ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1496.001×

9 examples

TechniqueUsed byProcedure example
T1496.001
Compute Hijacking
MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

T1496.001
Compute Hijacking
MalwareSkidmap

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

T1496.001
Compute Hijacking
MalwareBonadan

Bonadan can download an additional module which has a cryptocurrency mining extension.

T1496.001
Compute Hijacking
MalwareLucifer

Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.

T1496.001
Compute Hijacking
MalwareDarkGate

DarkGate can deploy follow-on cryptocurrency mining payloads.

T1496.001
Compute Hijacking
MalwareKinsing

Kinsing has created and run a Bitcoin cryptocurrency miner.

T1496.001
Compute Hijacking
MalwareCookieMiner

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

T1496.001
Compute Hijacking
MalwareLoudMiner

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

T1496.001
Compute Hijacking
ToolImminent Monitor

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.