Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBRICKSTORM | BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file. |
| T1027 Obfuscated Files or Information |
MalwareBRICKSTORM | BRICKSTORM has utilized Go libraries to include Garble to obfuscate code. |
| T1027.013 Encrypted/Encoded File |
MalwareBRICKSTORM | BRICKSTORM has utilized XOR cipher encryption to hide key strings within their code, to include IPv4 addresses of public DNS-over-HTTPS (DOH) servers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBRICKSTORM | BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`. |
| T1041 Exfiltration Over C2 Channel |
MalwareBRICKSTORM | BRICKSTORM has uploaded files from the victim system to C2 servers. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1057 Process Discovery |
MalwareBRICKSTORM | BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable. |
| T1059.004 Unix Shell |
MalwareBRICKSTORM | BRICKSTORM has executed shell commands using `/bin/sh`. |
| T1070.004 File Deletion |
MalwareBRICKSTORM | BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection. |
| T1070.010 Relocate Malware |
MalwareBRICKSTORM | BRICKSTORM has copied itself to the `usr/sbin/` folder. |
| T1071.001 Web Protocols |
MalwareBRICKSTORM | BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls. |
| T1071.004 DNS |
MalwareBRICKSTORM | BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection. |
| T1083 File and Directory Discovery |
MalwareBRICKSTORM | BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration. |
| T1090.001 Internal Proxy |
MalwareBRICKSTORM | BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic. |
| T1102 Web Service |
MalwareBRICKSTORM | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareBRICKSTORM | BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system. |
| T1132.001 Standard Encoding |
MalwareBRICKSTORM | BRICKSTORM has leveraged Base64 to encode C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBRICKSTORM | BRICKSTORM has decoded its encrypted C2 traffic prior to execution. BRICKSTORM also has the ability to decode its obfuscated payload before execution. |
| T1489 Service Stop |
MalwareBRICKSTORM | BRICKSTORM has terminated an existing process to ensure that its own new process can execute. |
| T1543 Create or Modify System Process |
MalwareBRICKSTORM | BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state. |
| T1568 Dynamic Resolution |
MalwareBRICKSTORM | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses. |
| T1572 Protocol Tunneling |
MalwareBRICKSTORM | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1573.002 Asymmetric Cryptography |
MalwareBRICKSTORM | BRICKSTORM has communicated with C2 infrastructure via TLS. |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareBRICKSTORM | BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path. |
| T1678 Delay Execution |
MalwareBRICKSTORM | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain. |
| T1690 Prevent Command History Logging |
MalwareBRICKSTORM | BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.