ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1564.009
Resource Forking
MalwareKeydnap

Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system.

T1564.009
Resource Forking
MalwareOSX/Shlayer

OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners.

T1564.010
Process Argument Spoofing
MalwareSombRAT

SombRAT has the ability to modify its process memory to hide process command-line arguments.

T1564.010
Process Argument Spoofing
MalwareCobalt Strike

Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands.

T1564.011
Ignore Process Interrupts
GroupKimsuky

Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events.

T1564.011
Ignore Process Interrupts
GroupUNC3886

UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted.

T1564.011
Ignore Process Interrupts
GroupSea Turtle

Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.

T1564.011
Ignore Process Interrupts
MalwareBOLDMOVE

BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic.

T1564.011
Ignore Process Interrupts
MalwareGoldMax

The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated.

T1564.011
Ignore Process Interrupts
MalwareBPFDoor

BPFDoor sets its process to ignore the following signals; `SIGHUP`, `SIGINT`, `SIGQUIT`, `SIGPIPE`, `SIGCHLD`, `SIGTTIN`, and `SIGTTOU`.

T1564.011
Ignore Process Interrupts
MalwareShai-Hulud

Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`.

T1564.011
Ignore Process Interrupts
MalwareOSX/Shlayer

OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals.

T1564.011
Ignore Process Interrupts
MalwareMini Shai-Hulud

Mini Shai-Hulud has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values.

T1564.012
File/Path Exclusions
GroupTurla

Turla has placed LunarWeb install files into directories that are excluded from scanning.

T1564.013
Bind Mounts
CampaignKV Botnet Activity

KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory.

T1565
Data Manipulation
GroupFIN13

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.

T1565
Data Manipulation
MalwarePHASEJAM

PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version.

T1565.001
Stored Data Manipulation
GroupAPT38

APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.

T1565.001
Stored Data Manipulation
MalwareMultiLayer Wiper

MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.

T1565.001
Stored Data Manipulation
MalwareSUNSPOT

SUNSPOT created a copy of the SolarWinds Orion software source file with a .bk extension to backup the original content, wrote SUNBURST using the same filename but with a .tmp extension, and then moved SUNBURST using MoveFileEx to the original filename with a .cs extension so it could be compiled within Orion software.

T1565.002
Transmitted Data Manipulation
GroupAPT38

APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer.

T1565.002
Transmitted Data Manipulation
MalwareLightNeuron

LightNeuron is capable of modifying email content, headers, and attachments during transit.

T1565.002
Transmitted Data Manipulation
MalwareGlassWorm

GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing.

T1565.002
Transmitted Data Manipulation
MalwareMetamorfo

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.

T1565.002
Transmitted Data Manipulation
MalwareMelcoz

Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary.

T1565.003
Runtime Data Manipulation
GroupAPT38

APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user.

T1566
Phishing
GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

T1566
Phishing
GroupAppleJeus

AppleJeus has used spearphishing emails to distribute malicious payloads.

T1566
Phishing
GroupMuddyWater

MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.

T1566
Phishing
GroupSea Turtle

Sea Turtle used spear phishing to gain initial access to victims.

T1566
Phishing
GroupAxiom

Axiom has used spear phishing to initially compromise victims.

T1566
Phishing
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines.

T1566
Phishing
GroupINC Ransom

INC Ransom has used phishing to gain initial access.

T1566
Phishing
GroupVOID MANTICORE

VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector.

T1566
Phishing
MalwareRoyal

Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email.

T1566
Phishing
MalwareHikit

Hikit has been spread through spear phishing.

T1566
Phishing
MalwareINC Ransomware

INC Ransomware campaigns have used spearphishing emails for initial access.

T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1566.001
Spearphishing Attachment
CampaignFrankenstein

During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents.

T1566.001
Spearphishing Attachment
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations.

T1566.001
Spearphishing Attachment
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

T1566.001
Spearphishing Attachment
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails.

T1566.001
Spearphishing Attachment
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware.

T1566.001
Spearphishing Attachment
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers.

T1566.001
Spearphishing Attachment
CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

T1566.001
Spearphishing Attachment
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
CampaignC0011

During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.

T1566.001
Spearphishing Attachment
GroupAPT38

APT38 has conducted spearphishing campaigns using malicious email attachments.

T1566.001
Spearphishing Attachment
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupSideCopy

SideCopy has sent spearphishing emails with malicious hta file attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.