Real-world descriptions of how a group, tool or campaign used a technique.
33 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareShai-Hulud | Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShai-Hulud | Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.009 Break Process Trees |
MalwareShai-Hulud | Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally. |
| T1041 Exfiltration Over C2 Channel |
MalwareShai-Hulud | Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1059.001 PowerShell |
MalwareShai-Hulud | Shai-Hulud has utilized PowerShell `Invoke-WebRequest` to download and install the malicious payload. |
| T1059.004 Unix Shell |
MalwareShai-Hulud | Shai-Hulud has utilized Linux shell commands to modify configuration files. |
| T1059.007 JavaScript |
MalwareShai-Hulud | Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1071.001 Web Protocols |
MalwareShai-Hulud | Shai-Hulud has utilized curl to install Bun over HTTPS. |
| T1078.004 Cloud Accounts |
MalwareShai-Hulud | Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1082 System Information Discovery |
MalwareShai-Hulud | Shai-Hulud has gathered victim system information. |
| T1098 Account Manipulation |
MalwareShai-Hulud | Shai-Hulud has modified GitHub account settings for private repositories and changed them to public. |
| T1105 Ingress Tool Transfer |
MalwareShai-Hulud | Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data. |
| T1119 Automated Collection |
MalwareShai-Hulud | Shai-Hulud has the ability to automatically collect host data, secrets, system information, and endpoints. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareShai-Hulud | Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| T1213.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them. |
| T1485 Data Destruction |
MalwareShai-Hulud | Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices. |
| T1528 Steal Application Access Token |
MalwareShai-Hulud | Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories. |
| T1543.002 Systemd Service |
MalwareShai-Hulud | Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls. |
| T1546.016 Installer Packages |
MalwareShai-Hulud | Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`. |
| T1548.003 Sudo and Sudo Caching |
MalwareShai-Hulud | Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`. |
| T1550.001 Application Access Token |
MalwareShai-Hulud | Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts. |
| T1552.001 Credentials In Files |
MalwareShai-Hulud | Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files. |
| T1552.005 Cloud Instance Metadata API |
MalwareShai-Hulud | Shai-Hulud has queried the AWS and GCP metadata endpoints for instances and service credentials. |
| T1553 Subvert Trust Controls |
MalwareShai-Hulud | Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0. |
| T1555.006 Cloud Secrets Management Stores |
MalwareShai-Hulud | Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault. |
| T1564.011 Ignore Process Interrupts |
MalwareShai-Hulud | Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`. |
| T1567.001 Exfiltration to Code Repository |
MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| T1567.004 Exfiltration Over Webhook |
MalwareShai-Hulud | Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`. |
| T1593.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string. |
| T1608.001 Upload Malware |
MalwareShai-Hulud | Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts. |
| T1677 Poisoned Pipeline Execution |
MalwareShai-Hulud | Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`. |
| T1678 Delay Execution |
MalwareShai-Hulud | Shai-Hulud has delayed execution of its larger payloads by forking itself into background process. |
| T1685 Disable or Modify Tools |
MalwareShai-Hulud | Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.