ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1568.002
Domain Generation Algorithms
MalwareMilan

Milan can use hardcoded domains as an input for domain generation algorithms.

T1568.002
Domain Generation Algorithms
MalwareCCBkdr

CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost.

T1568.002
Domain Generation Algorithms
MalwareCHOPSTICK

CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists.

T1568.002
Domain Generation Algorithms
MalwareBONDUPDATER

BONDUPDATER uses a DGA to communicate with command and control servers.

T1568.002
Domain Generation Algorithms
MalwareEbury

Ebury has used a DGA to generate a domain name for C2.

T1568.002
Domain Generation Algorithms
MalwareShadowPad

ShadowPad uses a DGA that is based on the day of the month for C2 servers.

T1568.002
Domain Generation Algorithms
MalwareAstaroth

Astaroth has used a DGA in C2 communications.

T1568.002
Domain Generation Algorithms
MalwareQakBot

QakBot can use domain generation algorithms in C2 communication.

T1568.002
Domain Generation Algorithms
Toolngrok

ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours.

T1568.002
Domain Generation Algorithms
ToolAsyncRAT

AsyncRAT use a DGA to generate a C2 domains.

T1568.003
DNS Calculation
GroupAPT12

APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port.

T1569.001
Launchctl
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `launchctl` to restart the Launch Agent.

T1569.001
Launchctl
MalwareCuckoo Stealer

Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence.

T1569.001
Launchctl
MalwareCalisto

Calisto uses launchctl to enable screen sharing on the victim’s machine.

T1569.001
Launchctl
MalwareXCSSET

XCSSET loads a system level launchdaemon using the launchctl load -w command from /System/Librarby/LaunchDaemons/ssh.plist.

T1569.001
Launchctl
MalwareAppleJeus

AppleJeus has loaded a plist file using the launchctl command.

T1569.001
Launchctl
MalwareLoudMiner

LoudMiner launched the QEMU services in the /Library/LaunchDaemons/ folder using launchctl. It also uses launchctl to unload all Launch Daemons when updating to a newer version of LoudMiner.

T1569.002
Service Execution
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys.

T1569.002
Service Execution
CampaignOperation Honeybee

During Operation Honeybee, threat actors ran sc start to start the COMSysApp as part of the service hijacking and sc stop to stop and reconfigure the COMSysApp.

T1569.002
Service Execution
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service.

T1569.002
Service Execution
CampaignAPT41 DUST

APT41 DUST used Windows services to execute DUSTPAN.

T1569.002
Service Execution
CampaignOperation Wocao

During Operation Wocao, threat actors created services on remote systems for execution purposes.

T1569.002
Service Execution
GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

T1569.002
Service Execution
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

T1569.002
Service Execution
GroupFIN7

FIN7 has started the SSH service by executing `sc start sshd`.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

T1569.002
Service Execution
GroupKe3chang

Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries.

T1569.002
Service Execution
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.

T1569.002
Service Execution
GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1569.002
Service Execution
GroupINC Ransom

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1569.002
Service Execution
GroupVelvet Ant

Velvet Ant executed and installed PlugX as a Windows service.

T1569.002
Service Execution
GroupMoonstone Sleet

Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services.

T1569.002
Service Execution
MalwareProxysvc

Proxysvc registers itself as a service on the victim’s machine to run as a standalone process.

T1569.002
Service Execution
MalwareStrongPity

StrongPity can install a service to execute itself as a service.

T1569.002
Service Execution
MalwareTinyTurla

TinyTurla can install itself as a service on compromised machines.

T1569.002
Service Execution
MalwareBad Rabbit

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

T1569.002
Service Execution
MalwareOlympic Destroyer

Olympic Destroyer utilizes PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareMafalda

Mafalda can create a remote service, let it run once, and then delete it.

T1569.002
Service Execution
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware executes as a service when deployed.

T1569.002
Service Execution
MalwareHOPLIGHT

HOPLIGHT has used svchost.exe to execute a malicious DLL .

T1569.002
Service Execution
MalwareWastedLocker

WastedLocker can execute itself as a service.

T1569.002
Service Execution
MalwareInvisiMole

InvisiMole has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1569.002
Service Execution
MalwareOkrum

Okrum's loader can create a new service named NtmsSvc to execute the payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.