ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1539
Steal Web Session Cookie
MalwareDarkGate

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.

T1539
Steal Web Session Cookie
MalwareChaes

Chaes has used a script that extracts the web session cookie and sends it to the C2 server.

T1539
Steal Web Session Cookie
MalwareLODEINFO

LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies.

T1539
Steal Web Session Cookie
MalwareEVILNUM

EVILNUM can harvest cookies and upload them to the C2 server.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1539
Steal Web Session Cookie
MalwareSpica

Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers.

T1539
Steal Web Session Cookie
MalwareBLUELIGHT

BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1539
Steal Web Session Cookie
MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

T1539
Steal Web Session Cookie
MalwareXLoader

XLoader can capture web session cookies and session information from victim browsers.

T1539
Steal Web Session Cookie
MalwareMgBot

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

T1539
Steal Web Session Cookie
MalwareTajMahal

TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications.

T1539
Steal Web Session Cookie
MalwareRaccoon Stealer

Raccoon Stealer attempts to steal cookies and related information in browser history.

T1539
Steal Web Session Cookie
MalwareXCSSET

XCSSET uses scp to access the ~/Library/Cookies/Cookies.binarycookies file.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1539
Steal Web Session Cookie
MalwareCookieMiner

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

T1539
Steal Web Session Cookie
Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

T1539
Steal Web Session Cookie
MalwareKali365

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

T1542.001
System Firmware
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

T1542.001
System Firmware
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1542.001
System Firmware
MalwareTrojan.Mebromi

Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal.

T1542.002
Component Firmware
GroupEquation

Equation is known to have the capability to overwrite the firmware on hard drives from some manufacturers.

T1542.002
Component Firmware
MalwareCyclops Blink

Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices.

T1542.003
Bootkit
GroupAPT41

APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems.

T1542.003
Bootkit
GroupAPT28

APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.

T1542.003
Bootkit
GroupLazarus Group

Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down.

T1542.003
Bootkit
MalwareTrickBot

TrickBot can implant malicious code into a compromised device's firmware.

T1542.003
Bootkit
MalwareWhisperGate

WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots.

T1542.003
Bootkit
MalwareFinFisher

Some FinFisher variants incorporate an MBR rootkit.

T1542.003
Bootkit
MalwareCarberp

Carberp has installed a bootkit on the system to maintain persistence.

T1542.003
Bootkit
MalwareROCKBOOT

ROCKBOOT is a Master Boot Record (MBR) bootkit that uses the MBR to establish persistence.

T1542.003
Bootkit
MalwareBOOTRASH

BOOTRASH is a Volume Boot Record (VBR) bootkit that uses the VBR to maintain persistence.

T1543
Create or Modify System Process
MalwareBRICKSTORM

BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state.

T1543
Create or Modify System Process
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root.

T1543
Create or Modify System Process
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background.

T1543
Create or Modify System Process
MalwareIMAPLoader

IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification.

T1543
Create or Modify System Process
MalwareBOLDMOVE

BOLDMOVE can free all resources and terminate itself on victim machines.

T1543
Create or Modify System Process
MalwareAkira _v2

Akira _v2 can create a child process for encryption.

T1543
Create or Modify System Process
MalwareLunarMail

LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory.

T1543
Create or Modify System Process
MalwareCanisterWorm

CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens.

T1543.001
Launch Agent
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist.

T1543.001
Launch Agent
MalwareInvisibleFerret

InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”.

T1543.001
Launch Agent
MalwaremacOS.OSAMiner

macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder.

T1543.001
Launch Agent
MalwareNETWIRE

NETWIRE can use launch agents for persistence.

T1543.001
Launch Agent
MalwareDacls

Dacls can establish persistence via a LaunchAgent.

T1543.001
Launch Agent
MalwareCuckoo Stealer

Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.

T1543.001
Launch Agent
MalwareFruitFly

FruitFly persists via a Launch Agent.

T1543.001
Launch Agent
MalwareKeydnap

Keydnap uses a Launch Agent to persist.

T1543.001
Launch Agent
MalwareGreen Lambert

Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to true, ensuring the `com.apple.GrowlHelper.plist` file runs every time a user logs in.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.