Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareSkidmap | Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low. |
| T1027.013 Encrypted/Encoded File |
MalwareSkidmap | Skidmap has encrypted it's main payload using 3DES. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSkidmap | Skidmap has created a fake |
| T1053.003 Cron |
MalwareSkidmap | Skidmap has installed itself via crontab. |
| T1057 Process Discovery |
MalwareSkidmap | Skidmap has monitored critical processes to ensure resiliency. |
| T1059.004 Unix Shell |
MalwareSkidmap | Skidmap has used |
| T1082 System Information Discovery |
MalwareSkidmap | Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use. |
| T1083 File and Directory Discovery |
MalwareSkidmap | Skidmap has checked for the existence of specific files including |
| T1098.004 SSH Authorized Keys |
MalwareSkidmap | Skidmap has the ability to add the public key of its handlers to the |
| T1105 Ingress Tool Transfer |
MalwareSkidmap | Skidmap has the ability to download files on an infected host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSkidmap | Skidmap has the ability to download, unpack, and decrypt tar.gz files . |
| T1496.001 Compute Hijacking |
MalwareSkidmap | Skidmap is a kernel-mode rootkit used for cryptocurrency mining. |
| T1518.001 Security Software Discovery |
MalwareSkidmap | Skidmap has the ability to check if |
| T1547.006 Kernel Modules and Extensions |
MalwareSkidmap | Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines. |
| T1556.003 Pluggable Authentication Modules |
MalwareSkidmap | Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users. |
| T1685 Disable or Modify Tools |
MalwareSkidmap | Skidmap has the ability to set SELinux to permissive mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.