ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.003
Steganography
MalwarePolyglotDuke

PolyglotDuke can use steganography to hide C2 information in images.

T1027.003
Steganography
MalwareRegDuke

RegDuke can hide data in images, including use of the Least Significant Bit (LSB).

T1027.003
Steganography
MalwareProLock

ProLock can use .jpg and .bmp files to store its payload.

T1027.003
Steganography
MalwareRDAT

RDAT can also embed data within a BMP image prior to exfiltration.

T1027.003
Steganography
MalwareOkrum

Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file.

T1027.003
Steganography
MalwareDiavol

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

T1027.003
Steganography
MalwareRaindrop

Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code.

T1027.003
Steganography
MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.003
Steganography
MalwareObliqueRAT

ObliqueRAT can hide its payload in BMP images hosted on compromised websites.

T1027.003
Steganography
MalwareBandook

Bandook has used .PNG images within a zip file to build the executable.

T1027.003
Steganography
MalwareLiteDuke

LiteDuke has used image files to hide its loader component.

T1027.003
Steganography
MalwareABK

ABK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
MalwareRamsay

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1027.003
Steganography
Malwarebuild_downer

build_downer can extract malware from a downloaded JPEG.

T1027.003
Steganography
MalwareBBK

BBK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
ToolInvoke-PSImage

Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.

T1027.003
Steganography
GroupTeamPCP

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

T1027.004
Compile After Delivery
GroupMuddyWater

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

T1027.004
Compile After Delivery
GroupGamaredon Group

Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in Microsoft.CSharp.CSharpCodeProvider class.

T1027.004
Compile After Delivery
GroupRocke

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

T1027.004
Compile After Delivery
GroupSea Turtle

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

T1027.004
Compile After Delivery
MalwareDarkWatchman

DarkWatchman has used the csc.exe tool to compile a C# executable.

T1027.004
Compile After Delivery
MalwareFoggyWeb

FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST.

T1027.004
Compile After Delivery
MalwareSamurai

Samurai can compile and execute downloaded modules at runtime.

T1027.004
Compile After Delivery
MalwareCardinal RAT

Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.

T1027.004
Compile After Delivery
MalwarenjRAT

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

T1027.004
Compile After Delivery
ToolSliver

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

T1027.005
Indicator Removal from Tools
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates.

T1027.005
Indicator Removal from Tools
CampaignOperation Wocao

During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection.

T1027.005
Indicator Removal from Tools
GroupGALLIUM

GALLIUM ensured each payload had a unique hash, including by using different types of packers.

T1027.005
Indicator Removal from Tools
GroupAPT3

APT3 has been known to remove indicators of compromise from tools.

T1027.005
Indicator Removal from Tools
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.005
Indicator Removal from Tools
GroupUNC3886

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

T1027.005
Indicator Removal from Tools
GroupOilRig

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

T1027.005
Indicator Removal from Tools
GroupTurla

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

T1027.005
Indicator Removal from Tools
GroupDeep Panda

Deep Panda has updated and modified its malware, resulting in different hash values that evade detection.

T1027.005
Indicator Removal from Tools
MalwareGravityRAT

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

T1027.005
Indicator Removal from Tools
MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1027.005
Indicator Removal from Tools
MalwareSUNBURST

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

T1027.005
Indicator Removal from Tools
MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1027.005
Indicator Removal from Tools
MalwarePenquin

Penquin can remove strings from binaries.

T1027.005
Indicator Removal from Tools
MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

T1027.005
Indicator Removal from Tools
MalwareWaterbear

Waterbear can scramble functions not to be executed again with random values.

T1027.005
Indicator Removal from Tools
ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

T1027.006
HTML Smuggling
GroupAPT29

APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution.

T1027.006
HTML Smuggling
MalwareEnvyScout

EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk.

T1027.006
HTML Smuggling
MalwareQakBot

QakBot has been delivered in ZIP files via HTML smuggling.

T1027.007
Dynamic API Resolution
GroupKimsuky

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

T1027.007
Dynamic API Resolution
GroupMustang Panda

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.