ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9034×

17 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1027.013
Encrypted/Encoded File
MalwareTsundere Botnet

Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk.

T1036.005
Match Legitimate Resource Name or Location
MalwareTsundere Botnet

Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software.

T1059.001
PowerShell
MalwareTsundere Botnet

Tsundere Botnet has been distributed via a PowerShell script.

T1059.007
JavaScript
MalwareTsundere Botnet

Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component.

T1071.001
Web Protocols
MalwareTsundere Botnet

Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes.

T1082
System Information Discovery
MalwareTsundere Botnet

Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information.

T1102.001
Dead Drop Resolver
MalwareTsundere Botnet

Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes.

T1105
Ingress Tool Transfer
MalwareTsundere Botnet

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.

T1140
Deobfuscate/Decode Files or Information
MalwareTsundere Botnet

Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareTsundere Botnet

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

T1218.007
Msiexec
MalwareTsundere Botnet

Tsundere Botnet has been distributed via an MSI installer.

T1480
Execution Guardrails
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1564.003
Hidden Window
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

T1567.002
Exfiltration to Cloud Storage
MalwareTsundere Botnet

Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server.

T1614
System Location Discovery
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.