ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1543.003
Windows Service
MalwareInnaputRAT

Some InnaputRAT variants create a new Windows service to establish persistence.

T1543.003
Windows Service
MalwareZxShell

ZxShell can create a new service using the service parser function ProcessScCommand.

T1543.003
Windows Service
MalwareWinnti for Windows

Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence.

T1543.003
Windows Service
MalwareAppleJeus

AppleJeus can install itself as a service.

T1543.003
Windows Service
MalwareSTARWHALE

STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`.

T1543.003
Windows Service
MalwareIndustroyer

Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary.

T1543.003
Windows Service
MalwareCozyCar

One persistence mechanism used by CozyCar is to register itself as a Windows service.

T1543.003
Windows Service
MalwareQakBot

QakBot can remotely create a temporary service on a target host.

T1543.003
Windows Service
MalwareGelsemium

Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts.

T1543.003
Windows Service
MalwareDtrack

Dtrack can add a service called WBService to establish persistence.

T1543.003
Windows Service
MalwareLoudMiner

LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file.

T1543.003
Windows Service
MalwareBitPaymer

BitPaymer has attempted to install itself as a service to maintain persistence.

T1543.003
Windows Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence.

T1543.003
Windows Service
MalwareFALLCHILL

FALLCHILL has been installed as a Windows service.

T1543.003
Windows Service
ToolSILENTTRINITY

SILENTTRINITY can establish persistence by creating a new service.

T1543.003
Windows Service
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs.

T1543.003
Windows Service
ToolEmpire

Empire can utilize built-in modules to modify service binaries and restore them to their original state.

T1543.003
Windows Service
ToolRemcos

Remcos can terminate, suspend, and resume a process by PID.

T1543.003
Windows Service
ToolPsExec

PsExec can leverage Windows services to escalate privileges from administrator to SYSTEM with the -s argument.

T1543.003
Windows Service
MalwareDuqu

Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key.

T1543.004
Launch Daemon
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus installs a Launch Daemon to execute the POOLRAT macOS backdoor software.

T1543.004
Launch Daemon
MalwareCOATHANGER

COATHANGER will create a daemon for timed check-ins with command and control infrastructure.

T1543.004
Launch Daemon
MalwareDacls

Dacls can establish persistence via a Launch Daemon.

T1543.004
Launch Daemon
MalwareREPTILE

The REPTILE launcher can daemonize a process.

T1543.004
Launch Daemon
MalwareGreen Lambert

Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence.

T1543.004
Launch Daemon
MalwareThiefQuest

When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the /Library/LaunchDaemons/ folder with the RunAtLoad key set to true establishing persistence as a Launch Daemon.

T1543.004
Launch Daemon
MalwareBundlore

Bundlore can persist via a LaunchDaemon.

T1543.004
Launch Daemon
MalwareOSX_OCEANLOTUS.D

If running with root permissions, OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchDaemons.

T1543.004
Launch Daemon
MalwareXCSSET

XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim.

T1543.004
Launch Daemon
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1543.004
Launch Daemon
MalwareLoudMiner

LoudMiner adds plist files with the naming format com.[random_name].plist in the /Library/LaunchDaemons folder with the RunAtLoad and KeepAlive keys set to true.

T1546
Event Triggered Execution
CampaignKV Botnet Activity

KV Botnet Activity involves managing events on victim systems via libevent to execute a callback function when any running process contains the following references in their path without also having a reference to bioset: busybox, wget, curl, tftp, telnetd, or lua. If the bioset string is not found, the related process is terminated.

T1546
Event Triggered Execution
MalwareUPSTYLE

UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run.

T1546
Event Triggered Execution
MalwareXCSSET

XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process.

T1546
Event Triggered Execution
ToolPacu

Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups.

T1546
Event Triggered Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions.

T1546.001
Change Default File Association
GroupKimsuky

Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents.

T1546.001
Change Default File Association
ToolSILENTTRINITY

SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process.

T1546.002
Screensaver
MalwareGazer

Gazer can establish persistence through the system screensaver by configuring it to execute the malware.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignOperation Ghost

During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMustang Panda

Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupLeviathan

Leviathan has used WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupBlue Mockingbird

Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file.

T1546.003
Windows Management Instrumentation Event Subscription
GroupTurla

Turla has used WMI event filters and consumers to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT29

APT29 has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMetador

Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`.

T1546.003
Windows Management Instrumentation Event Subscription
GroupHEXANE

HEXANE has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupRancor

Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT33

APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.