ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0604×

19 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareIndustroyer

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1016
System Network Configuration Discovery
MalwareIndustroyer

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1018
Remote System Discovery
MalwareIndustroyer

Industroyer can enumerate remote computers in the compromised network.

T1027
Obfuscated Files or Information
MalwareIndustroyer

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1041
Exfiltration Over C2 Channel
MalwareIndustroyer

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1046
Network Service Discovery
MalwareIndustroyer

Industroyer uses a custom port scanner to map out a network.

T1071.001
Web Protocols
MalwareIndustroyer

Industroyer’s main backdoor connected to a remote C2 server using HTTPS.

T1078
Valid Accounts
MalwareIndustroyer

Industroyer can use supplied user credentials to execute processes and stop services.

T1082
System Information Discovery
MalwareIndustroyer

Industroyer collects the victim machine’s Windows GUID.

T1083
File and Directory Discovery
MalwareIndustroyer

Industroyer’s data wiper component enumerates specific files on all the Windows drives.

T1090.003
Multi-hop Proxy
MalwareIndustroyer

Industroyer used Tor nodes for C2.

T1105
Ingress Tool Transfer
MalwareIndustroyer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareIndustroyer

Industroyer decrypts code to connect to a remote C2 server.

T1485
Data Destruction
MalwareIndustroyer

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1489
Service Stop
MalwareIndustroyer

Industroyer’s data wiper module writes zeros into the registry keys in SYSTEM\CurrentControlSet\Services to render a system inoperable.

T1499.004
Application or System Exploitation
MalwareIndustroyer

Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices.

T1543.003
Windows Service
MalwareIndustroyer

Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary.

T1554
Compromise Host Software Binary
MalwareIndustroyer

Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism.

T1572
Protocol Tunneling
MalwareIndustroyer

Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.