ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0451×

18 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLoudMiner

LoudMiner used a script to gather the IP address of the infected machine before sending to the C2.

T1027.010
Command Obfuscation
MalwareLoudMiner

LoudMiner has obfuscated various scripts.

T1027.013
Encrypted/Encoded File
MalwareLoudMiner

LoudMiner has encrypted DMG files.

T1057
Process Discovery
MalwareLoudMiner

LoudMiner used the ps command to monitor the running processes on the system.

T1059.003
Windows Command Shell
MalwareLoudMiner

LoudMiner used a batch script to run the Linux virtual machine as a service.

T1059.004
Unix Shell
MalwareLoudMiner

LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization.

T1070.004
File Deletion
MalwareLoudMiner

LoudMiner deleted installation files after completion.

T1082
System Information Discovery
MalwareLoudMiner

LoudMiner has monitored CPU usage.

T1105
Ingress Tool Transfer
MalwareLoudMiner

LoudMiner used SCP to update the miner from the C2.

T1189
Drive-by Compromise
MalwareLoudMiner

LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

T1218.007
Msiexec
MalwareLoudMiner

LoudMiner used an MSI installer to install the virtualization software.

T1496.001
Compute Hijacking
MalwareLoudMiner

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

T1543.003
Windows Service
MalwareLoudMiner

LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file.

T1543.004
Launch Daemon
MalwareLoudMiner

LoudMiner adds plist files with the naming format com.[random_name].plist in the /Library/LaunchDaemons folder with the RunAtLoad and KeepAlive keys set to true.

T1564.001
Hidden Files and Directories
MalwareLoudMiner

LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden".

T1564.006
Run Virtual Instance
MalwareLoudMiner

LoudMiner has used QEMU and VirtualBox to run a Tiny Core Linux virtual machine, which runs XMRig and makes connections to the C2 server for updates.

T1569.001
Launchctl
MalwareLoudMiner

LoudMiner launched the QEMU services in the /Library/LaunchDaemons/ folder using launchctl. It also uses launchctl to unload all Launch Daemons when updating to a newer version of LoudMiner.

T1569.002
Service Execution
MalwareLoudMiner

LoudMiner started the cryptomining virtual machine as a service on the infected machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.