ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9043×

55 examples

TechniqueUsed byProcedure example
T1003.007
Proc Filesystem
MalwareMini Shai-Hulud

Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens.

T1008
Fallback Channels
MalwareMini Shai-Hulud

Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable.

T1016
System Network Configuration Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`.

T1021.007
Cloud Services
MalwareMini Shai-Hulud

Mini Shai-Hulud has accessed and propagated to AWS EC2 instances via SSM Send-Command.

T1027.013
Encrypted/Encoded File
MalwareMini Shai-Hulud

Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime.

T1033
System Owner/User Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner.

T1036.005
Match Legitimate Resource Name or Location
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs.

T1041
Exfiltration Over C2 Channel
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains.

T1053.006
Systemd Timers
MalwareMini Shai-Hulud

Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts.

T1059.006
Python
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python scripts to execute payloads.

T1059.007
JavaScript
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts.

T1059.013
Container CLI/API
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials.

T1070.004
File Deletion
MalwareMini Shai-Hulud

Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection.

T1071.001
Web Protocols
MalwareMini Shai-Hulud

Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains.

T1078.004
Cloud Accounts
MalwareMini Shai-Hulud

Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages.

T1082
System Information Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host.

T1083
File and Directory Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated home directories, file paths and files associated with storing or containing credentials and other secrets.

T1087.004
Cloud Account
MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity.

T1090.003
Multi-hop Proxy
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network.

T1102.001
Dead Drop Resolver
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories.

T1105
Ingress Tool Transfer
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure.

T1119
Automated Collection
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to automatically compile gathered credentials from configuration files and password vaults within an archive and exfiltrate stolen data leveraging both a primary and fallback C2.

T1124
System Time Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host.

T1132.001
Standard Encoding
MalwareMini Shai-Hulud

Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2.

T1140
Deobfuscate/Decode Files or Information
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to decrypt obfuscated payloads.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareMini Shai-Hulud

Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims.

T1205
Traffic Signaling
MalwareMini Shai-Hulud

Mini Shai-Hulud has examined commit messages for a keyword followed by base64 encoded segments to validate communications and to execute subsequent actions to include exfiltration.

T1213.003
Code Repositories
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories.

T1480
Execution Guardrails
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel.

T1485
Data Destruction
MalwareMini Shai-Hulud

Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary.

T1497
Virtualization/Sandbox Evasion
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target.

T1497.001
System Checks
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.

T1528
Steal Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD.

T1543.001
Launch Agent
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds.

T1543.002
Systemd Service
MalwareMini Shai-Hulud

Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence.

T1546
Event Triggered Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions.

T1546.018
Python Startup Hooks
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution.

T1550.001
Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to authenticate using stolen application access tokens.

T1552.001
Credentials In Files
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.

T1552.004
Private Keys
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh.

T1552.005
Cloud Instance Metadata API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API.

T1552.007
Container API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators.

T1554
Compromise Host Software Binary
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers.

T1555.005
Password Managers
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults.

T1555.006
Cloud Secrets Management Stores
MalwareMini Shai-Hulud

Mini Shai-Hulud has captured credentials stored in cloud secret stores.

T1559
Inter-Process Communication
MalwareMini Shai-Hulud

Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.

T1560
Archive Collected Data
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures.

T1560.001
Archive via Utility
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration.

T1564.011
Ignore Process Interrupts
MalwareMini Shai-Hulud

Mini Shai-Hulud has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values.

T1567.001
Exfiltration to Code Repository
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.