ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0595×

18 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareThiefQuest

ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.

T1041
Exfiltration Over C2 Channel
MalwareThiefQuest

ThiefQuest exfiltrates targeted file extensions in the /Users/ folder to the command and control server via unencrypted HTTP. Network packets contain a string with two pieces of information: a file path and the contents of the file in a base64 encoded string.

T1056.001
Keylogging
MalwareThiefQuest

ThiefQuest uses the CGEventTap functions to perform keylogging.

T1057
Process Discovery
MalwareThiefQuest

ThiefQuest obtains a list of running processes using the function kill_unwanted.

T1059.002
AppleScript
MalwareThiefQuest

ThiefQuest uses AppleScript's osascript -e command to launch ThiefQuest's persistence via Launch Agent and Launch Daemon.

T1071.001
Web Protocols
MalwareThiefQuest

ThiefQuest uploads files via unencrypted HTTP.

T1105
Ingress Tool Transfer
MalwareThiefQuest

ThiefQuest can download and execute payloads in-memory or from disk.

T1106
Native API
MalwareThiefQuest

ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration.

T1486
Data Encrypted for Impact
MalwareThiefQuest

ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information.

T1497.003
Time Based Checks
MalwareThiefQuest

ThiefQuest invokes time call to check the system's time, executes a sleep command, invokes a second time call, and then compares the time difference between the two time calls and the amount of time the system slept to identify the sandbox.

T1518.001
Security Software Discovery
MalwareThiefQuest

ThiefQuest uses the kill_unwanted function to get a list of running processes, compares each process with an encrypted list of “unwanted” security related programs, and kills the processes for security related programs.

T1543.001
Launch Agent
MalwareThiefQuest

ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the ~/Library/LaunchAgents/ folder and configured with the path to the persistent binary located in the ~/Library/ folder.

T1543.004
Launch Daemon
MalwareThiefQuest

When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the /Library/LaunchDaemons/ folder with the RunAtLoad key set to true establishing persistence as a Launch Daemon.

T1554
Compromise Host Software Binary
MalwareThiefQuest

ThiefQuest searches through the /Users/ folder looking for executable files. For each executable, ThiefQuest prepends a copy of itself to the beginning of the file. When the file is executed, the ThiefQuest code is executed first. ThiefQuest creates a hidden file, copies the original target executable to the file, then executes the new hidden file to maintain the appearance of normal behavior.

T1564.001
Hidden Files and Directories
MalwareThiefQuest

ThiefQuest hides a copy of itself in the user's ~/Library directory by using a . at the beginning of the file name followed by 9 random characters.

T1620
Reflective Code Loading
MalwareThiefQuest

ThiefQuest uses various API functions such as NSCreateObjectFileImageFromMemory to load and link in-memory payloads.

T1622
Debugger Evasion
MalwareThiefQuest

ThiefQuest uses a function named is_debugging to perform anti-debugging logic. The function invokes sysctl checking the returned value of P_TRACED. ThiefQuest also calls ptrace with the PTRACE_DENY_ATTACH flag to prevent debugging.

T1685
Disable or Modify Tools
MalwareThiefQuest

ThiefQuest uses the function kill_unwanted to obtain a list of running processes and kills each process matching a list of security related processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.