Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1548.002 Bypass User Account Control |
GroupAPT38 | APT38 has used the legitimate application `ieinstal.exe` to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupPatchwork | Patchwork bypassed User Access Control (UAC). |
| T1548.002 Bypass User Account Control |
GroupEvilnum | Evilnum has used PowerShell to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupMuddyWater | MuddyWater uses various techniques to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupAPT37 | APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges. |
| T1548.002 Bypass User Account Control |
GroupAPT29 | APT29 has bypassed UAC. |
| T1548.002 Bypass User Account Control |
GroupMedusa Group | Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface. |
| T1548.002 Bypass User Account Control |
GroupBRONZE BUTLER | BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation. |
| T1548.002 Bypass User Account Control |
GroupEarth Lusca | Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges. |
| T1548.002 Bypass User Account Control |
GroupCobalt Group | Cobalt Group has bypassed UAC. |
| T1548.002 Bypass User Account Control |
GroupThreat Group-3390 | A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges. |
| T1548.002 Bypass User Account Control |
MalwareRCSession | RCSession can bypass UAC to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareBumblebee | Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges. |
| T1548.002 Bypass User Account Control |
MalwareDowndelph | Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database. |
| T1548.002 Bypass User Account Control |
MalwarePLAINTEE | An older variant of PLAINTEE performs UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareBad Rabbit | Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges. |
| T1548.002 Bypass User Account Control |
MalwareBADHATCH | BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWastedLocker | WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later. |
| T1548.002 Bypass User Account Control |
MalwareInvisiMole | InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareZeroT | Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file. |
| T1548.002 Bypass User Account Control |
MalwareRaspberry Robin | Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt. |
| T1548.002 Bypass User Account Control |
MalwareBlackCat | BlackCat can bypass UAC to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareHTTPTroy | HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command. |
| T1548.002 Bypass User Account Control |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges. |
| T1548.002 Bypass User Account Control |
MalwareBlackEnergy | BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later. |
| T1548.002 Bypass User Account Control |
MalwareShimRat | ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing. |
| T1548.002 Bypass User Account Control |
MalwareAvaddon | Avaddon bypasses UAC using the CMSTPLUA COM interface. |
| T1548.002 Bypass User Account Control |
MalwareClambling | Clambling has the ability to bypass UAC using a `passuac.dll` file. |
| T1548.002 Bypass User Account Control |
MalwareDarkGate | DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 3.0 | LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. |
| T1548.002 Bypass User Account Control |
MalwareSaint Bot | Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwarePipeMon | PipeMon installer can use UAC bypass techniques to install the payload. |
| T1548.002 Bypass User Account Control |
MalwareKONNI | KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify". |
| T1548.002 Bypass User Account Control |
MalwareShamoon | Shamoon attempts to disable UAC remote restrictions by modifying the Registry. |
| T1548.002 Bypass User Account Control |
MalwareRTM | RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges. |
| T1548.002 Bypass User Account Control |
MalwareGrandoreiro | Grandoreiro can bypass UAC by registering as the default handler for .MSC files. |
| T1548.002 Bypass User Account Control |
MalwareSakula | Sakula contains UAC bypass code for both 32- and 64-bit systems. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 2.0 | LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`. |
| T1548.002 Bypass User Account Control |
MalwareFinFisher | FinFisher performs UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareCobalt Strike | Cobalt Strike can use a number of known techniques to bypass Windows UAC. |
| T1548.002 Bypass User Account Control |
MalwareRamsay | |
| T1548.002 Bypass User Account Control |
MalwareLokibot | Lokibot has utilized multiple techniques to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWinnti for Windows | Winnti for Windows can use a variant of the sysprep UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareKOCTOPUS | KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe. |
| T1548.002 Bypass User Account Control |
MalwareQilin | Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context. |
| T1548.002 Bypass User Account Control |
MalwareAppleJeus | AppleJeus has presented the user with a UAC prompt to elevate privileges while installing. |
| T1548.002 Bypass User Account Control |
MalwareGelsemium | Gelsemium can bypass UAC to elevate process privileges on a compromised host. |
| T1548.002 Bypass User Account Control |
MalwareAutoIt backdoor | AutoIt backdoor attempts to escalate privileges by bypassing User Access Control. |
| T1548.002 Bypass User Account Control |
MalwareH1N1 | H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe). |
| T1548.002 Bypass User Account Control |
MalwareBitPaymer | BitPaymer can suppress UAC prompts by setting the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.