ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1178×

21 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShrinkLocker

ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption.

T1041
Exfiltration Over C2 Channel
MalwareShrinkLocker

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1047
Windows Management Instrumentation
MalwareShrinkLocker

ShrinkLocker uses WMI to query information about the victim operating system.

T1057
Process Discovery
MalwareShrinkLocker

ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running.

T1059.001
PowerShell
MalwareShrinkLocker

ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system.

T1059.005
Visual Basic
MalwareShrinkLocker

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1070.004
File Deletion
MalwareShrinkLocker

ShrinkLocker can delete itself depending on various checks performed during execution.

T1071.001
Web Protocols
MalwareShrinkLocker

ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor.

T1082
System Information Discovery
MalwareShrinkLocker

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1102
Web Service
MalwareShrinkLocker

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1124
System Time Discovery
MalwareShrinkLocker

ShrinkLocker retrieves a system timestamp that is used in generating an encryption key.

T1480
Execution Guardrails
MalwareShrinkLocker

ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria.

T1485
Data Destruction
MalwareShrinkLocker

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1486
Data Encrypted for Impact
MalwareShrinkLocker

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

T1491.001
Internal Defacement
MalwareShrinkLocker

ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation.

T1529
System Shutdown/Reboot
MalwareShrinkLocker

ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users.

T1561.002
Disk Structure Wipe
MalwareShrinkLocker

ShrinkLocker has used Diskpart to format newly-created partitions.

T1685
Disable or Modify Tools
MalwareShrinkLocker

ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems.

T1685.005
Clear Windows Event Logs
MalwareShrinkLocker

ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.