Real-world descriptions of how a group, tool or campaign used a technique.
51 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1548.002 Bypass User Account Control |
MalwareRCSession | RCSession can bypass UAC to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareBumblebee | Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges. |
| T1548.002 Bypass User Account Control |
MalwareDowndelph | Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database. |
| T1548.002 Bypass User Account Control |
MalwarePLAINTEE | An older variant of PLAINTEE performs UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareBad Rabbit | Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges. |
| T1548.002 Bypass User Account Control |
MalwareBADHATCH | BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWastedLocker | WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later. |
| T1548.002 Bypass User Account Control |
MalwareInvisiMole | InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareZeroT | Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file. |
| T1548.002 Bypass User Account Control |
MalwareRaspberry Robin | Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt. |
| T1548.002 Bypass User Account Control |
MalwareBlackCat | BlackCat can bypass UAC to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareHTTPTroy | HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command. |
| T1548.002 Bypass User Account Control |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges. |
| T1548.002 Bypass User Account Control |
MalwareBlackEnergy | BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later. |
| T1548.002 Bypass User Account Control |
MalwareShimRat | ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing. |
| T1548.002 Bypass User Account Control |
MalwareAvaddon | Avaddon bypasses UAC using the CMSTPLUA COM interface. |
| T1548.002 Bypass User Account Control |
MalwareClambling | Clambling has the ability to bypass UAC using a `passuac.dll` file. |
| T1548.002 Bypass User Account Control |
MalwareDarkGate | DarkGate uses two distinct User Account Control (UAC) bypass techniques to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 3.0 | LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. |
| T1548.002 Bypass User Account Control |
MalwareSaint Bot | Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges. |
| T1548.002 Bypass User Account Control |
MalwarePipeMon | PipeMon installer can use UAC bypass techniques to install the payload. |
| T1548.002 Bypass User Account Control |
MalwareKONNI | KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify". |
| T1548.002 Bypass User Account Control |
MalwareShamoon | Shamoon attempts to disable UAC remote restrictions by modifying the Registry. |
| T1548.002 Bypass User Account Control |
MalwareRTM | RTM can attempt to run the program as admin, then show a fake error message and a legitimate UAC bypass prompt to the user in an attempt to socially engineer the user into escalating privileges. |
| T1548.002 Bypass User Account Control |
MalwareGrandoreiro | Grandoreiro can bypass UAC by registering as the default handler for .MSC files. |
| T1548.002 Bypass User Account Control |
MalwareSakula | Sakula contains UAC bypass code for both 32- and 64-bit systems. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 2.0 | LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`. |
| T1548.002 Bypass User Account Control |
MalwareFinFisher | FinFisher performs UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareCobalt Strike | Cobalt Strike can use a number of known techniques to bypass Windows UAC. |
| T1548.002 Bypass User Account Control |
MalwareRamsay | |
| T1548.002 Bypass User Account Control |
MalwareLokibot | Lokibot has utilized multiple techniques to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWinnti for Windows | Winnti for Windows can use a variant of the sysprep UAC bypass. |
| T1548.002 Bypass User Account Control |
MalwareKOCTOPUS | KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe. |
| T1548.002 Bypass User Account Control |
MalwareQilin | Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context. |
| T1548.002 Bypass User Account Control |
MalwareAppleJeus | AppleJeus has presented the user with a UAC prompt to elevate privileges while installing. |
| T1548.002 Bypass User Account Control |
MalwareGelsemium | Gelsemium can bypass UAC to elevate process privileges on a compromised host. |
| T1548.002 Bypass User Account Control |
MalwareAutoIt backdoor | AutoIt backdoor attempts to escalate privileges by bypassing User Access Control. |
| T1548.002 Bypass User Account Control |
MalwareH1N1 | H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe). |
| T1548.002 Bypass User Account Control |
MalwareBitPaymer | BitPaymer can suppress UAC prompts by setting the |
| T1548.002 Bypass User Account Control |
MalwareUPPERCUT | UPPERCUT contains functionality to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWarzoneRAT | WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module. |
| T1548.002 Bypass User Account Control |
ToolUACMe | UACMe contains many methods for bypassing Windows User Account Control on multiple versions of the operating system. |
| T1548.002 Bypass User Account Control |
ToolSliver | Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems. |
| T1548.002 Bypass User Account Control |
ToolSILENTTRINITY | SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension. |
| T1548.002 Bypass User Account Control |
ToolEmpire | Empire includes various modules to attempt to bypass UAC for escalation of privileges. |
| T1548.002 Bypass User Account Control |
ToolPoshC2 | PoshC2 can utilize multiple methods to bypass UAC. |
| T1548.002 Bypass User Account Control |
ToolCSPY Downloader | CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges. |
| T1548.002 Bypass User Account Control |
ToolRemcos | Remcos has a command for UAC bypassing. |
| T1548.002 Bypass User Account Control |
ToolKoadic | Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`. |
| T1548.002 Bypass User Account Control |
ToolPupy | Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.