ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1548.002
Bypass User Account Control
GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

T1548.002
Bypass User Account Control
GroupPatchwork

Patchwork bypassed User Access Control (UAC).

T1548.002
Bypass User Account Control
GroupEvilnum

Evilnum has used PowerShell to bypass UAC.

T1548.002
Bypass User Account Control
GroupMuddyWater

MuddyWater uses various techniques to bypass UAC.

T1548.002
Bypass User Account Control
GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

T1548.002
Bypass User Account Control
GroupAPT29

APT29 has bypassed UAC.

T1548.002
Bypass User Account Control
GroupMedusa Group

Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.

T1548.002
Bypass User Account Control
GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

T1548.002
Bypass User Account Control
GroupEarth Lusca

Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.

T1548.002
Bypass User Account Control
GroupCobalt Group

Cobalt Group has bypassed UAC.

T1548.002
Bypass User Account Control
GroupThreat Group-3390

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.

T1548.002
Bypass User Account Control
MalwareRCSession

RCSession can bypass UAC to escalate privileges.

T1548.002
Bypass User Account Control
MalwareBumblebee

Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges.

T1548.002
Bypass User Account Control
MalwareDowndelph

Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database.

T1548.002
Bypass User Account Control
MalwarePLAINTEE

An older variant of PLAINTEE performs UAC bypass.

T1548.002
Bypass User Account Control
MalwareBad Rabbit

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.

T1548.002
Bypass User Account Control
MalwareBADHATCH

BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWastedLocker

WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later.

T1548.002
Bypass User Account Control
MalwareInvisiMole

InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges.

T1548.002
Bypass User Account Control
MalwareZeroT

Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file.

T1548.002
Bypass User Account Control
MalwareRaspberry Robin

Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt.

T1548.002
Bypass User Account Control
MalwareBlackCat

BlackCat can bypass UAC to escalate privileges.

T1548.002
Bypass User Account Control
MalwareHTTPTroy

HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command.

T1548.002
Bypass User Account Control
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges.

T1548.002
Bypass User Account Control
MalwareBlackEnergy

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.

T1548.002
Bypass User Account Control
MalwareShimRat

ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing.

T1548.002
Bypass User Account Control
MalwareAvaddon

Avaddon bypasses UAC using the CMSTPLUA COM interface.

T1548.002
Bypass User Account Control
MalwareClambling

Clambling has the ability to bypass UAC using a `passuac.dll` file.

T1548.002
Bypass User Account Control
MalwareDarkGate

DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges.

T1548.002
Bypass User Account Control
MalwareLockBit 3.0

LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface.

T1548.002
Bypass User Account Control
MalwareSaint Bot

Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges.

T1548.002
Bypass User Account Control
MalwarePipeMon

PipeMon installer can use UAC bypass techniques to install the payload.

T1548.002
Bypass User Account Control
MalwareKONNI

KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify".

T1548.002
Bypass User Account Control
MalwareShamoon

Shamoon attempts to disable UAC remote restrictions by modifying the Registry.

T1548.002
Bypass User Account Control
MalwareRTM

RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges.

T1548.002
Bypass User Account Control
MalwareGrandoreiro

Grandoreiro can bypass UAC by registering as the default handler for .MSC files.

T1548.002
Bypass User Account Control
MalwareSakula

Sakula contains UAC bypass code for both 32- and 64-bit systems.

T1548.002
Bypass User Account Control
MalwareLockBit 2.0

LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`.

T1548.002
Bypass User Account Control
MalwareFinFisher

FinFisher performs UAC bypass.

T1548.002
Bypass User Account Control
MalwareCobalt Strike

Cobalt Strike can use a number of known techniques to bypass Windows UAC.

T1548.002
Bypass User Account Control
MalwareRamsay

Ramsay can use UACMe for privilege escalation.

T1548.002
Bypass User Account Control
MalwareLokibot

Lokibot has utilized multiple techniques to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWinnti for Windows

Winnti for Windows can use a variant of the sysprep UAC bypass.

T1548.002
Bypass User Account Control
MalwareKOCTOPUS

KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe.

T1548.002
Bypass User Account Control
MalwareQilin

Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.

T1548.002
Bypass User Account Control
MalwareAppleJeus

AppleJeus has presented the user with a UAC prompt to elevate privileges while installing.

T1548.002
Bypass User Account Control
MalwareGelsemium

Gelsemium can bypass UAC to elevate process privileges on a compromised host.

T1548.002
Bypass User Account Control
MalwareAutoIt backdoor

AutoIt backdoor attempts to escalate privileges by bypassing User Access Control.

T1548.002
Bypass User Account Control
MalwareH1N1

H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe).

T1548.002
Bypass User Account Control
MalwareBitPaymer

BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.