ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9024×

23 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1027.013
Encrypted/Encoded File
MalwareSPAWNCHIMERA

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1037
Boot or Logon Initialization Scripts
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

T1040
Network Sniffing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1057
Process Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1059.006
Python
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1070.004
File Deletion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has deleted generated files and folders from victim devices.

T1070.006
Timestomp
MalwareSPAWNCHIMERA

SPAWNCHIMERA has updated the timestamp using the `touch` command.

T1082
System Information Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has obtained system information such as release, uptime, and current time.

T1140
Deobfuscate/Decode Files or Information
MalwareSPAWNCHIMERA

SPAWNCHIMERA has decoded a XOR encoded private key.

T1480.002
Mutual Exclusion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`.

T1505.003
Web Shell
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

T1518.001
Security Software Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has checked where SELinux is enabled on the targeted host.

T1553.002
Code Signing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate.

T1559
Inter-Process Communication
MalwareSPAWNCHIMERA

SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process.

T1571
Non-Standard Port
MalwareSPAWNCHIMERA

SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300.

T1572
Protocol Tunneling
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1574.006
Dynamic Linker Hijacking
MalwareSPAWNCHIMERA

SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection.

T1678
Delay Execution
MalwareSPAWNCHIMERA

SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution.

T1685
Disable or Modify Tools
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.