ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareShimRat

ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file.

T1027.015
Compression
MalwareSocGholish

The SocGholish JavaScript payload has been delivered within a compressed ZIP archive.

T1027.015
Compression
MalwareLine Runner

Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359.

T1027.015
Compression
MalwareDarkWatchman

DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims.

T1027.015
Compression
MalwareLODEINFO

LODEINFO components have been compressed with zip for delivery.

T1027.015
Compression
MalwareKerrdown

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1027.015
Compression
MalwareRTM

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1027.015
Compression
MalwareStrelaStealer

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1027.015
Compression
MalwareHermeticWiper

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1027.015
Compression
MalwarePandora

Pandora has the ability to compress stings with QuickLZ.

T1027.015
Compression
MalwareSUNBURST

SUNBURST strings were compressed and encoded in Base64.

T1027.015
Compression
MalwareSamurai

Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob.

T1027.015
Compression
MalwarePillowmint

Pillowmint has been compressed and stored within a registry key.

T1027.015
Compression
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.015
Compression
MalwareHancitor

Hancitor has delivered compressed payloads in ZIP files to victims.

T1027.015
Compression
MalwareGelsemium

Gelsemium has the ability to compress its components.

T1027.015
Compression
ToolPcShare

PcShare has been compressed with LZW algorithm.

T1027.015
Compression
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.016
Junk Code Insertion
Malwareyty

yty contains junk code in its binary, likely to confuse malware analysts.

T1027.016
Junk Code Insertion
MalwarePony

Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult.

T1027.016
Junk Code Insertion
MalwareWastedLocker

WastedLocker contains junk code to increase its entropy and hide the actual code.

T1027.016
Junk Code Insertion
MalwareZeroT

ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions.

T1027.016
Junk Code Insertion
MalwareSamSam

SamSam has used garbage code to pad some of its malware components.

T1027.016
Junk Code Insertion
MalwareFatDuke

FatDuke has been packed with junk code and strings.

T1027.016
Junk Code Insertion
MalwareCORESHELL

CORESHELL contains unused machine instructions in a likely attempt to hinder analysis.

T1027.016
Junk Code Insertion
MalwareNOOPLDR

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1027.016
Junk Code Insertion
MalwarePureCrypter

PureCrypter can insert junk code to avoid detection.

T1027.016
Junk Code Insertion
MalwareXTunnel

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.

T1027.016
Junk Code Insertion
MalwareLODEINFO

LODEINFO has inserted junk code to obstruct code analysis.

T1027.016
Junk Code Insertion
MalwareStrelaStealer

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1027.016
Junk Code Insertion
MalwareFinFisher

FinFisher contains junk code in its functions in an effort to confuse disassembly programs.

T1027.016
Junk Code Insertion
MalwareANELLDR

ANELLDR can use junk code for payload obfuscation.

T1027.016
Junk Code Insertion
MalwareMaze

Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process.

T1027.016
Junk Code Insertion
MalwarePOWERSTATS

POWERSTATS has used useless code blocks to counter analysis.

T1027.016
Junk Code Insertion
MalwareGoopy

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1027.016
Junk Code Insertion
MalwareGelsemium

Gelsemium can use junk code to hide functions and evade detection.

T1027.018
Invisible Unicode
MalwareGlassWorm

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1029
Scheduled Transfer
MalwareNinja

Ninja can configure its agent to work only in specific time frames.

T1029
Scheduled Transfer
MalwareTinyTurla

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.

T1029
Scheduled Transfer
MalwareMachete

Machete sends stolen data to the C2 server every 10 minutes.

T1029
Scheduled Transfer
MalwareKazuar

Kazuar can sleep for a specific time and be set to communicate at specific intervals.

T1029
Scheduled Transfer
MalwareShimRat

ShimRat can sleep when instructed to do so by the C2.

T1029
Scheduled Transfer
MalwareChrommme

Chrommme can set itself to sleep before requesting a new command from C2.

T1029
Scheduled Transfer
MalwareFlagpro

Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2.

T1029
Scheduled Transfer
MalwareLightNeuron

LightNeuron can be configured to exfiltrate data during nighttime or working hours.

T1029
Scheduled Transfer
MalwareShark

Shark can pause C2 communications for a specified time.

T1029
Scheduled Transfer
MalwareCobalt Strike

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.

T1029
Scheduled Transfer
MalwareComRAT

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1029
Scheduled Transfer
MalwareDipsind

Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic.

T1029
Scheduled Transfer
MalwarePOWERSTATS

POWERSTATS can sleep for a given number of seconds.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.