ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1529×

26 examples

TechniqueUsed byProcedure example
T1529
System Shutdown/Reboot
MalwareAcidRain

AcidRain reboots the target system once the various wiping processes are complete.

T1529
System Shutdown/Reboot
MalwareAvosLocker

AvosLocker’s Linux variant has terminated ESXi virtual machines.

T1529
System Shutdown/Reboot
MalwareOlympic Destroyer

Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings.

T1529
System Shutdown/Reboot
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system.

T1529
System Shutdown/Reboot
MalwareShrinkLocker

ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users.

T1529
System Shutdown/Reboot
MalwareApostle

Apostle reboots the victim machine following wiping and related activity.

T1529
System Shutdown/Reboot
MalwareWhisperGate

WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag.

T1529
System Shutdown/Reboot
MalwareAcidPour

AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain.

T1529
System Shutdown/Reboot
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

T1529
System Shutdown/Reboot
MalwareDCSrv

DCSrv has a function to sleep for two hours before rebooting the system.

T1529
System Shutdown/Reboot
MalwareNotPetya

NotPetya will reboot the system one hour after infection.

T1529
System Shutdown/Reboot
MalwareLockerGoga

LockerGoga has been observed shutting down infected systems.

T1529
System Shutdown/Reboot
MalwareMultiLayer Wiper

MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery.

T1529
System Shutdown/Reboot
MalwareDarkGate

DarkGate has used the `shutdown`command to shut down and/or restart the victim system.

T1529
System Shutdown/Reboot
MalwareLatrodectus

Latrodectus has the ability to restart compromised hosts.

T1529
System Shutdown/Reboot
MalwareShamoon

Shamoon will reboot the infected system once the wiping functionality has been completed.

T1529
System Shutdown/Reboot
MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

T1529
System Shutdown/Reboot
MalwareXLoader

XLoader can initiate a system reboot or shutdown.

T1529
System Shutdown/Reboot
MalwareHermeticWiper

HermeticWiper can initiate a system shutdown.

T1529
System Shutdown/Reboot
MalwareLookBack

LookBack can shutdown and reboot the victim machine.

T1529
System Shutdown/Reboot
MalwareBFG Agonizer

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

T1529
System Shutdown/Reboot
MalwareMaze

Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM.

T1529
System Shutdown/Reboot
MalwareKillDisk

KillDisk attempts to reboot the machine by terminating specific processes.

T1529
System Shutdown/Reboot
MalwareQilin

Qilin can initiate a reboot of the backup server to hinder recovery.

T1529
System Shutdown/Reboot
ToolRemcos

Remcos can shutdown and restart remote devices.

T1529
System Shutdown/Reboot
MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.