Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareIndustroyer | Industroyer has a data wiper component that enumerates keys in the Registry |
| T1016 System Network Configuration Discovery |
MalwareIndustroyer | Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses. |
| T1018 Remote System Discovery |
MalwareIndustroyer | Industroyer can enumerate remote computers in the compromised network. |
| T1027 Obfuscated Files or Information |
MalwareIndustroyer | Industroyer uses heavily obfuscated code in its Windows Notepad backdoor. |
| T1041 Exfiltration Over C2 Channel |
MalwareIndustroyer | Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request. |
| T1046 Network Service Discovery |
MalwareIndustroyer | Industroyer uses a custom port scanner to map out a network. |
| T1071.001 Web Protocols |
MalwareIndustroyer | Industroyer’s main backdoor connected to a remote C2 server using HTTPS. |
| T1078 Valid Accounts |
MalwareIndustroyer | Industroyer can use supplied user credentials to execute processes and stop services. |
| T1082 System Information Discovery |
MalwareIndustroyer | Industroyer collects the victim machine’s Windows GUID. |
| T1083 File and Directory Discovery |
MalwareIndustroyer | Industroyer’s data wiper component enumerates specific files on all the Windows drives. |
| T1090.003 Multi-hop Proxy |
MalwareIndustroyer | Industroyer used Tor nodes for C2. |
| T1105 Ingress Tool Transfer |
MalwareIndustroyer | Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIndustroyer | Industroyer decrypts code to connect to a remote C2 server. |
| T1485 Data Destruction |
MalwareIndustroyer | Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files. |
| T1489 Service Stop |
MalwareIndustroyer | Industroyer’s data wiper module writes zeros into the registry keys in |
| T1499.004 Application or System Exploitation |
MalwareIndustroyer | Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices. |
| T1543.003 Windows Service |
MalwareIndustroyer | Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1554 Compromise Host Software Binary |
MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| T1572 Protocol Tunneling |
MalwareIndustroyer | Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.