ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0468×

16 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareSkidmap

Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.

T1027.013
Encrypted/Encoded File
MalwareSkidmap

Skidmap has encrypted it's main payload using 3DES.

T1036.005
Match Legitimate Resource Name or Location
MalwareSkidmap

Skidmap has created a fake rm binary to replace the legitimate Linux binary.

T1053.003
Cron
MalwareSkidmap

Skidmap has installed itself via crontab.

T1057
Process Discovery
MalwareSkidmap

Skidmap has monitored critical processes to ensure resiliency.

T1059.004
Unix Shell
MalwareSkidmap

Skidmap has used pm.sh to download and install its main payload.

T1082
System Information Discovery
MalwareSkidmap

Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.

T1083
File and Directory Discovery
MalwareSkidmap

Skidmap has checked for the existence of specific files including /usr/sbin/setenforce and /etc/selinux/config. It also has the ability to monitor the cryptocurrency miner file and process.

T1098.004
SSH Authorized Keys
MalwareSkidmap

Skidmap has the ability to add the public key of its handlers to the authorized_keys file to maintain persistence on an infected host.

T1105
Ingress Tool Transfer
MalwareSkidmap

Skidmap has the ability to download files on an infected host.

T1140
Deobfuscate/Decode Files or Information
MalwareSkidmap

Skidmap has the ability to download, unpack, and decrypt tar.gz files .

T1496.001
Compute Hijacking
MalwareSkidmap

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

T1518.001
Security Software Discovery
MalwareSkidmap

Skidmap has the ability to check if /usr/sbin/setenforce exists. This file controls what mode SELinux is in.

T1547.006
Kernel Modules and Extensions
MalwareSkidmap

Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.

T1556.003
Pluggable Authentication Modules
MalwareSkidmap

Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users.

T1685
Disable or Modify Tools
MalwareSkidmap

Skidmap has the ability to set SELinux to permissive mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.