Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareEbury | Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days. |
| T1014 Rootkit |
MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| T1020 Automated Exfiltration |
MalwareEbury | If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| T1027 Obfuscated Files or Information |
MalwareEbury | Ebury has obfuscated its strings with a simple XOR encryption with a static key. |
| T1041 Exfiltration Over C2 Channel |
MalwareEbury | Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server. |
| T1059.004 Unix Shell |
MalwareEbury | Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level. |
| T1059.006 Python |
MalwareEbury | Ebury has used Python to implement its DGA. |
| T1071.004 DNS |
MalwareEbury | Ebury has used DNS requests over UDP port 53 for C2. |
| T1129 Shared Modules |
MalwareEbury | Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`. |
| T1132.001 Standard Encoding |
MalwareEbury | Ebury has encoded C2 traffic in hexadecimal format. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEbury | Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key. |
| T1552.004 Private Keys |
MalwareEbury | Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| T1553.002 Code Signing |
MalwareEbury | Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems. |
| T1554 Compromise Host Software Binary |
MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1556 Modify Authentication Process |
MalwareEbury | Ebury can intercept private keys using a trojanized |
| T1556.003 Pluggable Authentication Modules |
MalwareEbury | Ebury can deactivate PAM modules to tamper with the sshd configuration. |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1573.001 Symmetric Cryptography |
MalwareEbury | Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string. |
| T1574.006 Dynamic Linker Hijacking |
MalwareEbury | When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`. |
| T1685 Disable or Modify Tools |
MalwareEbury | Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules. |
| T1685.004 Disable or Modify Linux Audit System Log |
MalwareEbury | Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.