ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1222.002×

11 examples

TechniqueUsed byProcedure example
T1222.002
Linux and Mac Permissions
MalwareCOATHANGER

COATHANGER will set the GID of `httpsd` to 90 when infected.

T1222.002
Linux and Mac Permissions
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to modify file permissions.

T1222.002
Linux and Mac Permissions
MalwareBundlore

Bundlore changes the permissions of a payload using the command chmod -R 755.

T1222.002
Linux and Mac Permissions
MalwareBlack Basta

The Black Basta binary can use `chmod` to gain full permissions to targeted files.

T1222.002
Linux and Mac Permissions
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via chmod.

T1222.002
Linux and Mac Permissions
MalwarePenquin

Penquin can add the executable flag to a downloaded file.

T1222.002
Linux and Mac Permissions
MalwareKinsing

Kinsing has used chmod to modify permissions on key files for use.

T1222.002
Linux and Mac Permissions
MalwareXCSSET

XCSSET uses the chmod +x command to grant executable permissions to the malicious file.

T1222.002
Linux and Mac Permissions
MalwareDRYHOOK

DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.

T1222.002
Linux and Mac Permissions
MalwareOSX/Shlayer

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1222.002
Linux and Mac Permissions
MalwareDok

Dok gives all users execute permissions for the application using the command chmod +x /Users/Shared/AppStore.app.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.