the BIOS and manufacturer information for strings like "VMWare", "Virtual", and "XEN" and another WMI request to get the current temperature of the hardware to determine if it's a virtual machine environment.

T1497.001
System Checks
MalwaremacOS.OSAMiner

macOS.OSAMiner can parse the output of the native `system_profiler` tool to determine if the machine is running with 4 cores.

T1497.001
System Checks
MalwareDUSTTRAP

DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value.

T1497.001
System Checks
MalwareSnip3

Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string.

T1497.001
System Checks
MalwareGuLoader

GuLoader has the ability to perform anti-VM and anti-sandbox checks using string hashing, the API call EnumWindows, and checking for Qemu guest agent.

T1497.001
System Checks
MalwareWastedLocker

WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.

T1497.001
System Checks
MalwareInvisiMole

InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected.

T1497.001
System Checks
MalwareWhisperGate

WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools.

T1497.001
System Checks
MalwareOkrum

Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total.

T1497.001
System Checks
MalwareRaspberry Robin

Raspberry Robin performs a variety of system environment checks to determine if it is running in a virtualized or sandboxed environment, such as querying CPU temperature information and network card MAC address information.

T1497.001
System Checks
MalwareMispadu

Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.”

T1497.001
System Checks
MalwareUBoatRAT

UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine.

T1497.001
System Checks
MalwareNightdoor

Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments.

T1497.001
System Checks
MalwareLucifer

Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected.

T1497.001
System Checks
MalwareObliqueRAT

ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools.

T1497.001
System Checks
MalwareGoldMax

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

T1497.001
System Checks
MalwareDarkTortilla

DarkTortilla can search a compromised system's running processes and services to detect Hyper-V, QEMU, Virtual PC, Virtual Box, and VMware, as well as Sandboxie.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1497.001
System Checks
MalwareExbyte

Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis.

T1497.001
System Checks
MalwareDyre

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1497.001
System Checks
MalwarePlugX

PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd".

T1497.001
System Checks
MalwareLumma Stealer

Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection.

T1497.001
System Checks
MalwareDarkGate

DarkGate queries system resources on an infected machine to identify if it is executing in a sandbox or virtualized environment.

T1497.001
System Checks
MalwareSVCReady

SVCReady has the ability to determine if its runtime environment is virtualized.

T1497.001
System Checks
MalwareFerocious

Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function GET.WORKSPACE to determine the OS version, if there is a mouse present, and if the host is capable of playing sounds.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1497.001
System Checks
MalwareSaint Bot

Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers.

T1497.001
System Checks
MalwareP8RAT

P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments.

T1497.001
System Checks
MalwareTrojan.Karagany

Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.