Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1027.013 Encrypted/Encoded File |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption. |
| T1037 Boot or Logon Initialization Scripts |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| T1040 Network Sniffing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1055.002 Portable Executable Injection |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1057 Process Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched for running processes to include web or dsmdm. |
| T1059.006 Python |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files. |
| T1070.004 File Deletion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has deleted generated files and folders from victim devices. |
| T1070.006 Timestomp |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has updated the timestamp using the `touch` command. |
| T1082 System Information Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has obtained system information such as release, uptime, and current time. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has decoded a XOR encoded private key. |
| T1480.002 Mutual Exclusion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`. |
| T1505.003 Web Shell |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
| T1518.001 Security Software Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has checked where SELinux is enabled on the targeted host. |
| T1553.002 Code Signing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate. |
| T1559 Inter-Process Communication |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process. |
| T1571 Non-Standard Port |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1574 Hijack Execution Flow |
MalwareSPAWNCHIMERA | SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process. |
| T1574.006 Dynamic Linker Hijacking |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection. |
| T1678 Delay Execution |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.