Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses. |
| T1018 Remote System Discovery |
MalwareCanisterWorm | CanisterWorm has scanned the local /24 subnet for new targets. |
| T1027.009 Embedded Payloads |
MalwareCanisterWorm | CanisterWorm has used embedded second stage Base64-encoded payloads. |
| T1033 System Owner/User Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames. |
| T1036.004 Masquerade Task or Service |
MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCanisterWorm | CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
| T1053.006 Systemd Timers |
MalwareCanisterWorm | CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1059.006 Python |
MalwareCanisterWorm | CanisterWorm has used a Python script as a second-stage backdoor. |
| T1059.007 JavaScript |
MalwareCanisterWorm | CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation. |
| T1070.004 File Deletion |
MalwareCanisterWorm | CanisterWorm has deleted itself after execution. |
| T1083 File and Directory Discovery |
MalwareCanisterWorm | CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1105 Ingress Tool Transfer |
MalwareCanisterWorm | CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1124 System Time Discovery |
MalwareCanisterWorm | CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.” |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCanisterWorm | CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareCanisterWorm | CanisterWorm has spread through an automated process that infects and publishes npm packages. |
| T1480 Execution Guardrails |
MalwareCanisterWorm | CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran. |
| T1485 Data Destruction |
MalwareCanisterWorm | CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts. |
| T1497.003 Time Based Checks |
MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| T1528 Steal Application Access Token |
MalwareCanisterWorm | CanisterWorm has gathered cloud access tokens. |
| T1529 System Shutdown/Reboot |
MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
| T1543 Create or Modify System Process |
MalwareCanisterWorm | CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens. |
| T1548.003 Sudo and Sudo Caching |
MalwareCanisterWorm | CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command. |
| T1550.001 Application Access Token |
MalwareCanisterWorm | CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope. |
| T1552.004 Private Keys |
MalwareCanisterWorm | CanisterWorm has gathered SSH private keys from the .ssh file. |
| T1555.006 Cloud Secrets Management Stores |
MalwareCanisterWorm | CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. |
| T1569.003 Systemctl |
MalwareCanisterWorm | CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service. |
| T1609 Container Administration Command |
MalwareCanisterWorm | CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl. |
| T1613 Container and Resource Discovery |
MalwareCanisterWorm | CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `. |
| T1614.001 System Language Discovery |
MalwareCanisterWorm | CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component. |
| T1677 Poisoned Pipeline Execution |
MalwareCanisterWorm | CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.