ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0669×

20 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareKOCTOPUS

KOCTOPUS has obfuscated scripts with the BatchEncryption tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareKOCTOPUS

KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.

T1059.001
PowerShell
MalwareKOCTOPUS

KOCTOPUS has used PowerShell commands to download additional files.

T1059.003
Windows Command Shell
MalwareKOCTOPUS

KOCTOPUS has used `cmd.exe` and batch files for execution.

T1059.005
Visual Basic
MalwareKOCTOPUS

KOCTOPUS has used VBScript to call wscript to execute a PowerShell command.

T1070.009
Clear Persistence
MalwareKOCTOPUS

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

T1082
System Information Discovery
MalwareKOCTOPUS

KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command.

T1090
Proxy
MalwareKOCTOPUS

KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet.

T1105
Ingress Tool Transfer
MalwareKOCTOPUS

KOCTOPUS has executed a PowerShell command to download a file to the system.

T1106
Native API
MalwareKOCTOPUS

KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution.

T1112
Modify Registry
MalwareKOCTOPUS

KOCTOPUS has added and deleted keys from the Registry.

T1140
Deobfuscate/Decode Files or Information
MalwareKOCTOPUS

KOCTOPUS has deobfuscated itself before executing its commands.

T1204.001
Malicious Link
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking on a malicious link delivered via email.

T1204.002
Malicious File
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking a malicious document for execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareKOCTOPUS

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

T1548.002
Bypass User Account Control
MalwareKOCTOPUS

KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe.

T1564.003
Hidden Window
MalwareKOCTOPUS

KOCTOPUS has used -WindowsStyle Hidden to hide the command window.

T1566.001
Spearphishing Attachment
MalwareKOCTOPUS

KOCTOPUS has been distributed via spearphishing emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareKOCTOPUS

KOCTOPUS has been distributed as a malicious link within an email.

T1685
Disable or Modify Tools
MalwareKOCTOPUS

KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.