ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1078×

17 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareRotaJakiro

RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate.

T1037
Boot or Logon Initialization Scripts
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder.

T1041
Exfiltration Over C2 Channel
MalwareRotaJakiro

RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP.

T1057
Process Discovery
MalwareRotaJakiro

RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process.

T1082
System Information Discovery
MalwareRotaJakiro

RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution.

T1095
Non-Application Layer Protocol
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol using a type, length, value format over TCP.

T1106
Native API
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect".

T1119
Automated Collection
MalwareRotaJakiro

Depending on the Linux distribution, RotaJakiro executes a set of commands to collect device information and sends the collected information to the C2 server.

T1129
Shared Modules
MalwareRotaJakiro

RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`.

T1132.001
Standard Encoding
MalwareRotaJakiro

RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet.

T1140
Deobfuscate/Decode Files or Information
MalwareRotaJakiro

RotaJakiro uses the AES algorithm, bit shifts in a function called `rotate`, and an XOR cipher to decrypt resources required for persistence, process guarding, and file locking. It also performs this same function on encrypted stack strings and the `head` and `key` sections in the network packet structure used for C2 communications.

T1543.002
Systemd Service
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

T1546.004
Unix Shell Configuration Modification
MalwareRotaJakiro

When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder.

T1547.013
XDG Autostart Entries
MalwareRotaJakiro

When executing with user-level permissions, RotaJakiro can install persistence using a .desktop file under the `$HOME/.config/autostart/` folder.

T1559
Inter-Process Communication
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID.

T1571
Non-Standard Port
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol over TCP port 443.

T1573.001
Symmetric Cryptography
MalwareRotaJakiro

RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.