ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1543.003
Windows Service
GroupTeamTNT

TeamTNT has used malware that adds cryptocurrency miners as a service.

T1543.003
Windows Service
GroupFIN7

FIN7 created new Windows services and added them to the startup directories for persistence.

T1543.003
Windows Service
GroupOilRig

OilRig has used a compromised Domain Controller to create a service on a remote host.

T1543.003
Windows Service
GroupCarbanak

Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges.

T1543.003
Windows Service
GroupTropic Trooper

Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk.

T1543.003
Windows Service
GroupAquatic Panda

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

T1543.003
Windows Service
GroupKe3chang

Ke3chang backdoor RoyalDNS established persistence through adding a service called Nwsapagent.

T1543.003
Windows Service
GroupBlue Mockingbird

Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.

T1543.003
Windows Service
GroupDarkVishnya

DarkVishnya created new services for shellcode loaders distribution.

T1543.003
Windows Service
GroupLotus Blossom

Lotus Blossom has configured tools such as Sagerunex to run as Windows services.

T1543.003
Windows Service
GroupCinnamon Tempest

Cinnamon Tempest has created system services to establish persistence for deployed tooling.

T1543.003
Windows Service
GroupMedusa Group

Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.

T1543.003
Windows Service
GroupAgrius

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.

T1543.003
Windows Service
GroupLazarus Group

Several Lazarus Group malware families install themselves as new services.

T1543.003
Windows Service
GroupEarth Lusca

Earth Lusca created a service using the command sc create “SysUpdate” binpath= “cmd /c start “[file path]””&&sc config “SysUpdate” start= auto&&net
start SysUpdate
for persistence.

T1543.003
Windows Service
GroupCobalt Group

Cobalt Group has created new services to establish persistence.

T1543.003
Windows Service
GroupWizard Spider

Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.

T1543.003
Windows Service
GroupPROMETHIUM

PROMETHIUM has created new services and modified existing services for persistence.

T1543.003
Windows Service
GroupThreat Group-3390

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.

T1543.003
Windows Service
GroupAPT19

An APT19 Port 22 malware variant registers itself as a service.

T1546.001
Change Default File Association
GroupKimsuky

Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMustang Panda

Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupLeviathan

Leviathan has used WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupBlue Mockingbird

Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file.

T1546.003
Windows Management Instrumentation Event Subscription
GroupTurla

Turla has used WMI event filters and consumers to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT29

APT29 has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMetador

Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`.

T1546.003
Windows Management Instrumentation Event Subscription
GroupHEXANE

HEXANE has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupRancor

Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT33

APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts.

T1546.003
Windows Management Instrumentation Event Subscription
GroupFIN8

FIN8 has used WMI event subscriptions for persistence.

T1546.004
Unix Shell Configuration Modification
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`.

T1546.008
Accessibility Features
GroupAPT3

APT3 replaces the Sticky Keys binary C:\Windows\System32\sethc.exe for persistence.

T1546.008
Accessibility Features
GroupAPT41

APT41 leveraged sticky keys to establish persistence.

T1546.008
Accessibility Features
GroupAPT29

APT29 used sticky-keys to obtain unauthenticated, privileged console access.

T1546.008
Accessibility Features
GroupAxiom

Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence.

T1546.008
Accessibility Features
GroupDeep Panda

Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions.

T1546.008
Accessibility Features
GroupFox Kitten

Fox Kitten has used sticky keys to launch a command prompt.

T1546.010
AppInit DLLs
GroupAPT39

APT39 has used malware to set LoadAppInit_DLLs in the Registry key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows in order to establish persistence.

T1546.011
Application Shimming
GroupFIN7

FIN7 has used application shim databases for persistence.

T1546.013
PowerShell Profile
GroupTurla

Turla has used PowerShell profiles to maintain persistence on an infected machine.

T1546.015
Component Object Model Hijacking
GroupAPT28

APT28 has used COM hijacking for persistence by replacing the legitimate MMDeviceEnumerator object with a payload.

T1546.016
Installer Packages
GroupTeamPCP

TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.

T1547
Boot or Logon Autostart Execution
GroupAPT42

APT42 has modified the Registry to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupBlackByte

BlackByte has used Registry Run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT3

APT3 places scripts in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupDragonfly

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.