Real-world descriptions of how a group, tool or campaign used a technique.
45 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1480 Execution Guardrails |
MalwareTorisma | Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list. |
| T1480 Execution Guardrails |
MalwareStuxnet | Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met. |
| T1480 Execution Guardrails |
MalwareRansomHub | RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration. |
| T1480 Execution Guardrails |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region. |
| T1480 Execution Guardrails |
MalwareROAMINGHOUSE | ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected. |
| T1480 Execution Guardrails |
MalwareTONESHELL | TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`. |
| T1480 Execution Guardrails |
MalwareEnvyScout | EnvyScout can call |
| T1480 Execution Guardrails |
MalwareBOLDMOVE | BOLDMOVE verifies it is executing from a specific path during execution. |
| T1480 Execution Guardrails |
MalwareSystemBC | SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not. |
| T1480 Execution Guardrails |
MalwareShrinkLocker | ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1480 Execution Guardrails |
MalwareApostle | Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| T1480 Execution Guardrails |
MalwareRaspberry Robin | Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script. |
| T1480 Execution Guardrails |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.” |
| T1480 Execution Guardrails |
MalwareLightSpy | On macOS, LightSpy checks the existence of a process identification number (PID) file, `/Users/Shared/irc.pid`, to verify if LightSpy is currently running. |
| T1480 Execution Guardrails |
MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| T1480 Execution Guardrails |
MalwareExbyte | Exbyte checks for the presence of a configuration file before completing execution. |
| T1480 Execution Guardrails |
MalwareLunarLoader | LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets. |
| T1480 Execution Guardrails |
MalwarePureCrypter | PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions. |
| T1480 Execution Guardrails |
MalwareDarkGate | DarkGate uses per-victim links for hosting malicious archives, such as ZIP files, in services such as SharePoint to prevent other entities from retrieving them. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1480 Execution Guardrails |
MalwareLODEINFO | LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine. |
| T1480 Execution Guardrails |
MalwareSagerunex | Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory. |
| T1480 Execution Guardrails |
MalwareGlassWorm | GlassWorm has utilized logic to avoid executing on Russian based devices. |
| T1480 Execution Guardrails |
MalwareRedLine Stealer | RedLine Stealer has built in settings to not operate based on geolocation or country of the victim host. |
| T1480 Execution Guardrails |
MalwareBPFDoor | BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time. |
| T1480 Execution Guardrails |
MalwareAkira _v2 | Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined. |
| T1480 Execution Guardrails |
MalwareBlackByte Ransomware | BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1480 Execution Guardrails |
MalwareVaporRage | VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found. |
| T1480 Execution Guardrails |
MalwareHiddenFace | HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found. |
| T1480 Execution Guardrails |
MalwareLockBit 2.0 | LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
| T1480 Execution Guardrails |
MalwareNativeZone | NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1480 Execution Guardrails |
MalwareSUNSPOT | SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values. |
| T1480 Execution Guardrails |
MalwareBoomBox | BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found. |
| T1480 Execution Guardrails |
MalwareDEADEYE | DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain. |
| T1480 Execution Guardrails |
MalwareStealBit | StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger. |
| T1480 Execution Guardrails |
MalwareQilin | Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution. |
| T1480 Execution Guardrails |
MalwareLazyWiper | LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`. |
| T1480 Execution Guardrails |
MalwareBitPaymer | BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| T1480 Execution Guardrails |
MalwareSmall Sieve | Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line. |
| T1480 Execution Guardrails |
Toolevilginx2 | evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure. |
| T1480 Execution Guardrails |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube. |
| T1480 Execution Guardrails |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel. |
| T1480 Execution Guardrails |
MalwareCanisterWorm | CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.