ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1614.001
System Language Discovery
MalwareLockBit 2.0

LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so.

T1614.001
System Language Discovery
MalwareREvil

REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage. If the language is found in the list, the process terminates.

T1614.001
System Language Discovery
MalwareGrimAgent

GrimAgent has used Accept-Language to identify hosts in the United Kingdom, United States, France, and Spain.

T1614.001
System Language Discovery
MalwareClop

Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the GetTextCharset function.

T1614.001
System Language Discovery
MalwareStealBit

StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries.

T1614.001
System Language Discovery
MalwareMaze

Maze has checked the language of the machine with function GetUserDefaultUILanguage and terminated execution if the language matches with an entry in the predefined list.

T1614.001
System Language Discovery
MalwareXCSSET

XCSSET uses AppleScript to check the host's language and location with the command user locale of (get system info).

T1614.001
System Language Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language.

T1614.001
System Language Discovery
MalwareCanisterWorm

CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.

T1615
Group Policy Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed extensive Active Directory enumeration of victim environments during Leviathan Australian Intrusions.

T1615
Group Policy Discovery
GroupTurla

Turla surveys a system upon check-in to discover Group Policy details using the gpresult command.

T1615
Group Policy Discovery
MalwareEmissary

Emissary has the capability to execute gpresult.

T1615
Group Policy Discovery
MalwareDUSTTRAP

DUSTTRAP can identify victim environment Group Policy information.

T1615
Group Policy Discovery
MalwareLunarWeb

LunarWeb can capture information on group policy settings

T1615
Group Policy Discovery
ToolBloodHound

BloodHound has the ability to collect local admin information via GPO.

T1615
Group Policy Discovery
ToolEmpire

Empire includes various modules for enumerating Group Policy.

T1619
Cloud Storage Object Discovery
ToolPacu

Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes.

T1619
Cloud Storage Object Discovery
ToolTruffleHog

TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets.

T1619
Cloud Storage Object Discovery
ToolPeirates

Peirates can list AWS S3 buckets.

T1619
Cloud Storage Object Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.

T1620
Reflective Code Loading
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

T1620
Reflective Code Loading
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory.

T1620
Reflective Code Loading
GroupKimsuky

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.

T1620
Reflective Code Loading
GroupGamaredon Group

Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2.

T1620
Reflective Code Loading
GroupFIN7

FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`.

T1620
Reflective Code Loading
GroupLazarus Group

Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime.

T1620
Reflective Code Loading
MalwarePikabot

Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine.

T1620
Reflective Code Loading
MalwareSardonic

Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions.

T1620
Reflective Code Loading
MalwareEmotet

Emotet has reflectively loaded payloads into memory.

T1620
Reflective Code Loading
MalwareBADHATCH

BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`.

T1620
Reflective Code Loading
MalwareSystemBC

SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call.

T1620
Reflective Code Loading
MalwareWhisperGate

WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly.

T1620
Reflective Code Loading
MalwareLunarLoader

LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread.

T1620
Reflective Code Loading
MalwarePlugX

PlugX has loaded its payload into memory.

T1620
Reflective Code Loading
MalwareLumma Stealer

Lumma Stealer has used reflective loading techniques to load content into memory during execution.

T1620
Reflective Code Loading
MalwareCuba

Cuba loaded the payload into memory using PowerShell.

T1620
Reflective Code Loading
MalwareThiefQuest

ThiefQuest uses various API functions such as NSCreateObjectFileImageFromMemory to load and link in-memory payloads.

T1620
Reflective Code Loading
MalwareFoggyWeb

FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory.

T1620
Reflective Code Loading
MalwareMuddyViper

MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread.

T1620
Reflective Code Loading
MalwareFooder

Fooder has reflectively loaded a payload into memory.

T1620
Reflective Code Loading
MalwareUroburos

Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command.

T1620
Reflective Code Loading
MalwareCobalt Strike

Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process by loading the CLR.

T1620
Reflective Code Loading
MalwareLokibot

Lokibot has reflectively loaded the decoded DLL into memory.

T1620
Reflective Code Loading
MalwareIceApple

IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers.

T1620
Reflective Code Loading
MalwaremetaMain

metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file.

T1620
Reflective Code Loading
MalwareBRUSHFIRE

BRUSHFIRE has executed its commands within memory and is not saved on disk.

T1620
Reflective Code Loading
MalwareGelsemium

Gelsemium can use custom shellcode to map embedded DLLs into memory.

T1620
Reflective Code Loading
MalwareLizar

Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory.

T1620
Reflective Code Loading
ToolSILENTTRINITY

SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR.

T1620
Reflective Code Loading
ToolPowerSploit

PowerSploit reflectively loads a Windows PE file into a process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.