ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1543.001×

22 examples

TechniqueUsed byProcedure example
T1543.001
Launch Agent
MalwareInvisibleFerret

InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”.

T1543.001
Launch Agent
MalwaremacOS.OSAMiner

macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder.

T1543.001
Launch Agent
MalwareNETWIRE

NETWIRE can use launch agents for persistence.

T1543.001
Launch Agent
MalwareDacls

Dacls can establish persistence via a LaunchAgent.

T1543.001
Launch Agent
MalwareCuckoo Stealer

Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.

T1543.001
Launch Agent
MalwareFruitFly

FruitFly persists via a Launch Agent.

T1543.001
Launch Agent
MalwareKeydnap

Keydnap uses a Launch Agent to persist.

T1543.001
Launch Agent
MalwareGreen Lambert

Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to true, ensuring the `com.apple.GrowlHelper.plist` file runs every time a user logs in.

T1543.001
Launch Agent
MalwareThiefQuest

ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the ~/Library/LaunchAgents/ folder and configured with the path to the persistent binary located in the ~/Library/ folder.

T1543.001
Launch Agent
MalwareBundlore

Bundlore can persist via a LaunchAgent.

T1543.001
Launch Agent
MalwareGlassWorm

GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`.

T1543.001
Launch Agent
MalwareCrossRAT

CrossRAT creates a Launch Agent on macOS.

T1543.001
Launch Agent
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchAgents.

T1543.001
Launch Agent
MalwareCalisto

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

T1543.001
Launch Agent
MalwareMacMa

MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user.

T1543.001
Launch Agent
MalwareProton

Proton persists via Launch Agent.

T1543.001
Launch Agent
MalwareCoinTicker

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

T1543.001
Launch Agent
MalwareCookieMiner

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

T1543.001
Launch Agent
MalwareKomplex

The Komplex trojan creates a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist with launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist.

T1543.001
Launch Agent
MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

T1543.001
Launch Agent
MalwareMacSpy

MacSpy persists via a Launch Agent.

T1543.001
Launch Agent
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.