ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9042×

32 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1018
Remote System Discovery
MalwareCanisterWorm

CanisterWorm has scanned the local /24 subnet for new targets.

T1027.009
Embedded Payloads
MalwareCanisterWorm

CanisterWorm has used embedded second stage Base64-encoded payloads.

T1033
System Owner/User Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

T1036.004
Masquerade Task or Service
MalwareCanisterWorm

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

T1036.005
Match Legitimate Resource Name or Location
MalwareCanisterWorm

CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.

T1053.006
Systemd Timers
MalwareCanisterWorm

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

T1059.004
Unix Shell
MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

T1059.006
Python
MalwareCanisterWorm

CanisterWorm has used a Python script as a second-stage backdoor.

T1059.007
JavaScript
MalwareCanisterWorm

CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.

T1070.004
File Deletion
MalwareCanisterWorm

CanisterWorm has deleted itself after execution.

T1083
File and Directory Discovery
MalwareCanisterWorm

CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values.

T1102.001
Dead Drop Resolver
MalwareCanisterWorm

CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery.

T1105
Ingress Tool Transfer
MalwareCanisterWorm

CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.

T1124
System Time Discovery
MalwareCanisterWorm

CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.”

T1140
Deobfuscate/Decode Files or Information
MalwareCanisterWorm

CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareCanisterWorm

CanisterWorm has spread through an automated process that infects and publishes npm packages.

T1480
Execution Guardrails
MalwareCanisterWorm

CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran.

T1485
Data Destruction
MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

T1497.003
Time Based Checks
MalwareCanisterWorm

CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments.

T1528
Steal Application Access Token
MalwareCanisterWorm

CanisterWorm has gathered cloud access tokens.

T1529
System Shutdown/Reboot
MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

T1543
Create or Modify System Process
MalwareCanisterWorm

CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens.

T1548.003
Sudo and Sudo Caching
MalwareCanisterWorm

CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command.

T1550.001
Application Access Token
MalwareCanisterWorm

CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope.

T1552.004
Private Keys
MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

T1555.006
Cloud Secrets Management Stores
MalwareCanisterWorm

CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

T1569.003
Systemctl
MalwareCanisterWorm

CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service.

T1609
Container Administration Command
MalwareCanisterWorm

CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.

T1613
Container and Resource Discovery
MalwareCanisterWorm

CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `.

T1614.001
System Language Discovery
MalwareCanisterWorm

CanisterWorm has checked the target system's timezone `(/etc/timezone, timedatectl)` for `Asia/Tehran` or `Iran` and the `LANG` environment variable for `fa_IR` to identify systems matching an Iranian locale prior to deploying its destructive wiper component.

T1677
Poisoned Pipeline Execution
MalwareCanisterWorm

CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.