Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareWhisperGate | WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage. |
| T1036 Masquerading |
MalwareWhisperGate | WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file. |
| T1055.012 Process Hollowing |
MalwareWhisperGate | WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1059.001 PowerShell |
MalwareWhisperGate | WhisperGate can use PowerShell to support multiple actions including execution and defense evasion. |
| T1059.003 Windows Command Shell |
MalwareWhisperGate | WhisperGate can use `cmd.exe` to execute commands. |
| T1059.005 Visual Basic |
MalwareWhisperGate | WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender. |
| T1070.004 File Deletion |
MalwareWhisperGate | WhisperGate can delete tools from a compromised host after execution. |
| T1071.001 Web Protocols |
MalwareWhisperGate | WhisperGate can make an HTTPS connection to download additional files. |
| T1083 File and Directory Discovery |
MalwareWhisperGate | WhisperGate can locate files based on hardcoded file extensions. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1105 Ingress Tool Transfer |
MalwareWhisperGate | WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1106 Native API |
MalwareWhisperGate | WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls. |
| T1134.002 Create Process with Token |
MalwareWhisperGate | The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`. |
| T1135 Network Share Discovery |
MalwareWhisperGate | WhisperGate can enumerate connected remote logical drives. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWhisperGate | WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations. |
| T1218.004 InstallUtil |
MalwareWhisperGate | WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender. |
| T1485 Data Destruction |
MalwareWhisperGate | WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions. |
| T1497.001 System Checks |
MalwareWhisperGate | WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1518.001 Security Software Discovery |
MalwareWhisperGate | WhisperGate can recognize the presence of monitoring tools on a target system. |
| T1529 System Shutdown/Reboot |
MalwareWhisperGate | WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag. |
| T1542.003 Bootkit |
MalwareWhisperGate | WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots. |
| T1561.001 Disk Content Wipe |
MalwareWhisperGate | WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1620 Reflective Code Loading |
MalwareWhisperGate | WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly. |
| T1680 Local Storage Discovery |
MalwareWhisperGate | WhisperGate has the ability to enumerate fixed logical drives on a targeted system. |
| T1685 Disable or Modify Tools |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.