Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.002 Code Signing |
MalwareQakBot | QakBot can use signed loaders to evade detection. |
| T1553.002 Code Signing |
MalwareHelminth | Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared. |
| T1553.002 Code Signing |
MalwareHermeticWizard | HermeticWizard has been signed by valid certificates assigned to Hermetica Digital. |
| T1553.002 Code Signing |
ToolCSPY Downloader | CSPY Downloader has come signed with revoked certificates. |
| T1553.002 Code Signing |
ToolQuasarRAT | A QuasarRAT .dll file is digitally signed by a certificate from AirVPN. |
| T1553.002 Code Signing |
GroupTeamPCP | TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing. |
| T1553.002 Code Signing |
MalwareZeroCleare | ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards. |
| T1553.004 Install Root Certificate |
MalwareRTM | RTM can add a certificate to the Windows store. |
| T1553.004 Install Root Certificate |
MalwareHikit | Hikit installs a self-generated certificate to the local trust store as a root CA and Trusted Publisher. |
| T1553.004 Install Root Certificate |
MalwareDok | Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command |
| T1553.004 Install Root Certificate |
Toolcertutil | certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: |
| T1553.004 Install Root Certificate |
Toolevilginx2 | evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT38 | APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures. |
| T1553.005 Mark-of-the-Web Bypass |
GroupTA505 | TA505 has used .iso files to deploy malicious .lnk files. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT29 | APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareAmadey | Amadey has modified the `:Zone.Identifier` in the ADS area to zero. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareQakBot | QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures. |
| T1553.006 Code Signing Policy Modification |
GroupAPT39 | APT39 has used malware to turn off the |
| T1553.006 Code Signing Policy Modification |
GroupTurla | Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges. |
| T1553.006 Code Signing Policy Modification |
MalwareBlackEnergy | BlackEnergy has enabled the |
| T1553.006 Code Signing Policy Modification |
MalwareHikit | Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component. |
| T1553.006 Code Signing Policy Modification |
MalwarePandora | Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1554 Compromise Host Software Binary |
CampaignRedPenguin | During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons. |
| T1554 Compromise Host Software Binary |
CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| T1554 Compromise Host Software Binary |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer. |
| T1554 Compromise Host Software Binary |
GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| T1554 Compromise Host Software Binary |
GroupAPT5 | APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence. |
| T1554 Compromise Host Software Binary |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset. |
| T1554 Compromise Host Software Binary |
MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareBOLDMOVE | BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| T1554 Compromise Host Software Binary |
MalwareBonadan | Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwareLIGHTWIRE | LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution. |
| T1554 Compromise Host Software Binary |
MalwareThiefQuest | ThiefQuest searches through the |
| T1554 Compromise Host Software Binary |
MalwareGlassWorm | GlassWorm can modify hardware wallet applications. |
| T1554 Compromise Host Software Binary |
MalwareKobalos | Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems. |
| T1554 Compromise Host Software Binary |
MalwareWARPWIRE | WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareFRAMESTING | FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.` |
| T1554 Compromise Host Software Binary |
MalwareWIREFIRE | WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1554 Compromise Host Software Binary |
MalwareKessel | Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwarePHASEJAM | PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided. |
| T1554 Compromise Host Software Binary |
MalwareBFG Agonizer | BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| T1554 Compromise Host Software Binary |
MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1554 Compromise Host Software Binary |
MalwareXCSSET | XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules. |
| T1554 Compromise Host Software Binary |
MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| T1554 Compromise Host Software Binary |
MalwareSLOWPULSE | SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files. |
| T1554 Compromise Host Software Binary |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers. |
| T1555 Credentials from Password Stores |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords. |
| T1555 Credentials from Password Stores |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`. |
| T1555 Credentials from Password Stores |
GroupVolt Typhoon | Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY. |
| T1555 Credentials from Password Stores |
GroupAPT41 | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.