ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1490
Inhibit System Recovery
GroupScattered Spider

Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.

T1490
Inhibit System Recovery
GroupStorm-0501

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`,
`Microsoft.Compute/restorePointCollections/delete`,
`Microsoft.Storage/storageAccounts/delete`, and
`Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.

T1490
Inhibit System Recovery
GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
GroupWizard Spider

Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.

T1490
Inhibit System Recovery
GroupVOID MANTICORE

VOID MANTICORE has deleted virtual machines directly from the virtualization platform.

T1491.001
Internal Defacement
GroupBlackByte

BlackByte left ransom notes in all directories where encryption takes place.

T1491.001
Internal Defacement
GroupGamaredon Group

Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access.

T1491.001
Internal Defacement
GroupLazarus Group

Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe.

T1491.001
Internal Defacement
GroupShinyHunters

ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

T1491.002
External Defacement
GroupSandworm Team

Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019.

T1491.002
External Defacement
GroupEmber Bear

Ember Bear is linked to the defacement of several Ukrainian organization websites.

T1496.001
Compute Hijacking
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

T1496.001
Compute Hijacking
GroupTeamTNT

TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency.

T1496.001
Compute Hijacking
GroupRocke

Rocke has distributed cryptomining malware.

T1496.001
Compute Hijacking
GroupBlue Mockingbird

Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.

T1497
Virtualization/Sandbox Evasion
GroupContagious Interview

Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection.

T1497
Virtualization/Sandbox Evasion
GroupSaint Bear

Saint Bear contains several anti-analysis and anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
GroupDarkhotel

Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection.

T1497.001
System Checks
GroupKimsuky

Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`.

T1497.001
System Checks
GroupVolt Typhoon

Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.

T1497.001
System Checks
GroupEvilnum

Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments.

T1497.001
System Checks
GroupGamaredon Group

Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document.

T1497.001
System Checks
GroupOilRig

OilRig has used macros to verify if a mouse is connected to a compromised machine.

T1497.001
System Checks
GroupDarkhotel

Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with .Md5.exe, and if the program is executed from the root of the C:\ drive, as well as checks for sandbox-related libraries.

T1497.001
System Checks
GroupWIRTE

WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments.

T1497.002
User Activity Based Checks
GroupFIN7

FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes.

T1497.002
User Activity Based Checks
GroupDarkhotel

Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system.

T1498
Network Denial of Service
GroupAPT28

In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency.

T1499
Endpoint Denial of Service
GroupSandworm Team

Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019.

T1505.003
Web Shell
GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1505.003
Web Shell
GroupGALLIUM

GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration.

T1505.003
Web Shell
GroupKimsuky

Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code.

T1505.003
Web Shell
GroupVolt Typhoon

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.

T1505.003
Web Shell
GroupDragonfly

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.

T1505.003
Web Shell
GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1505.003
Web Shell
GroupSandworm Team

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.

T1505.003
Web Shell
GroupCURIUM

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

T1505.003
Web Shell
GroupMustang Panda

Mustang Panda has used China Chopper web shells to maintain access to victims’ environments.

T1505.003
Web Shell
GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

T1505.003
Web Shell
GroupMoses Staff

Moses Staff has dropped a web shell onto a compromised system.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1505.003
Web Shell
GroupTropic Trooper

Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1505.003
Web Shell
GroupMedusa Group

Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.

T1505.003
Web Shell
GroupBackdoorDiplomacy

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

T1505.003
Web Shell
GroupDeep Panda

Deep Panda uses Web shells on publicly accessible Web servers to access victim networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.