ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0687×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCyclops Blink

Cyclops Blink can upload files from a compromised host.

T1016
System Network Configuration Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.

T1036.005
Match Legitimate Resource Name or Location
MalwareCyclops Blink

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.

T1037.004
RC Scripts
MalwareCyclops Blink

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.

T1041
Exfiltration Over C2 Channel
MalwareCyclops Blink

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1057
Process Discovery
MalwareCyclops Blink

Cyclops Blink can enumerate the process it is currently running under.

T1070.006
Timestomp
MalwareCyclops Blink

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.

T1071.001
Web Protocols
MalwareCyclops Blink

Cyclops Blink can download files via HTTP and HTTPS.

T1082
System Information Discovery
MalwareCyclops Blink

Cyclops Blink has the ability to query device information.

T1083
File and Directory Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.

T1090.003
Multi-hop Proxy
MalwareCyclops Blink

Cyclops Blink has used Tor nodes for C2 traffic.

T1105
Ingress Tool Transfer
MalwareCyclops Blink

Cyclops Blink has the ability to download files to target systems.

T1106
Native API
MalwareCyclops Blink

Cyclops Blink can use various Linux API functions including those for execution and discovery.

T1132.002
Non-Standard Encoding
MalwareCyclops Blink

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1140
Deobfuscate/Decode Files or Information
MalwareCyclops Blink

Cyclops Blink can decrypt and parse instructions sent from C2.

T1542.002
Component Firmware
MalwareCyclops Blink

Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices.

T1559
Inter-Process Communication
MalwareCyclops Blink

Cyclops Blink has the ability to create a pipe to enable inter-process communication.

T1571
Non-Standard Port
MalwareCyclops Blink

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.

T1572
Protocol Tunneling
MalwareCyclops Blink

Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes.

T1573.002
Asymmetric Cryptography
MalwareCyclops Blink

Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.

T1686.002
Network Device Firewall
MalwareCyclops Blink

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.