ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0531×

43 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on window names.

T1016
System Network Configuration Discovery
MalwareGrandoreiro

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.

T1027.001
Binary Padding
MalwareGrandoreiro

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.

T1027.011
Fileless Storage
MalwareGrandoreiro

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1027.013
Encrypted/Encoded File
MalwareGrandoreiro

The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file.

T1033
System Owner/User Discovery
MalwareGrandoreiro

Grandoreiro can collect the username from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareGrandoreiro

Grandoreiro has named malicious browser extensions and update files to appear legitimate.

T1041
Exfiltration Over C2 Channel
MalwareGrandoreiro

Grandoreiro can send data it retrieves to the C2 server.

T1056.001
Keylogging
MalwareGrandoreiro

Grandoreiro can log keystrokes on the victim's machine.

T1057
Process Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on process names.

T1059.005
Visual Basic
MalwareGrandoreiro

Grandoreiro can use VBScript to execute malicious code.

T1070.004
File Deletion
MalwareGrandoreiro

Grandoreiro can delete .LNK files created in the Startup folder.

T1071.001
Web Protocols
MalwareGrandoreiro

Grandoreiro has the ability to use HTTP in C2 communications.

T1082
System Information Discovery
MalwareGrandoreiro

Grandoreiro can collect the computer name and OS version from a compromised host.

T1087.003
Email Account
MalwareGrandoreiro

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.

T1102.001
Dead Drop Resolver
MalwareGrandoreiro

Grandoreiro can obtain C2 information from Google Docs.

T1102.002
Bidirectional Communication
MalwareGrandoreiro

Grandoreiro can utilize web services including Google sites to send and receive C2 data.

T1105
Ingress Tool Transfer
MalwareGrandoreiro

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.

T1106
Native API
MalwareGrandoreiro

Grandoreiro can execute through the WinExec API.

T1112
Modify Registry
MalwareGrandoreiro

Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1115
Clipboard Data
MalwareGrandoreiro

Grandoreiro can capture clipboard data from a compromised host.

T1124
System Time Discovery
MalwareGrandoreiro

Grandoreiro can determine the time on the victim machine via IPinfo.

T1140
Deobfuscate/Decode Files or Information
MalwareGrandoreiro

Grandoreiro can decrypt its encrypted internal strings.

T1176.001
Browser Extensions
MalwareGrandoreiro

Grandoreiro can use malicious browser extensions to steal cookies and other user information.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1189
Drive-by Compromise
MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

T1204.001
Malicious Link
MalwareGrandoreiro

Grandoreiro has used malicious links to gain execution on victim machines.

T1204.002
Malicious File
MalwareGrandoreiro

Grandoreiro has infected victims via malicious attachments.

T1218.007
Msiexec
MalwareGrandoreiro

Grandoreiro can use MSI files to execute DLLs.

T1222.001
Windows Permissions
MalwareGrandoreiro

Grandoreiro can modify the binary ACL to prevent security tools from running.

T1497.001
System Checks
MalwareGrandoreiro

Grandoreiro can detect VMWare via its I/O port and Virtual PC via the vpcext instruction.

T1518.001
Security Software Discovery
MalwareGrandoreiro

Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections.

T1539
Steal Web Session Cookie
MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrandoreiro

Grandoreiro can use run keys and create link files in the startup folder for persistence.

T1547.009
Shortcut Modification
MalwareGrandoreiro

Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions.

T1548.002
Bypass User Account Control
MalwareGrandoreiro

Grandoreiro can bypass UAC by registering as the default handler for .MSC files.

T1555.003
Credentials from Web Browsers
MalwareGrandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.

T1566.002
Spearphishing Link
MalwareGrandoreiro

Grandoreiro has been spread via malicious links embedded in e-mails.

T1568.002
Domain Generation Algorithms
MalwareGrandoreiro

Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily.

T1573.002
Asymmetric Cryptography
MalwareGrandoreiro

Grandoreiro can use SSL in C2 communication.

T1685
Disable or Modify Tools
MalwareGrandoreiro

Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running.

T1686
Disable or Modify System Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686.002
Network Device Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.