Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareTONESHELL | TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1010 Application Window Discovery |
MalwareTONESHELL | TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.007 Dynamic API Resolution |
MalwareTONESHELL | TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1027.012 LNK Icon Smuggling |
MalwareTONESHELL | TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1033 System Owner/User Discovery |
MalwareTONESHELL | TONESHELL has obtained the username from an infected host. |
| T1036.004 Masquerade Task or Service |
MalwareTONESHELL | TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service). |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTONESHELL | TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll. |
| T1047 Windows Management Instrumentation |
MalwareTONESHELL | TONESHELL has used WMI queries to gather information from the system. |
| T1053.005 Scheduled Task |
MalwareTONESHELL | TONESHELL has created scheduled tasks to maintain persistence. |
| T1055.001 Dynamic-link Library Injection |
MalwareTONESHELL | TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1056.001 Keylogging |
MalwareTONESHELL | TONESHELL has capabilities to conduct keylogging. |
| T1057 Process Discovery |
MalwareTONESHELL | TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe. |
| T1059.003 Windows Command Shell |
MalwareTONESHELL | TONESHELL has created a reverse shell using `cmd.exe`. |
| T1070.004 File Deletion |
MalwareTONESHELL | TONESHELL has deleted payload files received from the C2 server. |
| T1071.001 Web Protocols |
MalwareTONESHELL | TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2. |
| T1082 System Information Discovery |
MalwareTONESHELL | TONESHELL has the ability to retrieve the name of the infected machine. |
| T1087 Account Discovery |
MalwareTONESHELL | TONESHELL included functionality to retrieve a list of user accounts. |
| T1095 Non-Application Layer Protocol |
MalwareTONESHELL | TONESHELL has utilized TCP-based reverse shells. |
| T1105 Ingress Tool Transfer |
MalwareTONESHELL | TONESHELL has the ability to download additional files to the victim device. |
| T1106 Native API |
MalwareTONESHELL | TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
| T1113 Screen Capture |
MalwareTONESHELL | TONESHELL has conducted screen capturing. |
| T1132.002 Non-Standard Encoding |
MalwareTONESHELL | TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR. |
| T1134.002 Create Process with Token |
MalwareTONESHELL | TONESHELL included functionality to create sub-processes with a specific user’s token. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTONESHELL | TONESHELL has decoded its payload prior to execution. |
| T1205 Traffic Signaling |
MalwareTONESHELL | TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values. |
| T1218.010 Regsvr32 |
MalwareTONESHELL | TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function. |
| T1218.013 Mavinject |
MalwareTONESHELL | TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`. |
| T1480 Execution Guardrails |
MalwareTONESHELL | TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`. |
| T1480.001 Environmental Keying |
MalwareTONESHELL | TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2. |
| T1480.002 Mutual Exclusion |
MalwareTONESHELL | TONESHELL has created a mutex to avoid duplicate execution. |
| T1497.002 User Activity Based Checks |
MalwareTONESHELL | TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1518.001 Security Software Discovery |
MalwareTONESHELL | TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`. |
| T1543.003 Windows Service |
MalwareTONESHELL | TONESHELL has created a malicious service DISMsrv to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTONESHELL | TONESHELL has added Registry Run keys to achieve persistence. |
| T1553.002 Code Signing |
MalwareTONESHELL | TONESHELL has used valid legitimate digital signatures and certificates to evade detection. |
| T1559 Inter-Process Communication |
MalwareTONESHELL | TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1573.001 Symmetric Cryptography |
MalwareTONESHELL | TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets. |
| T1574.001 DLL |
MalwareTONESHELL | TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadATTACKIQ MUSTANG PANDA TONESHELL March 2023CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Trend Micro Mustang Panda Earth Preta TONESHELL June 2023Trend Micro Mustang Panda Earth Preta Toneshell February 2025Zscaler |
| T1622 Debugger Evasion |
MalwareTONESHELL | TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger. |
| T1678 Delay Execution |
MalwareTONESHELL | TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities. |
| T1680 Local Storage Discovery |
MalwareTONESHELL | TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.