Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to move laterally via SMB. |
| T1047 Windows Management Instrumentation |
MalwareLockBit 2.0 | LockBit 2.0 can use wmic.exe to delete volume shadow copies. |
| T1053.005 Scheduled Task |
MalwareLockBit 2.0 | LockBit 2.0 can be executed via scheduled task. |
| T1057 Process Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration. |
| T1059.001 PowerShell |
MalwareLockBit 2.0 | LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy. |
| T1059.003 Windows Command Shell |
MalwareLockBit 2.0 | LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
| T1070.004 File Deletion |
MalwareLockBit 2.0 | LockBit 2.0 can delete itself from disk after execution. |
| T1082 System Information Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate system information including hostname and domain information. |
| T1083 File and Directory Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can exclude files associated with core system functions from encryption. |
| T1112 Modify Registry |
MalwareLockBit 2.0 | LockBit 2.0 can create Registry keys to bypass UAC and for persistence. |
| T1120 Peripheral Device Discovery |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to identify mounted external storage devices. |
| T1135 Network Share Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can discover remote shares. |
| T1136 Create Account |
MalwareLockBit 2.0 | LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 2.0 | LockBit 2.0 can decode scripts and strings in loaded modules. |
| T1480 Execution Guardrails |
MalwareLockBit 2.0 | LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
| T1484.001 Group Policy Modification |
MalwareLockBit 2.0 | LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 2.0 | LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data. |
| T1489 Service Stop |
MalwareLockBit 2.0 | LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes. |
| T1490 Inhibit System Recovery |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLockBit 2.0 | LockBit 2.0 can use a Registry Run key to establish persistence at startup. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 2.0 | LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`. |
| T1564.003 Hidden Window |
MalwareLockBit 2.0 | LockBit 2.0 can execute command line arguments in a hidden window. |
| T1614.001 System Language Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so. |
| T1680 Local Storage Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate local drive configuration. |
| T1685 Disable or Modify Tools |
MalwareLockBit 2.0 | LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 2.0 | LockBit 2.0 can delete log files through the use of wevtutil. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.