Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1490 Inhibit System Recovery |
GroupScattered Spider | Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts. |
| T1490 Inhibit System Recovery |
GroupStorm-0501 | Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
GroupWizard Spider | Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin. |
| T1490 Inhibit System Recovery |
GroupVOID MANTICORE | VOID MANTICORE has deleted virtual machines directly from the virtualization platform. |
| T1491.001 Internal Defacement |
GroupBlackByte | BlackByte left ransom notes in all directories where encryption takes place. |
| T1491.001 Internal Defacement |
GroupGamaredon Group | Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access. |
| T1491.001 Internal Defacement |
GroupLazarus Group | Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe. |
| T1491.001 Internal Defacement |
GroupShinyHunters | ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. |
| T1491.002 External Defacement |
GroupSandworm Team | Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019. |
| T1491.002 External Defacement |
GroupEmber Bear | Ember Bear is linked to the defacement of several Ukrainian organization websites. |
| T1496.001 Compute Hijacking |
GroupAPT41 | APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment. |
| T1496.001 Compute Hijacking |
GroupTeamTNT | TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency. |
| T1496.001 Compute Hijacking |
GroupRocke | Rocke has distributed cryptomining malware. |
| T1496.001 Compute Hijacking |
GroupBlue Mockingbird | Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems. |
| T1497 Virtualization/Sandbox Evasion |
GroupContagious Interview | Contagious Interview has requested victims to disable Docker and other container environments in attempts to thwart container isolation and ensure device infection. |
| T1497 Virtualization/Sandbox Evasion |
GroupSaint Bear | Saint Bear contains several anti-analysis and anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
GroupDarkhotel | Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection. |
| T1497.001 System Checks |
GroupKimsuky | Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`. |
| T1497.001 System Checks |
GroupVolt Typhoon | Volt Typhoon has run system checks to determine if they were operating in a virtualized environment. |
| T1497.001 System Checks |
GroupEvilnum | Evilnum has used a component called TerraLoader to check certain hardware and file information to detect sandboxed environments. |
| T1497.001 System Checks |
GroupGamaredon Group | Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document. |
| T1497.001 System Checks |
GroupOilRig | OilRig has used macros to verify if a mouse is connected to a compromised machine. |
| T1497.001 System Checks |
GroupDarkhotel | Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with |
| T1497.001 System Checks |
GroupWIRTE | WIRTE has configured C2 servers to check location and user-agent strings for victim endpoints to prevent sending a payload to sandboxed environments. |
| T1497.002 User Activity Based Checks |
GroupFIN7 | FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes. |
| T1497.002 User Activity Based Checks |
GroupDarkhotel | Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system. |
| T1498 Network Denial of Service |
GroupAPT28 | In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency. |
| T1499 Endpoint Denial of Service |
GroupSandworm Team | Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019. |
| T1505.003 Web Shell |
GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1505.003 Web Shell |
GroupGALLIUM | GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration. |
| T1505.003 Web Shell |
GroupKimsuky | Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code. |
| T1505.003 Web Shell |
GroupVolt Typhoon | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments. |
| T1505.003 Web Shell |
GroupDragonfly | Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files. |
| T1505.003 Web Shell |
GroupAPT32 | APT32 has used Web shells to maintain access to victim websites. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1505.003 Web Shell |
GroupSandworm Team | Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks. |
| T1505.003 Web Shell |
GroupCURIUM | CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks. |
| T1505.003 Web Shell |
GroupMustang Panda | Mustang Panda has used China Chopper web shells to maintain access to victims’ environments. |
| T1505.003 Web Shell |
GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| T1505.003 Web Shell |
GroupMoses Staff | Moses Staff has dropped a web shell onto a compromised system. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1505.003 Web Shell |
GroupTropic Trooper | Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1505.003 Web Shell |
GroupMedusa Group | Medusa Group has utilized webshells to an exploited Microsoft Exchange Server. |
| T1505.003 Web Shell |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system. |
| T1505.003 Web Shell |
GroupDeep Panda | Deep Panda uses Web shells on publicly accessible Web servers to access victim networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.