ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0168×

18 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareGazer

Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources.

T1033
System Owner/User Discovery
MalwareGazer

Gazer obtains the current user's security identifier.

T1053.005
Scheduled Task
MalwareGazer

Gazer can establish persistence by creating a scheduled task.

T1055
Process Injection
MalwareGazer

Gazer injects its communication module into an Internet accessible process through which it performs C2.

T1055.003
Thread Execution Hijacking
MalwareGazer

Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.

T1070.004
File Deletion
MalwareGazer

Gazer has commands to delete files and persistence mechanisms from the victim.

T1070.006
Timestomp
MalwareGazer

For early Gazer versions, the compilation timestamp was faked.

T1071.001
Web Protocols
MalwareGazer

Gazer communicates with its C2 servers over HTTP.

T1105
Ingress Tool Transfer
MalwareGazer

Gazer can execute a task to download a file.

T1480.002
Mutual Exclusion
MalwareGazer

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1546.002
Screensaver
MalwareGazer

Gazer can establish persistence through the system screensaver by configuring it to execute the malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.004
Winlogon Helper DLL
MalwareGazer

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.009
Shortcut Modification
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe.

T1553.002
Code Signing
MalwareGazer

Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd."

T1564.004
NTFS File Attributes
MalwareGazer

Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible.

T1573.001
Symmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses 3DES.

T1573.002
Asymmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.