ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1543.002×

11 examples

TechniqueUsed byProcedure example
T1543.002
Systemd Service
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

T1543.002
Systemd Service
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1543.002
Systemd Service
MalwareGomir

Gomir creates a systemd service named `syslogd` for persistence.

T1543.002
Systemd Service
MalwareHildegard

Hildegard has started a monero service.

T1543.002
Systemd Service
MalwareFysbis

Fysbis has established persistence using a systemd service.

T1543.002
Systemd Service
MalwareSysUpdate

SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges.

T1543.002
Systemd Service
MalwareRIFLESPINE

RIFLESPINE can create a systemd service file for execution.

T1543.002
Systemd Service
MalwareShai-Hulud

Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls.

T1543.002
Systemd Service
ToolPupy

Pupy can be used to establish persistence using a systemd service.

T1543.002
Systemd Service
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence.

T1543.002
Systemd Service
MalwareMini Shai-Hulud

Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.