ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1489×

47 examples

TechniqueUsed byProcedure example
T1489
Service Stop
MalwareEKANS

EKANS stops database, data backup solution, antivirus, and ICS-related processes.

T1489
Service Stop
MalwareBRICKSTORM

BRICKSTORM has terminated an existing process to ensure that its own new process can execute.

T1489
Service Stop
MalwareAvosLocker

AvosLocker has terminated specific processes before encryption.

T1489
Service Stop
MalwareRobbinHood

RobbinHood stops 181 Windows services on the system before beginning the encryption process.

T1489
Service Stop
MalwareRansomHub

RansomHub has the ability to terminate specified services.

T1489
Service Stop
MalwarePrestige

Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`.

T1489
Service Stop
MalwareInvisibleFerret

InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes.

T1489
Service Stop
MalwareHannotog

Hannotog can stop Windows services.

T1489
Service Stop
MalwareMedusa Ransomware

Medusa Ransomware has the capability to terminate services related to backups, security, databases, communication, filesharing and websites. Medusa Ransomware has also utilized the `taskkill /F /IM <process> /T` command to stop targeted processes and `net stop <process>` command to stop designated services.

T1489
Service Stop
MalwareOlympic Destroyer

Olympic Destroyer uses the API call ChangeServiceConfigW to disable all services on the affected system.

T1489
Service Stop
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can terminate running services.

T1489
Service Stop
MalwareConti

Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of net stop.

T1489
Service Stop
MalwareMegazord

Megazord has the ability to terminate a list of services and processes.

T1489
Service Stop
MalwareDiavol

Diavol will terminate services using the Service Control Manager (SCM) API.

T1489
Service Stop
MalwareBlackCat

BlackCat has the ability to stop VM services on compromised networks.

T1489
Service Stop
MalwareRagnar Locker

Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted.

T1489
Service Stop
MalwareAvaddon

Avaddon looks for and attempts to stop database processes.

T1489
Service Stop
MalwareCheerscrypt

Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`.

T1489
Service Stop
MalwareBabuk

Babuk can stop specific services related to backups.

T1489
Service Stop
MalwareCuba

Cuba has a hardcoded list of services and processes to terminate.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1489
Service Stop
MalwareNetwalker

Netwalker can terminate system processes and services, some of which relate to backup software.

T1489
Service Stop
MalwareWannaCry

WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.

T1489
Service Stop
MalwarePay2Key

Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service.

T1489
Service Stop
MalwareRoyal

Royal can use `RmShutDown` to kill applications and services using the resources that are targeted for encryption.

T1489
Service Stop
MalwareEmbargo

Embargo has terminated active processes and services based on a hardcoded list using the `CloseServiceHandle()` function. Embargo has also leveraged MS4Killer to terminate processes contained in an embedded list of security software process names that were XOR-encrypted.

T1489
Service Stop
MalwareMegaCortex

MegaCortex can stop and disable services on the system.

T1489
Service Stop
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

T1489
Service Stop
MalwareRyuk

Ryuk has called kill.bat for stopping services, disabling services and killing processes.

T1489
Service Stop
MalwareHermeticWiper

HermeticWiper has the ability to stop the Volume Shadow Copy service.

T1489
Service Stop
MalwarePysa

Pysa can stop services and processes.

T1489
Service Stop
MalwareLockBit 2.0

LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes.

T1489
Service Stop
MalwareHotCroissant

HotCroissant has the ability to stop services on the infected host.

T1489
Service Stop
MalwareREvil

REvil has the capability to stop services and kill processes.

T1489
Service Stop
MalwareROADSWEEP

ROADSWEEP can disable critical services and processes.

T1489
Service Stop
MalwareLookBack

LookBack can kill processes and delete services.

T1489
Service Stop
MalwarePHASEJAM

PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances.

T1489
Service Stop
MalwareClop

Clop can kill several processes and services related to backups and security solutions.

T1489
Service Stop
MalwareMeteor

Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`.

T1489
Service Stop
MalwareMaze

Maze has stopped SQL services to ensure it can encrypt any database.

T1489
Service Stop
MalwareVIRTUALPITA

VIRTUALPITA can start and stop the `vmsyslogd` service.

T1489
Service Stop
MalwareKillDisk

KillDisk terminates various processes to get the user to reboot the victim machine.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1489
Service Stop
MalwareIndustroyer

Industroyer’s data wiper module writes zeros into the registry keys in SYSTEM\CurrentControlSet\Services to render a system inoperable.

T1489
Service Stop
MalwareDRYHOOK

DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file.

T1489
Service Stop
MalwareINC Ransomware

INC Ransomware can issue a command to kill a process on compromised hosts.

T1489
Service Stop
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to stop processes and services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.