ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0377×

21 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareEbury

Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days.

T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1020
Automated Exfiltration
MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1027
Obfuscated Files or Information
MalwareEbury

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1041
Exfiltration Over C2 Channel
MalwareEbury

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1059.004
Unix Shell
MalwareEbury

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1059.006
Python
MalwareEbury

Ebury has used Python to implement its DGA.

T1071.004
DNS
MalwareEbury

Ebury has used DNS requests over UDP port 53 for C2.

T1129
Shared Modules
MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1132.001
Standard Encoding
MalwareEbury

Ebury has encoded C2 traffic in hexadecimal format.

T1140
Deobfuscate/Decode Files or Information
MalwareEbury

Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key.

T1552.004
Private Keys
MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1553.002
Code Signing
MalwareEbury

Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems.

T1554
Compromise Host Software Binary
MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1556
Modify Authentication Process
MalwareEbury

Ebury can intercept private keys using a trojanized ssh-add function.

T1556.003
Pluggable Authentication Modules
MalwareEbury

Ebury can deactivate PAM modules to tamper with the sshd configuration.

T1568.002
Domain Generation Algorithms
MalwareEbury

Ebury has used a DGA to generate a domain name for C2.

T1573.001
Symmetric Cryptography
MalwareEbury

Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string.

T1574.006
Dynamic Linker Hijacking
MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

T1685
Disable or Modify Tools
MalwareEbury

Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules.

T1685.004
Disable or Modify Linux Audit System Log
MalwareEbury

Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.