ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1569.002×

16 examples

TechniqueUsed byProcedure example
T1569.002
Service Execution
GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

T1569.002
Service Execution
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

T1569.002
Service Execution
GroupFIN7

FIN7 has started the SSH service by executing `sc start sshd`.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

T1569.002
Service Execution
GroupKe3chang

Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries.

T1569.002
Service Execution
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.

T1569.002
Service Execution
GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1569.002
Service Execution
GroupINC Ransom

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1569.002
Service Execution
GroupVelvet Ant

Velvet Ant executed and installed PlugX as a Windows service.

T1569.002
Service Execution
GroupMoonstone Sleet

Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.