Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.009 Resource Forking |
MalwareKeydnap | Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system. |
| T1564.009 Resource Forking |
MalwareOSX/Shlayer | OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners. |
| T1564.010 Process Argument Spoofing |
MalwareSombRAT | SombRAT has the ability to modify its process memory to hide process command-line arguments. |
| T1564.010 Process Argument Spoofing |
MalwareCobalt Strike | Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands. |
| T1564.011 Ignore Process Interrupts |
GroupKimsuky | Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events. |
| T1564.011 Ignore Process Interrupts |
GroupUNC3886 | UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted. |
| T1564.011 Ignore Process Interrupts |
GroupSea Turtle | Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal. |
| T1564.011 Ignore Process Interrupts |
MalwareBOLDMOVE | BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic. |
| T1564.011 Ignore Process Interrupts |
MalwareGoldMax | The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated. |
| T1564.011 Ignore Process Interrupts |
MalwareBPFDoor | BPFDoor sets its process to ignore the following signals; `SIGHUP`, `SIGINT`, `SIGQUIT`, `SIGPIPE`, `SIGCHLD`, `SIGTTIN`, and `SIGTTOU`. |
| T1564.011 Ignore Process Interrupts |
MalwareShai-Hulud | Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`. |
| T1564.011 Ignore Process Interrupts |
MalwareOSX/Shlayer | OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals. |
| T1564.011 Ignore Process Interrupts |
MalwareMini Shai-Hulud | Mini Shai-Hulud has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values. |
| T1564.012 File/Path Exclusions |
GroupTurla | Turla has placed LunarWeb install files into directories that are excluded from scanning. |
| T1564.013 Bind Mounts |
CampaignKV Botnet Activity | KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory. |
| T1565 Data Manipulation |
GroupFIN13 | FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money. |
| T1565 Data Manipulation |
MalwarePHASEJAM | PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version. |
| T1565.001 Stored Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions. |
| T1565.001 Stored Data Manipulation |
MalwareMultiLayer Wiper | MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult. |
| T1565.001 Stored Data Manipulation |
MalwareSUNSPOT | SUNSPOT created a copy of the SolarWinds Orion software source file with a |
| T1565.002 Transmitted Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer. |
| T1565.002 Transmitted Data Manipulation |
MalwareLightNeuron | LightNeuron is capable of modifying email content, headers, and attachments during transit. |
| T1565.002 Transmitted Data Manipulation |
MalwareGlassWorm | GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing. |
| T1565.002 Transmitted Data Manipulation |
MalwareMetamorfo | Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address. |
| T1565.002 Transmitted Data Manipulation |
MalwareMelcoz | Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary. |
| T1565.003 Runtime Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user. |
| T1566 Phishing |
GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| T1566 Phishing |
GroupAppleJeus | AppleJeus has used spearphishing emails to distribute malicious payloads. |
| T1566 Phishing |
GroupMuddyWater | MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com. |
| T1566 Phishing |
GroupSea Turtle | Sea Turtle used spear phishing to gain initial access to victims. |
| T1566 Phishing |
GroupAxiom | Axiom has used spear phishing to initially compromise victims. |
| T1566 Phishing |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines. |
| T1566 Phishing |
GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| T1566 Phishing |
GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| T1566 Phishing |
MalwareRoyal | Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email. |
| T1566 Phishing |
MalwareHikit | Hikit has been spread through spear phishing. |
| T1566 Phishing |
MalwareINC Ransomware | INC Ransomware campaigns have used spearphishing emails for initial access. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1566.001 Spearphishing Attachment |
CampaignFrankenstein | During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware. |
| T1566.001 Spearphishing Attachment |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers. |
| T1566.001 Spearphishing Attachment |
CampaignC0015 | For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims. |
| T1566.001 Spearphishing Attachment |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
CampaignC0011 | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India. |
| T1566.001 Spearphishing Attachment |
GroupAPT38 | APT38 has conducted spearphishing campaigns using malicious email attachments. |
| T1566.001 Spearphishing Attachment |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupSideCopy | SideCopy has sent spearphishing emails with malicious hta file attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.