ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1036.008
Masquerade File Type
GroupBlackByte

BlackByte masqueraded configuration files containing encryption keys as PNG files.

T1036.008
Masquerade File Type
GroupVolt Typhoon

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

T1036.008
Masquerade File Type
GroupMustang Panda

Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware.

T1036.008
Masquerade File Type
GroupMirrorFace

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

T1036.008
Masquerade File Type
MalwareAvosLocker

AvosLocker has been disguised as a .jpg file.

T1036.008
Masquerade File Type
MalwareHeartCrypt

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

T1036.008
Masquerade File Type
MalwareSTATICPLUGIN

STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension.

T1036.008
Masquerade File Type
MalwareRaspberry Robin

Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder.

T1036.008
Masquerade File Type
MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1036.008
Masquerade File Type
MalwarePureCrypter

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1036.008
Masquerade File Type
MalwareMagicRAT

MagicRAT can download additional executable payloads that masquerade as GIF files.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1036.008
Masquerade File Type
MalwareKapeka

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

T1036.008
Masquerade File Type
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1036.008
Masquerade File Type
MalwareANDROMEDA

ANDROMEDA has been delivered through a LNK file disguised as a folder.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1036.008
Masquerade File Type
ToolBrute Ratel C4

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

T1036.009
Break Process Trees
MalwareBPFDoor

After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init.

T1036.009
Break Process Trees
MalwareShai-Hulud

Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.

T1036.010
Masquerade Account Name
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System).

T1036.010
Masquerade Account Name
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1036.010
Masquerade Account Name
GroupDragonfly

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

T1036.010
Masquerade Account Name
GroupStorm-1811

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

T1036.010
Masquerade Account Name
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1036.010
Masquerade Account Name
MalwareServHelper

ServHelper has created a new user named `supportaccount`.

T1036.010
Masquerade Account Name
MalwareFlame

Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available.

T1036.011
Overwrite Process Arguments
MalwareBPFDoor

BPFDoor overwrites the `argv[0]` value used by the Linux `/proc` filesystem to determine the command line and command name to display for each process. BPFDoor selects a name from 10 hardcoded names that resemble Linux system daemons, such as; `/sbin/udevd -d`, `dbus-daemon --system`, `avahi-daemon: chroot helper`, `/sbin/auditd -n`, and `/usr/lib/systemd/systemd-journald`.

T1036.012
Browser Fingerprint
MalwareFatDuke

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

T1037
Boot or Logon Initialization Scripts
CampaignArcaneDoor

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

T1037
Boot or Logon Initialization Scripts
GroupAPT41

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.

T1037
Boot or Logon Initialization Scripts
GroupRocke

Rocke has installed an "init.d" startup script to maintain persistence.

T1037
Boot or Logon Initialization Scripts
GroupUNC3886

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

T1037
Boot or Logon Initialization Scripts
GroupAPT29

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

T1037
Boot or Logon Initialization Scripts
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder.

T1037
Boot or Logon Initialization Scripts
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

T1037
Boot or Logon Initialization Scripts
MalwareVIRTUALPITA

VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems.

T1037.001
Logon Script (Windows)
GroupAPT28

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1037.001
Logon Script (Windows)
GroupCobalt Group

Cobalt Group has added persistence by registering the file name for the next stage malware under HKCU\Environment\UserInitMprLogonScript.

T1037.001
Logon Script (Windows)
MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1037.001
Logon Script (Windows)
MalwareKGH_SPY

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

T1037.001
Logon Script (Windows)
MalwareAttor

Attor's dispatcher can establish persistence via adding a Registry key with a logon script HKEY_CURRENT_USER\Environment "UserInitMprLogonScript" .

T1037.001
Logon Script (Windows)
MalwareZebrocy

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

T1037.004
RC Scripts
GroupUNC3886

UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence.

T1037.004
RC Scripts
GroupAPT29

APT29 has installed a run command on a compromised system to enable malware execution on system startup.

T1037.004
RC Scripts
GroupVelvet Ant

Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence.

T1037.004
RC Scripts
MalwareiKitten

iKitten adds an entry to the rc.common file for persistence.

T1037.004
RC Scripts
MalwareGreen Lambert

Green Lambert can add init.d and rc.d files in the /etc folder to establish persistence.

T1037.004
RC Scripts
MalwareCyclops Blink

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.

T1037.004
RC Scripts
MalwareHiddenWasp

HiddenWasp installs reboot persistence by adding itself to /etc/rc.local.

T1037.005
Startup Items
MalwarejRAT

jRAT can list and manage startup entries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.