Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1529 System Shutdown/Reboot |
MalwareAcidRain | AcidRain reboots the target system once the various wiping processes are complete. |
| T1529 System Shutdown/Reboot |
MalwareAvosLocker | AvosLocker’s Linux variant has terminated ESXi virtual machines. |
| T1529 System Shutdown/Reboot |
MalwareOlympic Destroyer | Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings. |
| T1529 System Shutdown/Reboot |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system. |
| T1529 System Shutdown/Reboot |
MalwareShrinkLocker | ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users. |
| T1529 System Shutdown/Reboot |
MalwareApostle | Apostle reboots the victim machine following wiping and related activity. |
| T1529 System Shutdown/Reboot |
MalwareWhisperGate | WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag. |
| T1529 System Shutdown/Reboot |
MalwareAcidPour | AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain. |
| T1529 System Shutdown/Reboot |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| T1529 System Shutdown/Reboot |
MalwareDCSrv | DCSrv has a function to sleep for two hours before rebooting the system. |
| T1529 System Shutdown/Reboot |
MalwareNotPetya | NotPetya will reboot the system one hour after infection. |
| T1529 System Shutdown/Reboot |
MalwareLockerGoga | LockerGoga has been observed shutting down infected systems. |
| T1529 System Shutdown/Reboot |
MalwareMultiLayer Wiper | MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery. |
| T1529 System Shutdown/Reboot |
MalwareDarkGate | DarkGate has used the `shutdown`command to shut down and/or restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareLatrodectus | Latrodectus has the ability to restart compromised hosts. |
| T1529 System Shutdown/Reboot |
MalwareShamoon | Shamoon will reboot the infected system once the wiping functionality has been completed. |
| T1529 System Shutdown/Reboot |
MalwareBlack Basta | Black Basta has used `ShellExecuteA` to shut down and restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareXLoader | XLoader can initiate a system reboot or shutdown. |
| T1529 System Shutdown/Reboot |
MalwareHermeticWiper | HermeticWiper can initiate a system shutdown. |
| T1529 System Shutdown/Reboot |
MalwareLookBack | LookBack can shutdown and reboot the victim machine. |
| T1529 System Shutdown/Reboot |
MalwareBFG Agonizer | BFG Agonizer uses elevated privileges to call |
| T1529 System Shutdown/Reboot |
MalwareMaze | Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM. |
| T1529 System Shutdown/Reboot |
MalwareKillDisk | KillDisk attempts to reboot the machine by terminating specific processes. |
| T1529 System Shutdown/Reboot |
MalwareQilin | Qilin can initiate a reboot of the backup server to hinder recovery. |
| T1529 System Shutdown/Reboot |
ToolRemcos | Remcos can shutdown and restart remote devices. |
| T1529 System Shutdown/Reboot |
MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.