ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1552.005
Cloud Instance Metadata API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API.

T1552.006
Group Policy Preferences
GroupWizard Spider

Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy.

T1552.006
Group Policy Preferences
GroupAPT33

APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.

T1552.006
Group Policy Preferences
MalwareMirrorStealer

MirrorStealer can target Group Policy Preferences for credentials.

T1552.006
Group Policy Preferences
ToolSILENTTRINITY

SILENTTRINITY has a module that can extract cached GPP passwords.

T1552.006
Group Policy Preferences
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences.

T1552.007
Container API
ToolPeirates

Peirates can query the Kubernetes API for secrets.

T1552.007
Container API
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can query the Kubernetes API for credentials.

T1552.007
Container API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators.

T1552.008
Chat Messages
GroupLAPSUS$

LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.

T1553
Subvert Trust Controls
GroupAxiom

Axiom has used digital certificates to deliver malware.

T1553
Subvert Trust Controls
MalwareShai-Hulud

Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0.

T1553.001
Gatekeeper Bypass
MalwareCuckoo Stealer

Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute.

T1553.001
Gatekeeper Bypass
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses the command xattr -d com.apple.quarantine to remove the quarantine file attribute used by Gatekeeper.

T1553.001
Gatekeeper Bypass
MalwareMacMa

MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`.

T1553.001
Gatekeeper Bypass
MalwareCoinTicker

CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag.

T1553.001
Gatekeeper Bypass
MalwareXCSSET

XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13).

T1553.001
Gatekeeper Bypass
MalwareOSX/Shlayer

If running with elevated privileges, OSX/Shlayer has used the spctl command to disable Gatekeeper protection for a downloaded file. OSX/Shlayer can also leverage system links pointing to bash scripts in the downloaded DMG file to bypass Gatekeeper, a flaw patched in macOS 11.3 and later versions. OSX/Shlayer has been Notarized by Apple, resulting in successful passing of additional Gatekeeper checks.

T1553.002
Code Signing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection.

T1553.002
Code Signing
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations.

T1553.002
Code Signing
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature.

T1553.002
Code Signing
Campaign3CX Supply Chain Attack

Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate.

T1553.002
Code Signing
CampaignC0015

For C0015, the threat actors used DLL files that had invalid certificates.

T1553.002
Code Signing
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.

T1553.002
Code Signing
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT.

T1553.002
Code Signing
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

T1553.002
Code Signing
GroupGALLIUM

GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC.

T1553.002
Code Signing
GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

T1553.002
Code Signing
GroupPatchwork

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1553.002
Code Signing
GroupmenuPass

menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures.

T1553.002
Code Signing
GroupFIN6

FIN6 has used Comodo code-signing certificates.

T1553.002
Code Signing
GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
GroupScattered Spider

Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC.

T1553.002
Code Signing
GroupMoses Staff

Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.

T1553.002
Code Signing
GroupOilRig

OilRig has signed its malware with stolen certificates.

T1553.002
Code Signing
GroupSuckfly

Suckfly has used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupSaint Bear

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

T1553.002
Code Signing
GroupMirrorFace

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.

T1553.002
Code Signing
GroupMedusa Group

Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

T1553.002
Code Signing
GroupLuminousMoth

LuminousMoth has signed their malware with a valid digital signature.

T1553.002
Code Signing
GroupWinnti Group

Winnti Group used stolen certificates to sign its malware.

T1553.002
Code Signing
GroupLazarus Group

Lazarus Group has digitally signed malware and utilities to evade detection.

T1553.002
Code Signing
GroupSilence

Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot).

T1553.002
Code Signing
GroupCopyKittens

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

T1553.002
Code Signing
GroupWizard Spider

Wizard Spider has used Digicert code-signing certificates for some of its malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.