ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0457×

18 examples

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwareNetwalker

Netwalker's DLL has been embedded within the PowerShell script in hex format.

T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1047
Windows Management Instrumentation
MalwareNetwalker

Netwalker can use WMI to delete Shadow Volumes.

T1055.001
Dynamic-link Library Injection
MalwareNetwalker

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1059.001
PowerShell
MalwareNetwalker

Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.

T1059.003
Windows Command Shell
MalwareNetwalker

Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload.

T1082
System Information Discovery
MalwareNetwalker

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.

T1105
Ingress Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1106
Native API
MalwareNetwalker

Netwalker can use Windows API functions to inject the ransomware DLL.

T1112
Modify Registry
MalwareNetwalker

Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.

T1140
Deobfuscate/Decode Files or Information
MalwareNetwalker

Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.

T1486
Data Encrypted for Impact
MalwareNetwalker

Netwalker can encrypt files on infected machines to extort victims.

T1489
Service Stop
MalwareNetwalker

Netwalker can terminate system processes and services, some of which relate to backup software.

T1490
Inhibit System Recovery
MalwareNetwalker

Netwalker can delete the infected system's Shadow Volumes to prevent recovery.

T1518.001
Security Software Discovery
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

T1569.002
Service Execution
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1570
Lateral Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.

T1685
Disable or Modify Tools
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.