ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1134.001×

17 examples

TechniqueUsed byProcedure example
T1134.001
Token Impersonation/Theft
MalwareStuxnet

Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager.

T1134.001
Token Impersonation/Theft
MalwareHavoc

Havoc has a module capable of token impersonation.

T1134.001
Token Impersonation/Theft
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

T1134.001
Token Impersonation/Theft
MalwareBADHATCH

BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token.

T1134.001
Token Impersonation/Theft
MalwareOkrum

Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API.

T1134.001
Token Impersonation/Theft
MalwareSiloscape

Siloscape impersonates the main thread of CExecSvc.exe by calling NtImpersonateThread.

T1134.001
Token Impersonation/Theft
MalwareFooder

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

T1134.001
Token Impersonation/Theft
MalwareLP-Notes

LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API.

T1134.001
Token Impersonation/Theft
MalwareShamoon

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

T1134.001
Token Impersonation/Theft
MalwareTarrask

Tarrask leverages token theft to obtain `lsass.exe` security permissions.

T1134.001
Token Impersonation/Theft
MalwareFinFisher

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

T1134.001
Token Impersonation/Theft
MalwareREvil

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.

T1134.001
Token Impersonation/Theft
MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

T1134.001
Token Impersonation/Theft
ToolSILENTTRINITY

SILENTTRINITY can find a process owned by a specific user and impersonate the associated token.

T1134.001
Token Impersonation/Theft
ToolPupy

Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.