ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1039×

39 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBumblebee

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1008
Fallback Channels
MalwareBumblebee

Bumblebee can use backup C2 servers if the primary server fails.

T1012
Query Registry
MalwareBumblebee

Bumblebee can check the Registry for specific keys.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1033
System Owner/User Discovery
MalwareBumblebee

Bumblebee has the ability to identify the user name.

T1036.005
Match Legitimate Resource Name or Location
MalwareBumblebee

Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer.

T1041
Exfiltration Over C2 Channel
MalwareBumblebee

Bumblebee can send collected data in JSON format to C2.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1053.005
Scheduled Task
MalwareBumblebee

Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task.

T1055
Process Injection
MalwareBumblebee

Bumblebee can inject code into multiple processes on infected endpoints.

T1055.001
Dynamic-link Library Injection
MalwareBumblebee

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.004
Asynchronous Procedure Call
MalwareBumblebee

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

T1057
Process Discovery
MalwareBumblebee

Bumblebee can identify processes associated with analytical tools.

T1059.001
PowerShell
MalwareBumblebee

Bumblebee can use PowerShell for execution.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1059.005
Visual Basic
MalwareBumblebee

Bumblebee can create a Visual Basic script to enable persistence.

T1070.004
File Deletion
MalwareBumblebee

Bumblebee can uninstall its loader through the use of a `Sdl` command.

T1082
System Information Discovery
MalwareBumblebee

Bumblebee can enumerate the OS version and domain on a targeted system.

T1102
Web Service
MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1106
Native API
MalwareBumblebee

Bumblebee can use multiple Native APIs.

T1129
Shared Modules
MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

T1132.001
Standard Encoding
MalwareBumblebee

Bumblebee has the ability to base64 encode C2 server responses.

T1140
Deobfuscate/Decode Files or Information
MalwareBumblebee

Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts.

T1204.001
Malicious Link
MalwareBumblebee

Bumblebee has relied upon a user downloading a file from a OneDrive link for execution.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1218.008
Odbcconf
MalwareBumblebee

Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts.

T1218.011
Rundll32
MalwareBumblebee

Bumblebee has used `rundll32` for execution of the loader component.

T1497
Virtualization/Sandbox Evasion
MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

T1497.001
System Checks
MalwareBumblebee

Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products.

T1497.003
Time Based Checks
MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1548.002
Bypass User Account Control
MalwareBumblebee

Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges.

T1559.001
Component Object Model
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

T1560
Archive Collected Data
MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1566.002
Spearphishing Link
MalwareBumblebee

Bumblebee has been spread through e-mail campaigns with malicious links.

T1573.001
Symmetric Cryptography
MalwareBumblebee

Bumblebee can encrypt C2 requests and responses with RC4

T1622
Debugger Evasion
MalwareBumblebee

Bumblebee can search for tools used in static analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.