Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCyclops Blink | Cyclops Blink can upload files from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCyclops Blink | Cyclops Blink can rename its running process to |
| T1037.004 RC Scripts |
MalwareCyclops Blink | Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled. |
| T1041 Exfiltration Over C2 Channel |
MalwareCyclops Blink | Cyclops Blink has the ability to upload exfiltrated files to a C2 server. |
| T1057 Process Discovery |
MalwareCyclops Blink | Cyclops Blink can enumerate the process it is currently running under. |
| T1070.006 Timestomp |
MalwareCyclops Blink | Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images. |
| T1071.001 Web Protocols |
MalwareCyclops Blink | Cyclops Blink can download files via HTTP and HTTPS. |
| T1082 System Information Discovery |
MalwareCyclops Blink | Cyclops Blink has the ability to query device information. |
| T1083 File and Directory Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory. |
| T1090.003 Multi-hop Proxy |
MalwareCyclops Blink | Cyclops Blink has used Tor nodes for C2 traffic. |
| T1105 Ingress Tool Transfer |
MalwareCyclops Blink | Cyclops Blink has the ability to download files to target systems. |
| T1106 Native API |
MalwareCyclops Blink | Cyclops Blink can use various Linux API functions including those for execution and discovery. |
| T1132.002 Non-Standard Encoding |
MalwareCyclops Blink | Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCyclops Blink | Cyclops Blink can decrypt and parse instructions sent from C2. |
| T1542.002 Component Firmware |
MalwareCyclops Blink | Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices. |
| T1559 Inter-Process Communication |
MalwareCyclops Blink | Cyclops Blink has the ability to create a pipe to enable inter-process communication. |
| T1571 Non-Standard Port |
MalwareCyclops Blink | Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic. |
| T1572 Protocol Tunneling |
MalwareCyclops Blink | Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes. |
| T1573.002 Asymmetric Cryptography |
MalwareCyclops Blink | Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key. |
| T1686.002 Network Device Firewall |
MalwareCyclops Blink | Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.