Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1222.002 Linux and Mac Permissions |
MalwareCOATHANGER | COATHANGER will set the GID of `httpsd` to 90 when infected. |
| T1222.002 Linux and Mac Permissions |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to modify file permissions. |
| T1222.002 Linux and Mac Permissions |
MalwareBundlore | Bundlore changes the permissions of a payload using the command |
| T1222.002 Linux and Mac Permissions |
MalwareBlack Basta | The Black Basta binary can use `chmod` to gain full permissions to targeted files. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via |
| T1222.002 Linux and Mac Permissions |
MalwarePenquin | Penquin can add the executable flag to a downloaded file. |
| T1222.002 Linux and Mac Permissions |
MalwareKinsing | Kinsing has used chmod to modify permissions on key files for use. |
| T1222.002 Linux and Mac Permissions |
MalwareXCSSET | XCSSET uses the |
| T1222.002 Linux and Mac Permissions |
MalwareDRYHOOK | DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1222.002 Linux and Mac Permissions |
MalwareOSX/Shlayer | OSX/Shlayer can use the |
| T1222.002 Linux and Mac Permissions |
MalwareDok | Dok gives all users execute permissions for the application using the command |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.