ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9015×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBRICKSTORM

BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.

T1027
Obfuscated Files or Information
MalwareBRICKSTORM

BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.

T1027.013
Encrypted/Encoded File
MalwareBRICKSTORM

BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers.

T1036.005
Match Legitimate Resource Name or Location
MalwareBRICKSTORM

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1057
Process Discovery
MalwareBRICKSTORM

BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable.

T1059.004
Unix Shell
MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

T1070.004
File Deletion
MalwareBRICKSTORM

BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection.

T1070.010
Relocate Malware
MalwareBRICKSTORM

BRICKSTORM has copied itself to the `usr/sbin/` folder.

T1071.001
Web Protocols
MalwareBRICKSTORM

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1071.004
DNS
MalwareBRICKSTORM

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

T1083
File and Directory Discovery
MalwareBRICKSTORM

BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration.

T1090.001
Internal Proxy
MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1102
Web Service
MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1132.001
Standard Encoding
MalwareBRICKSTORM

BRICKSTORM has leveraged Base64 to encode C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareBRICKSTORM

BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution.

T1489
Service Stop
MalwareBRICKSTORM

BRICKSTORM has terminated an existing process to ensure that its own new process can execute.

T1543
Create or Modify System Process
MalwareBRICKSTORM

BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state.

T1568
Dynamic Resolution
MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

T1572
Protocol Tunneling
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

T1573.002
Asymmetric Cryptography
MalwareBRICKSTORM

BRICKSTORM has communicated with C2 infrastructure via TLS.

T1574.007
Path Interception by PATH Environment Variable
MalwareBRICKSTORM

BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path.

T1678
Delay Execution
MalwareBRICKSTORM

BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.

T1690
Prevent Command History Logging
MalwareBRICKSTORM

BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.