ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1559
Inter-Process Communication
MalwareHyperStack

HyperStack can connect to the IPC$ share on remote machines.

T1559
Inter-Process Communication
MalwareRaspberry Robin

Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory.

T1559
Inter-Process Communication
MalwareUroburos

Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes.

T1559
Inter-Process Communication
MalwareOilBooster

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

T1559
Inter-Process Communication
MalwareCyclops Blink

Cyclops Blink has the ability to create a pipe to enable inter-process communication.

T1559
Inter-Process Communication
MalwareROADSWEEP

ROADSWEEP can pipe command output to a targeted process.

T1559
Inter-Process Communication
MalwareStealBit

StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner.

T1559
Inter-Process Communication
MalwareSPAWNCHIMERA

SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process.

T1559
Inter-Process Communication
MalwarePITSTOP

PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`.

T1559
Inter-Process Communication
MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

T1559
Inter-Process Communication
MalwareMini Shai-Hulud

Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.

T1559.001
Component Object Model
GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1559.001
Component Object Model
GroupGamaredon Group

Gamaredon Group malware can insert malicious macros into documents using a Microsoft.Office.Interop object.

T1559.001
Component Object Model
GroupMedusa Group

Medusa Group has leveraged Component Object Model (COM) to bypass UAC.

T1559.001
Component Object Model
MalwareTrickBot

TrickBot used COM to setup scheduled task for persistence.

T1559.001
Component Object Model
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

T1559.001
Component Object Model
MalwareUrsnif

Ursnif droppers have used COM objects to execute the malware's full executable payload.

T1559.001
Component Object Model
MalwareSTATICPLUGIN

STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file.

T1559.001
Component Object Model
MalwareInvisiMole

InvisiMole can use the ITaskService, ITaskDefinition and ITaskSettings COM interfaces to schedule a task.

T1559.001
Component Object Model
MalwareCLAIMLOADER

CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface.

T1559.001
Component Object Model
MalwareNeoichor

Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2.

T1559.001
Component Object Model
MalwareRaspberry Robin

Raspberry Robin creates an elevated COM object for CMLuaUtil and uses this to set a registry value that points to the malicious LNK file during execution.

T1559.001
Component Object Model
MalwareRustyWater

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

T1559.001
Component Object Model
MalwareDarkTortilla

DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1559.001
Component Object Model
MalwareMilan

Milan can use a COM component to generate scheduled tasks.

T1559.001
Component Object Model
MalwareRamsay

Ramsay can use the Windows COM API to schedule tasks and maintain persistence.

T1559.001
Component Object Model
MalwareFunnyDream

FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms.

T1559.001
Component Object Model
MalwarePOWERSTATS

POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts.

T1559.001
Component Object Model
MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

T1559.001
Component Object Model
MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

T1559.001
Component Object Model
ToolSILENTTRINITY

SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object.

T1559.002
Dynamic Data Exchange
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims.

T1559.002
Dynamic Data Exchange
GroupPatchwork

Patchwork leveraged the DDE protocol to deliver their malware.

T1559.002
Dynamic Data Exchange
GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

T1559.002
Dynamic Data Exchange
GroupGallmaker

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

T1559.002
Dynamic Data Exchange
GroupFIN7

FIN7 spear phishing campaigns have included malicious Word documents with DDE execution.

T1559.002
Dynamic Data Exchange
GroupSidewinder

Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.

T1559.002
Dynamic Data Exchange
GroupAPT37

APT37 has used Windows DDE for execution of commands and a malicious VBS.

T1559.002
Dynamic Data Exchange
GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

T1559.002
Dynamic Data Exchange
GroupTA505

TA505 has leveraged malicious Word documents that abused DDE.

T1559.002
Dynamic Data Exchange
GroupBITTER

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

T1559.002
Dynamic Data Exchange
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

T1559.002
Dynamic Data Exchange
GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

T1559.002
Dynamic Data Exchange
MalwareHAWKBALL

HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode.

T1559.002
Dynamic Data Exchange
MalwareGravityRAT

GravityRAT has been delivered via Word documents using DDE for execution.

T1559.002
Dynamic Data Exchange
MalwareKeyBoy

KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads.

T1559.002
Dynamic Data Exchange
MalwareRTM

RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism.

T1559.002
Dynamic Data Exchange
MalwareValak

Valak can execute tasks via OLE.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.