ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1543.003
Windows Service
GroupLotus Blossom

Lotus Blossom has configured tools such as Sagerunex to run as Windows services.

T1543.003
Windows Service
GroupCinnamon Tempest

Cinnamon Tempest has created system services to establish persistence for deployed tooling.

T1543.003
Windows Service
GroupMedusa Group

Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.

T1543.003
Windows Service
GroupAgrius

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.

T1543.003
Windows Service
GroupLazarus Group

Several Lazarus Group malware families install themselves as new services.

T1543.003
Windows Service
GroupEarth Lusca

Earth Lusca created a service using the command sc create “SysUpdate” binpath= “cmd /c start “[file path]””&&sc config “SysUpdate” start= auto&&net
start SysUpdate
for persistence.

T1543.003
Windows Service
GroupCobalt Group

Cobalt Group has created new services to establish persistence.

T1543.003
Windows Service
GroupWizard Spider

Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.

T1543.003
Windows Service
GroupPROMETHIUM

PROMETHIUM has created new services and modified existing services for persistence.

T1543.003
Windows Service
GroupThreat Group-3390

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.

T1543.003
Windows Service
GroupAPT19

An APT19 Port 22 malware variant registers itself as a service.

T1543.003
Windows Service
MalwareTrickBot

TrickBot establishes persistence by creating an autostart service that allows it to run whenever the machine boots.

T1543.003
Windows Service
MalwareNinja

Ninja can create the services `httpsvc` and `w3esvc` for persistence .

T1543.003
Windows Service
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can create a service.

T1543.003
Windows Service
MalwareExaramel for Windows

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.”

T1543.003
Windows Service
MalwareStuxnet

Stuxnet uses a driver registered as a boot start service as the main load-point.

T1543.003
Windows Service
MalwareTDTESS

If running as administrator, TDTESS installs itself as a new service named bmwappushservice to establish persistence.

T1543.003
Windows Service
MalwareEmissary

Emissary is capable of configuring itself as a service.

T1543.003
Windows Service
MalwareUrsnif

Ursnif has registered itself as a system service in the Registry for automatic execution at system startup.

T1543.003
Windows Service
MalwareThreatNeedle

ThreatNeedle can run in memory and register its payload as a Windows service.

T1543.003
Windows Service
MalwareZLib

ZLib creates Registry keys to allow itself to run as various services.

T1543.003
Windows Service
MalwareBankshot

Bankshot can terminate a specific process by its process id.

T1543.003
Windows Service
MalwareStrongPity

StrongPity has created new services and modified existing services for persistence.

T1543.003
Windows Service
MalwareNebulae

Nebulae can create a service to establish persistence.

T1543.003
Windows Service
MalwareAuditCred

AuditCred is installed as a new service on the system.

T1543.003
Windows Service
MalwareTONESHELL

TONESHELL has created a malicious service DISMsrv to maintain persistence.

T1543.003
Windows Service
MalwareHannotog

Hannotog creates a new service for persistence.

T1543.003
Windows Service
MalwareMedusa Ransomware

Medusa Ransomware has created a new PowerShell process using the `CreateProcessA` API.

T1543.003
Windows Service
MalwareRainyDay

RainyDay can use services to establish persistence.

T1543.003
Windows Service
MalwareBOOKWORM

BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence.

T1543.003
Windows Service
MalwareCosmicDuke

CosmicDuke uses Windows services typically named "javamtsup" for persistence.

T1543.003
Windows Service
MalwareGreyEnergy

GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.

T1543.003
Windows Service
MalwareEmotet

Emotet has been observed creating new services to maintain persistence.

T1543.003
Windows Service
MalwareTEARDROP

TEARDROP ran as a Windows service from the c:\windows\syswow64 folder.

T1543.003
Windows Service
MalwareDUSTPAN

DUSTPAN can persist as a Windows Service in operations.

T1543.003
Windows Service
MalwarePingPull

PingPull has the ability to install itself as a service.

T1543.003
Windows Service
MalwareSUGARUSH

SUGARUSH has created a service named `Service1` for persistence.

T1543.003
Windows Service
MalwareWastedLocker

WastedLocker created and established a service that runs until the encryption process is complete.

T1543.003
Windows Service
MalwareInvisiMole

InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence.

T1543.003
Windows Service
MalwareNaid

Naid creates a new service to establish.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

T1543.003
Windows Service
MalwareZeroT

ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system.

T1543.003
Windows Service
MalwareRDAT

RDAT has created a service when it is installed on the victim machine.

T1543.003
Windows Service
MalwareOkrum

To establish persistence, Okrum can install itself as a new service named NtmSsvc.

T1543.003
Windows Service
MalwareKazuar

Kazuar can install itself as a new service.

T1543.003
Windows Service
MalwareRagnar Locker

Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver.

T1543.003
Windows Service
MalwareBlackEnergy

One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name.

T1543.003
Windows Service
MalwarezwShell

zwShell has established persistence by adding itself as a new service.

T1543.003
Windows Service
MalwareDCSrv

DCSrv has created new services for persistence by modifying the Registry.

T1543.003
Windows Service
MalwareShimRat

ShimRat has installed a Windows service to maintain persistence on victim machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.