ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0477×

18 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareGoopy

Goopy has the ability to exfiltrate documents from infected systems.

T1027.001
Binary Padding
MalwareGoopy

Goopy has had null characters padded in its malicious DLL payload.

T1027.016
Junk Code Insertion
MalwareGoopy

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1033
System Owner/User Discovery
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoopy

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

T1041
Exfiltration Over C2 Channel
MalwareGoopy

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1053.005
Scheduled Task
MalwareGoopy

Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour.

T1057
Process Discovery
MalwareGoopy

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.

T1059.003
Windows Command Shell
MalwareGoopy

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.

T1059.005
Visual Basic
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1070.008
Clear Mailbox Data
MalwareGoopy

Goopy has the ability to delete emails used for C2 once the content has been copied.

T1071.001
Web Protocols
MalwareGoopy

Goopy has the ability to communicate with its C2 over HTTP.

T1071.003
Mail Protocols
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1071.004
DNS
MalwareGoopy

Goopy has the ability to communicate with its C2 over DNS.

T1106
Native API
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name via GetUserNameW.

T1140
Deobfuscate/Decode Files or Information
MalwareGoopy

Goopy has used a polymorphic decryptor to decrypt itself at runtime.

T1574.001
DLL
MalwareGoopy

Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google.

T1685
Disable or Modify Tools
MalwareGoopy

Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.