ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1068×

19 examples

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
MalwareStuxnet

Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines.

T1068
Exploitation for Privilege Escalation
MalwareCosmicDuke

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

T1068
Exploitation for Privilege Escalation
MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1068
Exploitation for Privilege Escalation
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.

T1068
Exploitation for Privilege Escalation
MalwareProLock

ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareSiloscape

Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host.

T1068
Exploitation for Privilege Escalation
MalwareRemsec

Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareEmbargo

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

T1068
Exploitation for Privilege Escalation
MalwareJHUHUGIT

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1068
Exploitation for Privilege Escalation
MalwarePandora

Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1068
Exploitation for Privilege Escalation
MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

T1068
Exploitation for Privilege Escalation
MalwareWingbird

Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.

T1068
Exploitation for Privilege Escalation
MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1068
Exploitation for Privilege Escalation
MalwareXCSSET

XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP.

T1068
Exploitation for Privilege Escalation
MalwareZox

Zox has the ability to leverage local and remote exploits to escalate privileges.

T1068
Exploitation for Privilege Escalation
ToolEmpire

Empire can exploit vulnerabilities such as MS16-032 and MS16-135.

T1068
Exploitation for Privilege Escalation
ToolPoshC2

PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099.

T1068
Exploitation for Privilege Escalation
MalwareZeroCleare

ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.