Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1569.002 Service Execution |
GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
| T1569.002 Service Execution |
GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| T1569.002 Service Execution |
GroupFIN7 | FIN7 has started the SSH service by executing `sc start sshd`. |
| T1569.002 Service Execution |
GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
| T1569.002 Service Execution |
GroupKe3chang | Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries. |
| T1569.002 Service Execution |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service. |
| T1569.002 Service Execution |
GroupChimera | Chimera has used PsExec to deploy beacons on compromised systems. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1569.002 Service Execution |
GroupINC Ransom | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`. |
| T1569.002 Service Execution |
GroupSilence | Silence has used Winexe to install a service on the remote system. |
| T1569.002 Service Execution |
GroupWizard Spider | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network. |
| T1569.002 Service Execution |
GroupVelvet Ant | Velvet Ant executed and installed PlugX as a Windows service. |
| T1569.002 Service Execution |
GroupMoonstone Sleet | Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.