Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1480.002 Mutual Exclusion |
MalwareTONESHELL | TONESHELL has created a mutex to avoid duplicate execution. |
| T1480.002 Mutual Exclusion |
MalwareCLAIMLOADER | CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running. |
| T1480.002 Mutual Exclusion |
MalwarePlugX | PlugX has leveraged a mutex in its infection process. |
| T1480.002 Mutual Exclusion |
MalwarePureCrypter | PureCrypter code contains a global mutex. |
| T1480.002 Mutual Exclusion |
MalwareLockBit 3.0 | LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance. |
| T1480.002 Mutual Exclusion |
MalwareGazer | Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running. |
| T1480.002 Mutual Exclusion |
MalwareEmbargo | Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip." |
| T1480.002 Mutual Exclusion |
MalwareBPFDoor | When executed, BPFDoor attempts to create and lock a runtime file, `/var/run/initd.lock`, and exits if it fails using the specified file, resulting in a makeshift mutex. |
| T1480.002 Mutual Exclusion |
MalwareBlack Basta | Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing. |
| T1480.002 Mutual Exclusion |
MalwareStrelaStealer | StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection. |
| T1480.002 Mutual Exclusion |
MalwareHiddenFace | HiddenFace can create a mutex to ensure only one instance is running at a time. |
| T1480.002 Mutual Exclusion |
MalwareREvil | REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host. |
| T1480.002 Mutual Exclusion |
MalwarePoisonIvy | PoisonIvy creates a mutex using either a custom or default value. |
| T1480.002 Mutual Exclusion |
MalwareSUNSPOT | SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running. |
| T1480.002 Mutual Exclusion |
MalwareGrimAgent | GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`. |
| T1480.002 Mutual Exclusion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`. |
| T1480.002 Mutual Exclusion |
MalwareTroll Stealer | Troll Stealer creates a mutex during installation to prevent duplicate execution. |
| T1480.002 Mutual Exclusion |
MalwareQilin | Qilin can create a mutex to ensure only one instance is running. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.