Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareBlack Basta | Black Basta can check whether the service name `FAX` is present. |
| T1018 Remote System Discovery |
MalwareBlack Basta | Black Basta can use LDAP queries to connect to AD and iterate over connected workstations. |
| T1027.001 Binary Padding |
MalwareBlack Basta | Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload. |
| T1036.004 Masquerade Task or Service |
MalwareBlack Basta | Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBlack Basta | The Black Basta dropper has mimicked an application for creating USB bootable drivers. |
| T1047 Windows Management Instrumentation |
MalwareBlack Basta | Black Basta has used WMI to execute files over the network. |
| T1059.001 PowerShell |
MalwareBlack Basta | Black Basta has used PowerShell scripts for discovery and to execute files over the network. |
| T1059.003 Windows Command Shell |
MalwareBlack Basta | Black Basta can use `cmd.exe` to enable shadow copy deletion. |
| T1082 System Information Discovery |
MalwareBlack Basta | Black Basta can collect system boot configuration and CPU information. |
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1106 Native API |
MalwareBlack Basta | Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion. |
| T1112 Modify Registry |
MalwareBlack Basta | Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence. |
| T1204.002 Malicious File |
MalwareBlack Basta | Black Basta has been downloaded and executed from malicious Excel files. |
| T1222.002 Linux and Mac Permissions |
MalwareBlack Basta | The Black Basta binary can use `chmod` to gain full permissions to targeted files. |
| T1480.002 Mutual Exclusion |
MalwareBlack Basta | Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing. |
| T1486 Data Encrypted for Impact |
MalwareBlack Basta | Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion. BlackBerry Black Basta May 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022Uptycs Black Basta ESXi June 2022 |
| T1490 Inhibit System Recovery |
MalwareBlack Basta | Black Basta can delete shadow copies using vssadmin.exe. Avertium Black Basta June 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022 |
| T1491.001 Internal Defacement |
MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBlack Basta | Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis. |
| T1497.001 System Checks |
MalwareBlack Basta | Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing. |
| T1529 System Shutdown/Reboot |
MalwareBlack Basta | Black Basta has used `ShellExecuteA` to shut down and restart the victim system. |
| T1543.003 Windows Service |
MalwareBlack Basta | Black Basta can create a new service to establish persistence. |
| T1553.002 Code Signing |
MalwareBlack Basta | The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives. |
| T1622 Debugger Evasion |
MalwareBlack Basta | The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present. |
| T1680 Local Storage Discovery |
MalwareBlack Basta | Black Basta can enumerate volumes. |
| T1688 Safe Mode Boot |
MalwareBlack Basta | Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.