ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0256×

17 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMosquito

Mosquito uses the ipconfig command.

T1027.011
Fileless Storage
MalwareMosquito

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

T1027.013
Encrypted/Encoded File
MalwareMosquito

Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer.

T1033
System Owner/User Discovery
MalwareMosquito

Mosquito runs whoami on the victim’s machine.

T1047
Windows Management Instrumentation
MalwareMosquito

Mosquito's installer uses WMI to search for antivirus display names.

T1057
Process Discovery
MalwareMosquito

Mosquito runs tasklist to obtain running processes.

T1059.001
PowerShell
MalwareMosquito

Mosquito can launch PowerShell Scripts.

T1059.003
Windows Command Shell
MalwareMosquito

Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server.

T1070.004
File Deletion
MalwareMosquito

Mosquito deletes files using DeleteFileW API call.

T1105
Ingress Tool Transfer
MalwareMosquito

Mosquito can upload and download files to the victim.

T1106
Native API
MalwareMosquito

Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions.

T1112
Modify Registry
MalwareMosquito

Mosquito can modify Registry keys under HKCU\Software\Microsoft\[dllname] to store configuration values. Mosquito also modifies Registry keys under HKCR\CLSID\...\InprocServer32 with a path to the launcher.

T1218.011
Rundll32
MalwareMosquito

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1518.001
Security Software Discovery
MalwareMosquito

Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system.

T1546.015
Component Object Model Hijacking
MalwareMosquito

Mosquito uses COM hijacking as a method of persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareMosquito

Mosquito establishes persistence under the Registry key HKCU\Software\Run auto_update.

T1573.001
Symmetric Cryptography
MalwareMosquito

Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.