Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.008 Masquerade File Type |
GroupBlackByte | BlackByte masqueraded configuration files containing encryption keys as PNG files. |
| T1036.008 Masquerade File Type |
GroupVolt Typhoon | Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension. |
| T1036.008 Masquerade File Type |
GroupMustang Panda | Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware. |
| T1036.008 Masquerade File Type |
GroupMirrorFace | MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files. |
| T1036.008 Masquerade File Type |
MalwareAvosLocker | AvosLocker has been disguised as a .jpg file. |
| T1036.008 Masquerade File Type |
MalwareHeartCrypt | HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files. |
| T1036.008 Masquerade File Type |
MalwareSTATICPLUGIN | STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension. |
| T1036.008 Masquerade File Type |
MalwareRaspberry Robin | Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder. |
| T1036.008 Masquerade File Type |
MalwareLumma Stealer | Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content. |
| T1036.008 Masquerade File Type |
MalwarePureCrypter | PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files. |
| T1036.008 Masquerade File Type |
MalwareMagicRAT | MagicRAT can download additional executable payloads that masquerade as GIF files. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1036.008 Masquerade File Type |
MalwareKapeka | Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file. |
| T1036.008 Masquerade File Type |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1036.008 Masquerade File Type |
MalwareANDROMEDA | ANDROMEDA has been delivered through a LNK file disguised as a folder. |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1036.008 Masquerade File Type |
ToolBrute Ratel C4 | Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files. |
| T1036.009 Break Process Trees |
MalwareBPFDoor | After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init. |
| T1036.009 Break Process Trees |
MalwareShai-Hulud | Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally. |
| T1036.010 Masquerade Account Name |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). |
| T1036.010 Masquerade Account Name |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1036.010 Masquerade Account Name |
GroupDragonfly | Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account. |
| T1036.010 Masquerade Account Name |
GroupStorm-1811 | Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing. |
| T1036.010 Masquerade Account Name |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1036.010 Masquerade Account Name |
MalwareServHelper | ServHelper has created a new user named `supportaccount`. |
| T1036.010 Masquerade Account Name |
MalwareFlame | Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available. |
| T1036.011 Overwrite Process Arguments |
MalwareBPFDoor | BPFDoor overwrites the `argv[0]` value used by the Linux `/proc` filesystem to determine the command line and command name to display for each process. BPFDoor selects a name from 10 hardcoded names that resemble Linux system daemons, such as; `/sbin/udevd -d`, `dbus-daemon --system`, `avahi-daemon: chroot helper`, `/sbin/auditd -n`, and `/usr/lib/systemd/systemd-journald`. |
| T1036.012 Browser Fingerprint |
MalwareFatDuke | FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser. |
| T1037 Boot or Logon Initialization Scripts |
CampaignArcaneDoor | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT41 | APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit. |
| T1037 Boot or Logon Initialization Scripts |
GroupRocke | Rocke has installed an "init.d" startup script to maintain persistence. |
| T1037 Boot or Logon Initialization Scripts |
GroupUNC3886 | UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT29 | APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| T1037 Boot or Logon Initialization Scripts |
MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder. |
| T1037 Boot or Logon Initialization Scripts |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| T1037 Boot or Logon Initialization Scripts |
MalwareVIRTUALPITA | VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems. |
| T1037.001 Logon Script (Windows) |
GroupAPT28 | An APT28 loader Trojan adds the Registry key |
| T1037.001 Logon Script (Windows) |
GroupCobalt Group | Cobalt Group has added persistence by registering the file name for the next stage malware under |
| T1037.001 Logon Script (Windows) |
MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| T1037.001 Logon Script (Windows) |
MalwareKGH_SPY | KGH_SPY has the ability to set the |
| T1037.001 Logon Script (Windows) |
MalwareAttor | Attor's dispatcher can establish persistence via adding a Registry key with a logon script |
| T1037.001 Logon Script (Windows) |
MalwareZebrocy | Zebrocy performs persistence with a logon script via adding to the Registry key |
| T1037.004 RC Scripts |
GroupUNC3886 | UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence. |
| T1037.004 RC Scripts |
GroupAPT29 | APT29 has installed a run command on a compromised system to enable malware execution on system startup. |
| T1037.004 RC Scripts |
GroupVelvet Ant | Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence. |
| T1037.004 RC Scripts |
MalwareiKitten | iKitten adds an entry to the rc.common file for persistence. |
| T1037.004 RC Scripts |
MalwareGreen Lambert | Green Lambert can add |
| T1037.004 RC Scripts |
MalwareCyclops Blink | Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled. |
| T1037.004 RC Scripts |
MalwareHiddenWasp | HiddenWasp installs reboot persistence by adding itself to |
| T1037.005 Startup Items |
MalwarejRAT | jRAT can list and manage startup entries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.