ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.016
Junk Code Insertion
MalwareStrelaStealer

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1027.016
Junk Code Insertion
MalwareFinFisher

FinFisher contains junk code in its functions in an effort to confuse disassembly programs.

T1027.016
Junk Code Insertion
MalwareANELLDR

ANELLDR can use junk code for payload obfuscation.

T1027.016
Junk Code Insertion
MalwareMaze

Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process.

T1027.016
Junk Code Insertion
MalwarePOWERSTATS

POWERSTATS has used useless code blocks to counter analysis.

T1027.016
Junk Code Insertion
MalwareGoopy

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1027.016
Junk Code Insertion
MalwareGelsemium

Gelsemium can use junk code to hide functions and evade detection.

T1027.018
Invisible Unicode
MalwareGlassWorm

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1029
Scheduled Transfer
GroupHigaisa

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.

T1029
Scheduled Transfer
MalwareNinja

Ninja can configure its agent to work only in specific time frames.

T1029
Scheduled Transfer
MalwareTinyTurla

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.

T1029
Scheduled Transfer
MalwareMachete

Machete sends stolen data to the C2 server every 10 minutes.

T1029
Scheduled Transfer
MalwareKazuar

Kazuar can sleep for a specific time and be set to communicate at specific intervals.

T1029
Scheduled Transfer
MalwareShimRat

ShimRat can sleep when instructed to do so by the C2.

T1029
Scheduled Transfer
MalwareChrommme

Chrommme can set itself to sleep before requesting a new command from C2.

T1029
Scheduled Transfer
MalwareFlagpro

Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2.

T1029
Scheduled Transfer
MalwareLightNeuron

LightNeuron can be configured to exfiltrate data during nighttime or working hours.

T1029
Scheduled Transfer
MalwareShark

Shark can pause C2 communications for a specified time.

T1029
Scheduled Transfer
MalwareCobalt Strike

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.

T1029
Scheduled Transfer
MalwareComRAT

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1029
Scheduled Transfer
MalwareDipsind

Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic.

T1029
Scheduled Transfer
MalwarePOWERSTATS

POWERSTATS can sleep for a given number of seconds.

T1029
Scheduled Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure.

T1029
Scheduled Transfer
MalwareShadowPad

ShadowPad has sent data back to C2 every 8 hours.

T1029
Scheduled Transfer
MalwarejRAT

jRAT can be configured to reconnect at certain intervals.

T1029
Scheduled Transfer
MalwareADVSTORESHELL

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

T1030
Data Transfer Size Limits
CampaignC0015

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

T1030
Data Transfer Size Limits
CampaignC0026

During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.

T1030
Data Transfer Size Limits
GroupAPT41

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

T1030
Data Transfer Size Limits
GroupLuminousMoth

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

T1030
Data Transfer Size Limits
GroupAPT28

APT28 has split archived exfiltration files into chunks smaller than 1MB.

T1030
Data Transfer Size Limits
GroupPlay

Play has split victims' files into chunks for exfiltration.

T1030
Data Transfer Size Limits
GroupThreat Group-3390

Threat Group-3390 actors have split RAR files for exfiltration into parts.

T1030
Data Transfer Size Limits
MalwareAppleSeed

AppleSeed has divided files if the size is 0x1000000 bytes or more.

T1030
Data Transfer Size Limits
MalwareRDAT

RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions.

T1030
Data Transfer Size Limits
MalwareObliqueRAT

ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration.

T1030
Data Transfer Size Limits
MalwarePOSHSPY

POSHSPY uploads data in 2048-byte chunks.

T1030
Data Transfer Size Limits
MalwareCarbanak

Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes .

T1030
Data Transfer Size Limits
MalwareOopsIE

OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.

T1030
Data Transfer Size Limits
MalwareCobalt Strike

Cobalt Strike will break large data sets into smaller chunks for exfiltration.

T1030
Data Transfer Size Limits
MalwareKessel

Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries.

T1030
Data Transfer Size Limits
MalwareStealBit

StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms.

T1030
Data Transfer Size Limits
MalwareLunarWeb

LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB.

T1030
Data Transfer Size Limits
MalwareKevin

Kevin can exfiltrate data to the C2 server in 27-character chunks.

T1030
Data Transfer Size Limits
MalwareHelminth

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

T1030
Data Transfer Size Limits
ToolRclone

The Rclone "chunker" overlay supports splitting large files in smaller chunks during upload to circumvent size limits.

T1030
Data Transfer Size Limits
ToolMythic

Mythic supports custom chunk sizes used to upload/download files.

T1033
System Owner/User Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels.

T1033
System Owner/User Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.

T1033
System Owner/User Discovery
CampaignC0018

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.