ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1543.001
Launch Agent
MalwareThiefQuest

ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the ~/Library/LaunchAgents/ folder and configured with the path to the persistent binary located in the ~/Library/ folder.

T1543.001
Launch Agent
MalwareBundlore

Bundlore can persist via a LaunchAgent.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1543.001
Launch Agent
MalwareCrossRAT

CrossRAT creates a Launch Agent on macOS.

T1543.001
Launch Agent
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchAgents.

T1543.001
Launch Agent
MalwareCalisto

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

T1543.001
Launch Agent
MalwareProton

Proton persists via Launch Agent.

T1543.001
Launch Agent
MalwareCoinTicker

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

T1543.001
Launch Agent
MalwareCookieMiner

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

T1543.001
Launch Agent
MalwareKomplex

The Komplex trojan creates a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist with launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist.

T1543.001
Launch Agent
MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

T1543.001
Launch Agent
MalwareMacSpy

MacSpy persists via a Launch Agent.

T1543.001
Launch Agent
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds.

T1543.002
Systemd Service
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins.

T1543.002
Systemd Service
GroupTeamTNT

TeamTNT has established persistence through the creation of a cryptocurrency mining system service using systemctl.

T1543.002
Systemd Service
GroupRocke

Rocke has installed a systemd service script to maintain persistence.

T1543.002
Systemd Service
GroupScattered Spider

Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/
system/teleport.service` to establish persistence for the Teleport remote access tool.

T1543.002
Systemd Service
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

T1543.002
Systemd Service
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1543.002
Systemd Service
MalwareGomir

Gomir creates a systemd service named `syslogd` for persistence.

T1543.002
Systemd Service
MalwareHildegard

Hildegard has started a monero service.

T1543.002
Systemd Service
MalwareFysbis

Fysbis has established persistence using a systemd service.

T1543.002
Systemd Service
MalwareSysUpdate

SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges.

T1543.002
Systemd Service
MalwareRIFLESPINE

RIFLESPINE can create a systemd service file for execution.

T1543.002
Systemd Service
MalwareShai-Hulud

Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls.

T1543.002
Systemd Service
ToolPupy

Pupy can be used to establish persistence using a systemd service.

T1543.002
Systemd Service
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence.

T1543.002
Systemd Service
MalwareMini Shai-Hulud

Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence.

T1543.002
Systemd Service
GroupTeamPCP

TeamPCP has used the systemd user service for malware persistence in targeted environments.

T1543.003
Windows Service
CampaignOperation Honeybee

During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services.

T1543.003
Windows Service
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code.

T1543.003
Windows Service
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence.

T1543.003
Windows Service
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

T1543.003
Windows Service
CampaignAPT41 DUST

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

T1543.003
Windows Service
GroupAPT38

APT38 has installed a new Windows service to establish persistence.

T1543.003
Windows Service
GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

T1543.003
Windows Service
GroupAPT3

APT3 has a tool that creates a new service for persistence.

T1543.003
Windows Service
GroupKimsuky

Kimsuky has created new services for persistence.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1543.003
Windows Service
GroupAPT32

APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence.

T1543.003
Windows Service
GroupTeamTNT

TeamTNT has used malware that adds cryptocurrency miners as a service.

T1543.003
Windows Service
GroupFIN7

FIN7 created new Windows services and added them to the startup directories for persistence.

T1543.003
Windows Service
GroupOilRig

OilRig has used a compromised Domain Controller to create a service on a remote host.

T1543.003
Windows Service
GroupCarbanak

Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges.

T1543.003
Windows Service
GroupTropic Trooper

Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk.

T1543.003
Windows Service
GroupAquatic Panda

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

T1543.003
Windows Service
GroupKe3chang

Ke3chang backdoor RoyalDNS established persistence through adding a service called Nwsapagent.

T1543.003
Windows Service
GroupBlue Mockingbird

Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.

T1543.003
Windows Service
GroupDarkVishnya

DarkVishnya created new services for shellcode loaders distribution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.