Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1068 Exploitation for Privilege Escalation |
MalwareStuxnet | Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines. |
| T1068 Exploitation for Privilege Escalation |
MalwareCosmicDuke | CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398. |
| T1068 Exploitation for Privilege Escalation |
MalwareHildegard | Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1068 Exploitation for Privilege Escalation |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service. |
| T1068 Exploitation for Privilege Escalation |
MalwareProLock | ProLock can use CVE-2019-0859 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
MalwareInvisiMole | InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareSiloscape | Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host. |
| T1068 Exploitation for Privilege Escalation |
MalwareRemsec | Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareEmbargo | Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.” |
| T1068 Exploitation for Privilege Escalation |
MalwareJHUHUGIT | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwarePandora | Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1068 Exploitation for Privilege Escalation |
MalwareWingbird | Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareCarberp | Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
MalwareXCSSET | XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1068 Exploitation for Privilege Escalation |
MalwareZox | Zox has the ability to leverage local and remote exploits to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
ToolEmpire | Empire can exploit vulnerabilities such as MS16-032 and MS16-135. |
| T1068 Exploitation for Privilege Escalation |
ToolPoshC2 | PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099. |
| T1068 Exploitation for Privilege Escalation |
MalwareZeroCleare | ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.