ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1001.003×

18 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareNinja

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1001.003
Protocol or Service Impersonation
MalwareBankshot

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

T1001.003
Protocol or Service Impersonation
MalwareTONESHELL

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1001.003
Protocol or Service Impersonation
MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1001.003
Protocol or Service Impersonation
MalwarePUBLOAD

PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.

T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1001.003
Protocol or Service Impersonation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareKeyBoy

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1001.003
Protocol or Service Impersonation
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FakeTLS for session authentication.

T1001.003
Protocol or Service Impersonation
MalwareUroburos

Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic.

T1001.003
Protocol or Service Impersonation
MalwareBADCALL

BADCALL uses a FakeTLS method during C2.

T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1001.003
Protocol or Service Impersonation
MalwareSUNBURST

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1001.003
Protocol or Service Impersonation
MalwareFakeM

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

T1001.003
Protocol or Service Impersonation
MalwareFRAMESTING

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

T1001.003
Protocol or Service Impersonation
MalwareHARDRAIN

HARDRAIN uses FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareStarProxy

StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareFALLCHILL

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.