ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1553.002
Code Signing
MalwareQakBot

QakBot can use signed loaders to evade detection.

T1553.002
Code Signing
MalwareHelminth

Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared.

T1553.002
Code Signing
MalwareHermeticWizard

HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.

T1553.002
Code Signing
ToolCSPY Downloader

CSPY Downloader has come signed with revoked certificates.

T1553.002
Code Signing
ToolQuasarRAT

A QuasarRAT .dll file is digitally signed by a certificate from AirVPN.

T1553.002
Code Signing
GroupTeamPCP

TeamPCP has compromised legitimate software release workflows resulting in malicious packages receiving legitimate project cryptographic signing.

T1553.002
Code Signing
MalwareZeroCleare

ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards.

T1553.004
Install Root Certificate
MalwareRTM

RTM can add a certificate to the Windows store.

T1553.004
Install Root Certificate
MalwareHikit

Hikit installs a self-generated certificate to the local trust store as a root CA and Trusted Publisher.

T1553.004
Install Root Certificate
MalwareDok

Dok installs a root certificate to aid in Adversary-in-the-Middle actions using the command add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/filename.

T1553.004
Install Root Certificate
Toolcertutil

certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: certutil -addstore -f -user ROOT ProgramData\cert512121.der.

T1553.004
Install Root Certificate
Toolevilginx2

evilginx2 has obtained a valid SSL/TLS certificate from LetsEncrypt to provide responses to Automatic Certificate Management Environment (ACME) challenges.

T1553.005
Mark-of-the-Web Bypass
GroupAPT38

APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures.

T1553.005
Mark-of-the-Web Bypass
GroupTA505

TA505 has used .iso files to deploy malicious .lnk files.

T1553.005
Mark-of-the-Web Bypass
GroupAPT29

APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web.

T1553.005
Mark-of-the-Web Bypass
MalwareAmadey

Amadey has modified the `:Zone.Identifier` in the ADS area to zero.

T1553.005
Mark-of-the-Web Bypass
MalwareQakBot

QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.

T1553.006
Code Signing Policy Modification
GroupAPT39

APT39 has used malware to turn off the RequireSigned feature which ensures only signed DLLs can be run on Windows.

T1553.006
Code Signing Policy Modification
GroupTurla

Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges.

T1553.006
Code Signing Policy Modification
MalwareBlackEnergy

BlackEnergy has enabled the TESTSIGNING boot configuration option to facilitate loading of a driver component.

T1553.006
Code Signing Policy Modification
MalwareHikit

Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component.

T1553.006
Code Signing Policy Modification
MalwarePandora

Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1554
Compromise Host Software Binary
CampaignRedPenguin

During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.

T1554
Compromise Host Software Binary
CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

T1554
Compromise Host Software Binary
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer.

T1554
Compromise Host Software Binary
GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

T1554
Compromise Host Software Binary
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

T1554
Compromise Host Software Binary
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset.

T1554
Compromise Host Software Binary
MalwareBUSHWALK

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
MalwareBOLDMOVE

BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades.

T1554
Compromise Host Software Binary
MalwareBonadan

Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1554
Compromise Host Software Binary
MalwareLIGHTWIRE

LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution.

T1554
Compromise Host Software Binary
MalwareThiefQuest

ThiefQuest searches through the /Users/ folder looking for executable files. For each executable, ThiefQuest prepends a copy of itself to the beginning of the file. When the file is executed, the ThiefQuest code is executed first. ThiefQuest creates a hidden file, copies the original target executable to the file, then executes the new hidden file to maintain the appearance of normal behavior.

T1554
Compromise Host Software Binary
MalwareGlassWorm

GlassWorm can modify hardware wallet applications.

T1554
Compromise Host Software Binary
MalwareKobalos

Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems.

T1554
Compromise Host Software Binary
MalwareWARPWIRE

WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
MalwareFRAMESTING

FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.`

T1554
Compromise Host Software Binary
MalwareWIREFIRE

WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution.

T1554
Compromise Host Software Binary
MalwareKessel

Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1554
Compromise Host Software Binary
MalwarePHASEJAM

PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided.

T1554
Compromise Host Software Binary
MalwareBFG Agonizer

BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use.

T1554
Compromise Host Software Binary
MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1554
Compromise Host Software Binary
MalwareXCSSET

XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules.

T1554
Compromise Host Software Binary
MalwareIndustroyer

Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism.

T1554
Compromise Host Software Binary
MalwareSLOWPULSE

SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files.

T1554
Compromise Host Software Binary
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers.

T1555
Credentials from Password Stores
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords.

T1555
Credentials from Password Stores
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`.

T1555
Credentials from Password Stores
GroupVolt Typhoon

Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.

T1555
Credentials from Password Stores
GroupAPT41

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.