ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1480.002×

18 examples

TechniqueUsed byProcedure example
T1480.002
Mutual Exclusion
MalwareTONESHELL

TONESHELL has created a mutex to avoid duplicate execution.

T1480.002
Mutual Exclusion
MalwareCLAIMLOADER

CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running.

T1480.002
Mutual Exclusion
MalwarePlugX

PlugX has leveraged a mutex in its infection process.

T1480.002
Mutual Exclusion
MalwarePureCrypter

PureCrypter code contains a global mutex.

T1480.002
Mutual Exclusion
MalwareLockBit 3.0

LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance.

T1480.002
Mutual Exclusion
MalwareGazer

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareEmbargo

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1480.002
Mutual Exclusion
MalwareBPFDoor

When executed, BPFDoor attempts to create and lock a runtime file, `/var/run/initd.lock`, and exits if it fails using the specified file, resulting in a makeshift mutex.

T1480.002
Mutual Exclusion
MalwareBlack Basta

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

T1480.002
Mutual Exclusion
MalwareStrelaStealer

StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection.

T1480.002
Mutual Exclusion
MalwareHiddenFace

HiddenFace can create a mutex to ensure only one instance is running at a time.

T1480.002
Mutual Exclusion
MalwareREvil

REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.

T1480.002
Mutual Exclusion
MalwarePoisonIvy

PoisonIvy creates a mutex using either a custom or default value.

T1480.002
Mutual Exclusion
MalwareSUNSPOT

SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareGrimAgent

GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`.

T1480.002
Mutual Exclusion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`.

T1480.002
Mutual Exclusion
MalwareTroll Stealer

Troll Stealer creates a mutex during installation to prevent duplicate execution.

T1480.002
Mutual Exclusion
MalwareQilin

Qilin can create a mutex to ensure only one instance is running.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.