ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9041×

47 examples

TechniqueUsed byProcedure example
T1003.007
Proc Filesystem
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens.

T1008
Fallback Channels
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset.

T1016
System Network Configuration Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to enumerate network interfaces.

T1020
Automated Exfiltration
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there.

T1027.013
Encrypted/Encoded File
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis.

T1033
System Owner/User Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user.

T1036.005
Match Legitimate Resource Name or Location
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems.

T1041
Exfiltration Over C2 Channel
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org.

T1049
System Network Connections Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord.

T1057
Process Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can locate GitHub Actions runner processes.

T1059.004
Unix Shell
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.

T1059.006
Python
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence.

T1059.007
JavaScript
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file.

T1070.004
File Deletion
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration.

T1071.001
Web Protocols
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains.

T1074.001
Local Data Staging
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data.

T1082
System Information Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable  GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`.

T1083
File and Directory Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets.

T1105
Ingress Tool Transfer
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems.

T1119
Automated Collection
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify and collect credentials across over 50 file paths in Cloud, CI/CD, developer tooling, and container enviornments.

T1140
Deobfuscate/Decode Files or Information
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can deobfuscate an encoded Python script prior to execution.

T1213.003
Code Repositories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials.

T1213.006
Databases
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf.

T1480
Execution Guardrails
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube.

T1518
Software Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts.

T1526
Cloud Service Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search GitHub for Actions runner processes.

T1528
Steal Application Access Token
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens.

T1543.002
Systemd Service
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence.

T1546.016
Installer Packages
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution.

T1546.018
Python Startup Hooks
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup.

T1548.003
Sudo and Sudo Caching
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `sudo` for code execution.

T1552.001
Credentials In Files
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.

T1552.003
Shell History
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners.

T1552.004
Private Keys
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys.

T1552.007
Container API
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can query the Kubernetes API for credentials.

T1555
Credentials from Password Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys.

T1555.006
Cloud Secrets Management Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

T1560.001
Archive via Utility
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration.

T1564.001
Hidden Files and Directories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.

T1567.001
Exfiltration to Code Repository
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.

T1573.001
Symmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.

T1573.002
Asymmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`.

T1580
Cloud Infrastructure Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to search for generic GitHub runners.

T1609
Container Administration Command
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes.

T1613
Container and Resource Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials.

T1657
Financial Theft
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero.

T1678
Delay Execution
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.