Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareEmbargo | Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`. |
| T1027.013 Encrypted/Encoded File |
MalwareEmbargo | Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4. |
| T1053.005 Scheduled Task |
MalwareEmbargo | Embargo has obtained persistence of the loader MDeployer by creating a scheduled task named “Perf_sys.” |
| T1057 Process Discovery |
MalwareEmbargo | Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`. |
| T1059.003 Windows Command Shell |
MalwareEmbargo | Embargo has utilized a BAT script to disable security solutions. |
| T1068 Exploitation for Privilege Escalation |
MalwareEmbargo | Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.” |
| T1070.004 File Deletion |
MalwareEmbargo | Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system. |
| T1083 File and Directory Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume. |
| T1106 Native API |
MalwareEmbargo | Embargo has leveraged Windows Native API functions to execute its operations. |
| T1112 Modify Registry |
MalwareEmbargo | Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender. |
| T1135 Network Share Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmbargo | Embargo has utilized MDeployer to decrypt two payloads that contain MS4Killer toolkit b.cache and the Embargo ransomware executable a.cache with a hardcoded RC4 key `wlQYLoPCil3niI7x8CvR9EtNtL/aeaHrZ23LP3fAsJogVTIzdnZ5Pi09ZVeHFkiB`. |
| T1480.002 Mutual Exclusion |
MalwareEmbargo | Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip." |
| T1486 Data Encrypted for Impact |
MalwareEmbargo | Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files. |
| T1489 Service Stop |
MalwareEmbargo | Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted. |
| T1490 Inhibit System Recovery |
MalwareEmbargo | Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`. |
| T1543.003 Windows Service |
MalwareEmbargo | Embargo has created persistence through the DLL variant of the MDeployer toolkit by creating a service called irnagentd that launches after the system is rebooted in Safe Mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmbargo | Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode. |
| T1569.002 Service Execution |
MalwareEmbargo | Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode. |
| T1657 Financial Theft |
MalwareEmbargo | Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom. |
| T1679 Selective Exclusion |
MalwareEmbargo | Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary. |
| T1688 Safe Mode Boot |
MalwareEmbargo | Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.