ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareGelsemium

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareOSX/Shlayer

OSX/Shlayer can masquerade as a Flash Player update.

T1036.005
Match Legitimate Resource Name or Location
MalwareDtrack

One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrifeWater

StrifeWater has been named `calc.exe` to appear as a legitimate calculator program.

T1036.005
Match Legitimate Resource Name or Location
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareXORIndex Loader

XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
MalwareSmall Sieve

Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWizard

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1036.005
Match Legitimate Resource Name or Location
ToolShimRatReporter

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1036.005
Match Legitimate Resource Name or Location
ToolPcShare

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1036.005
Match Legitimate Resource Name or Location
ToolBrute Ratel C4

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.

T1036.005
Match Legitimate Resource Name or Location
ToolMCMD

MCMD has been named Readme.txt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs.

T1036.005
Match Legitimate Resource Name or Location
MalwareCanisterWorm

CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.

T1036.006
Space after Filename
MalwareKeydnap

Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program.

T1036.007
Double File Extension
MalwareDarkGate

DarkGate masquerades malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1036.007
Double File Extension
MalwareBazar

The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe.

T1036.007
Double File Extension
MalwareMilan

Milan has used an executable named `companycatalog.exe.config` to appear benign.

T1036.008
Masquerade File Type
MalwareAvosLocker

AvosLocker has been disguised as a .jpg file.

T1036.008
Masquerade File Type
MalwareHeartCrypt

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

T1036.008
Masquerade File Type
MalwareSTATICPLUGIN

STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension.

T1036.008
Masquerade File Type
MalwareRaspberry Robin

Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder.

T1036.008
Masquerade File Type
MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1036.008
Masquerade File Type
MalwarePureCrypter

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1036.008
Masquerade File Type
MalwareMagicRAT

MagicRAT can download additional executable payloads that masquerade as GIF files.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1036.008
Masquerade File Type
MalwareKapeka

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

T1036.008
Masquerade File Type
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1036.008
Masquerade File Type
MalwareANDROMEDA

ANDROMEDA has been delivered through a LNK file disguised as a folder.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1036.008
Masquerade File Type
ToolBrute Ratel C4

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

T1036.009
Break Process Trees
MalwareBPFDoor

After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init.

T1036.009
Break Process Trees
MalwareShai-Hulud

Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.

T1036.010
Masquerade Account Name
MalwareServHelper

ServHelper has created a new user named `supportaccount`.

T1036.010
Masquerade Account Name
MalwareFlame

Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available.

T1036.011
Overwrite Process Arguments
MalwareBPFDoor

BPFDoor overwrites the `argv[0]` value used by the Linux `/proc` filesystem to determine the command line and command name to display for each process. BPFDoor selects a name from 10 hardcoded names that resemble Linux system daemons, such as; `/sbin/udevd -d`, `dbus-daemon --system`, `avahi-daemon: chroot helper`, `/sbin/auditd -n`, and `/usr/lib/systemd/systemd-journald`.

T1036.012
Browser Fingerprint
MalwareFatDuke

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

T1037
Boot or Logon Initialization Scripts
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder.

T1037
Boot or Logon Initialization Scripts
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

T1037
Boot or Logon Initialization Scripts
MalwareVIRTUALPITA

VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems.

T1037.001
Logon Script (Windows)
MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1037.001
Logon Script (Windows)
MalwareKGH_SPY

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

T1037.001
Logon Script (Windows)
MalwareAttor

Attor's dispatcher can establish persistence via adding a Registry key with a logon script HKEY_CURRENT_USER\Environment "UserInitMprLogonScript" .

T1037.001
Logon Script (Windows)
MalwareZebrocy

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

T1037.004
RC Scripts
MalwareiKitten

iKitten adds an entry to the rc.common file for persistence.

T1037.004
RC Scripts
MalwareGreen Lambert

Green Lambert can add init.d and rc.d files in the /etc folder to establish persistence.

T1037.004
RC Scripts
MalwareCyclops Blink

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.

T1037.004
RC Scripts
MalwareHiddenWasp

HiddenWasp installs reboot persistence by adding itself to /etc/rc.local.

T1037.005
Startup Items
MalwarejRAT

jRAT can list and manage startup entries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.