ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1180×

21 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareBlackByte Ransomware

BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key.

T1021.002
SMB/Windows Admin Shares
MalwareBlackByte Ransomware

BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB.

T1027.013
Encrypted/Encoded File
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as an encrypted payload.

T1046
Network Service Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads.

T1053.005
Scheduled Task
MalwareBlackByte Ransomware

BlackByte Ransomware creates a schedule task to execute remotely deployed ransomware payloads.

T1059.007
JavaScript
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as a JavaScript launcher file.

T1082
System Information Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware gathers victim system information to generate a unique victim identifier.

T1106
Native API
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep.

T1112
Modify Registry
MalwareBlackByte Ransomware

BlackByte Ransomware modifies the victim Registry to prevent system recovery.

T1135
Network Share Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware can identify network shares connected to the victim machine.

T1140
Deobfuscate/Decode Files or Information
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file.

T1222.001
Windows Permissions
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

T1480
Execution Guardrails
MalwareBlackByte Ransomware

BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate.

T1486
Data Encrypted for Impact
MalwareBlackByte Ransomware

BlackByte Ransomware is ransomware using a shared key across victims for encryption.

T1490
Inhibit System Recovery
MalwareBlackByte Ransomware

BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment.

T1497.001
System Checks
MalwareBlackByte Ransomware

BlackByte Ransomware checks for files related to known sandboxes.

T1518.001
Security Software Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware looks for security software products prior to full execution.

T1570
Lateral Tool Transfer
MalwareBlackByte Ransomware

BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders.

T1614.001
System Language Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware identifies the language on the victim system.

T1685
Disable or Modify Tools
MalwareBlackByte Ransomware

BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility.

T1689
Downgrade Attack
MalwareBlackByte Ransomware

BlackByte Ransomware enables SMBv1 during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.