ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0265×

31 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareKazuar

Kazuar uploads files from a specified directory to the C2 server.

T1008
Fallback Channels
MalwareKazuar

Kazuar can accept multiple URLs for C2 servers.

T1010
Application Window Discovery
MalwareKazuar

Kazuar gathers information about opened windows.

T1016
System Network Configuration Discovery
MalwareKazuar

Kazuar gathers information about network adapters.

T1027
Obfuscated Files or Information
MalwareKazuar

Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher.

T1029
Scheduled Transfer
MalwareKazuar

Kazuar can sleep for a specific time and be set to communicate at specific intervals.

T1033
System Owner/User Discovery
MalwareKazuar

Kazuar gathers information on users.

T1047
Windows Management Instrumentation
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying.

T1055.001
Dynamic-link Library Injection
MalwareKazuar

If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes.

T1057
Process Discovery
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying and the ps command.

T1059.003
Windows Command Shell
MalwareKazuar

Kazuar uses cmd.exe to execute commands on the victim’s machine.

T1059.004
Unix Shell
MalwareKazuar

Kazuar uses /bin/bash to execute commands on the victim’s machine.

T1069.001
Local Groups
MalwareKazuar

Kazuar gathers information about local groups and members.

T1070.004
File Deletion
MalwareKazuar

Kazuar can delete files.

T1071.001
Web Protocols
MalwareKazuar

Kazuar uses HTTP and HTTPS to communicate with the C2 server. Kazuar can also act as a webserver and listen for inbound HTTP requests through an exposed API.

T1071.002
File Transfer Protocols
MalwareKazuar

Kazuar uses FTP and FTPS to communicate with the C2 server.

T1074.001
Local Data Staging
MalwareKazuar

Kazuar stages command output and collected data in files before exfiltration.

T1082
System Information Discovery
MalwareKazuar

Kazuar gathers information on the system.

T1083
File and Directory Discovery
MalwareKazuar

Kazuar finds a specified directory, lists the files and metadata about those files.

T1087.001
Local Account
MalwareKazuar

Kazuar gathers information on local groups and members on the victim’s machine.

T1090.001
Internal Proxy
MalwareKazuar

Kazuar has used internal nodes on the compromised network for C2 communications.

T1102.002
Bidirectional Communication
MalwareKazuar

Kazuar has used compromised WordPress blogs as C2 servers.

T1105
Ingress Tool Transfer
MalwareKazuar

Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.

T1113
Screen Capture
MalwareKazuar

Kazuar captures screenshots of the victim’s screen.

T1125
Video Capture
MalwareKazuar

Kazuar captures images from the webcam.

T1132.001
Standard Encoding
MalwareKazuar

Kazuar encodes communications to the C2 server in Base64.

T1485
Data Destruction
MalwareKazuar

Kazuar can overwrite files with random data before deleting them.

T1543.003
Windows Service
MalwareKazuar

Kazuar can install itself as a new service.

T1547.001
Registry Run Keys / Startup Folder
MalwareKazuar

Kazuar adds a sub-key under several Registry run keys.

T1547.009
Shortcut Modification
MalwareKazuar

Kazuar adds a .lnk file to the Windows startup folder.

T1680
Local Storage Discovery
MalwareKazuar

Kazuar gathers information on local drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.