ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0689×

28 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareWhisperGate

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.

T1036
Masquerading
MalwareWhisperGate

WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file.

T1055.012
Process Hollowing
MalwareWhisperGate

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.

T1059.001
PowerShell
MalwareWhisperGate

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.

T1059.003
Windows Command Shell
MalwareWhisperGate

WhisperGate can use `cmd.exe` to execute commands.

T1059.005
Visual Basic
MalwareWhisperGate

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.

T1070.004
File Deletion
MalwareWhisperGate

WhisperGate can delete tools from a compromised host after execution.

T1071.001
Web Protocols
MalwareWhisperGate

WhisperGate can make an HTTPS connection to download additional files.

T1083
File and Directory Discovery
MalwareWhisperGate

WhisperGate can locate files based on hardcoded file extensions.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1105
Ingress Tool Transfer
MalwareWhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1106
Native API
MalwareWhisperGate

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.

T1134.002
Create Process with Token
MalwareWhisperGate

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.

T1135
Network Share Discovery
MalwareWhisperGate

WhisperGate can enumerate connected remote logical drives.

T1140
Deobfuscate/Decode Files or Information
MalwareWhisperGate

WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations.

T1218.004
InstallUtil
MalwareWhisperGate

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1497.001
System Checks
MalwareWhisperGate

WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1518.001
Security Software Discovery
MalwareWhisperGate

WhisperGate can recognize the presence of monitoring tools on a target system.

T1529
System Shutdown/Reboot
MalwareWhisperGate

WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag.

T1542.003
Bootkit
MalwareWhisperGate

WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots.

T1561.001
Disk Content Wipe
MalwareWhisperGate

WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets.

T1561.002
Disk Structure Wipe
MalwareWhisperGate

WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1620
Reflective Code Loading
MalwareWhisperGate

WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly.

T1680
Local Storage Discovery
MalwareWhisperGate

WhisperGate has the ability to enumerate fixed logical drives on a targeted system.

T1685
Disable or Modify Tools
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.