Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwareNetwalker | Netwalker's DLL has been embedded within the PowerShell script in hex format. |
| T1027.010 Command Obfuscation |
MalwareNetwalker | Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables. |
| T1047 Windows Management Instrumentation |
MalwareNetwalker | Netwalker can use WMI to delete Shadow Volumes. |
| T1055.001 Dynamic-link Library Injection |
MalwareNetwalker | The Netwalker DLL has been injected reflectively into the memory of a legitimate running process. |
| T1059.001 PowerShell |
MalwareNetwalker | Netwalker has been written in PowerShell and executed directly in memory, avoiding detection. |
| T1059.003 Windows Command Shell |
MalwareNetwalker | Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload. |
| T1082 System Information Discovery |
MalwareNetwalker | Netwalker can determine the system architecture it is running on to choose which version of the DLL to use. |
| T1105 Ingress Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1106 Native API |
MalwareNetwalker | Netwalker can use Windows API functions to inject the ransomware DLL. |
| T1112 Modify Registry |
MalwareNetwalker | Netwalker can add the following registry entry: |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNetwalker | Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory. |
| T1486 Data Encrypted for Impact |
MalwareNetwalker | Netwalker can encrypt files on infected machines to extort victims. |
| T1489 Service Stop |
MalwareNetwalker | Netwalker can terminate system processes and services, some of which relate to backup software. |
| T1490 Inhibit System Recovery |
MalwareNetwalker | Netwalker can delete the infected system's Shadow Volumes to prevent recovery. |
| T1518.001 Security Software Discovery |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
| T1569.002 Service Execution |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1570 Lateral Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems. |
| T1685 Disable or Modify Tools |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.