Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1489 Service Stop |
MalwareEKANS | EKANS stops database, data backup solution, antivirus, and ICS-related processes. |
| T1489 Service Stop |
MalwareBRICKSTORM | BRICKSTORM has terminated an existing process to ensure that its own new process can execute. |
| T1489 Service Stop |
MalwareAvosLocker | AvosLocker has terminated specific processes before encryption. |
| T1489 Service Stop |
MalwareRobbinHood | RobbinHood stops 181 Windows services on the system before beginning the encryption process. |
| T1489 Service Stop |
MalwareRansomHub | RansomHub has the ability to terminate specified services. |
| T1489 Service Stop |
MalwarePrestige | Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`. |
| T1489 Service Stop |
MalwareInvisibleFerret | InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes. |
| T1489 Service Stop |
MalwareHannotog | Hannotog can stop Windows services. |
| T1489 Service Stop |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services. |
| T1489 Service Stop |
MalwareOlympic Destroyer | Olympic Destroyer uses the API call |
| T1489 Service Stop |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can terminate running services. |
| T1489 Service Stop |
MalwareConti | Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of |
| T1489 Service Stop |
MalwareMegazord | Megazord has the ability to terminate a list of services and processes. |
| T1489 Service Stop |
MalwareDiavol | Diavol will terminate services using the Service Control Manager (SCM) API. |
| T1489 Service Stop |
MalwareBlackCat | BlackCat has the ability to stop VM services on compromised networks. |
| T1489 Service Stop |
MalwareRagnar Locker | Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted. |
| T1489 Service Stop |
MalwareAvaddon | Avaddon looks for and attempts to stop database processes. |
| T1489 Service Stop |
MalwareCheerscrypt | Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`. |
| T1489 Service Stop |
MalwareBabuk | Babuk can stop specific services related to backups. |
| T1489 Service Stop |
MalwareCuba | Cuba has a hardcoded list of services and processes to terminate. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1489 Service Stop |
MalwareNetwalker | Netwalker can terminate system processes and services, some of which relate to backup software. |
| T1489 Service Stop |
MalwareWannaCry | WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores. |
| T1489 Service Stop |
MalwarePay2Key | Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service. |
| T1489 Service Stop |
MalwareRoyal | Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption. |
| T1489 Service Stop |
MalwareEmbargo | Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted. |
| T1489 Service Stop |
MalwareMegaCortex | MegaCortex can stop and disable services on the system. |
| T1489 Service Stop |
MalwareAkira _v2 | Akira _v2 can stop running virtual machines. |
| T1489 Service Stop |
MalwareRyuk | Ryuk has called |
| T1489 Service Stop |
MalwareHermeticWiper | HermeticWiper has the ability to stop the Volume Shadow Copy service. |
| T1489 Service Stop |
MalwarePysa | Pysa can stop services and processes. |
| T1489 Service Stop |
MalwareLockBit 2.0 | LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes. |
| T1489 Service Stop |
MalwareHotCroissant | HotCroissant has the ability to stop services on the infected host. |
| T1489 Service Stop |
MalwareREvil | REvil has the capability to stop services and kill processes. |
| T1489 Service Stop |
MalwareROADSWEEP | ROADSWEEP can disable critical services and processes. |
| T1489 Service Stop |
MalwareLookBack | LookBack can kill processes and delete services. |
| T1489 Service Stop |
MalwarePHASEJAM | PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances. |
| T1489 Service Stop |
MalwareClop | Clop can kill several processes and services related to backups and security solutions. |
| T1489 Service Stop |
MalwareMeteor | Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`. |
| T1489 Service Stop |
MalwareMaze | Maze has stopped SQL services to ensure it can encrypt any database. |
| T1489 Service Stop |
MalwareVIRTUALPITA | VIRTUALPITA can start and stop the `vmsyslogd` service. |
| T1489 Service Stop |
MalwareKillDisk | KillDisk terminates various processes to get the user to reboot the victim machine. |
| T1489 Service Stop |
MalwareQilin | Qilin can terminate specific services on compromised hosts. |
| T1489 Service Stop |
MalwareIndustroyer | Industroyer’s data wiper module writes zeros into the registry keys in |
| T1489 Service Stop |
MalwareDRYHOOK | DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file. |
| T1489 Service Stop |
MalwareINC Ransomware | INC Ransomware can issue a command to kill a process on compromised hosts. |
| T1489 Service Stop |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to stop processes and services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.