Real-world descriptions of how a group, tool or campaign used a technique.
53 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.002 Code Signing |
MalwareTrickBot | TrickBot has come with a signed downloader component. |
| T1553.002 Code Signing |
MalwareBLINDINGCAN | BLINDINGCAN has been signed with code-signing certificates such as CodeRipper. |
| T1553.002 Code Signing |
MalwareStuxnet | Stuxnet used a digitally signed driver with a compromised Realtek certificate. |
| T1553.002 Code Signing |
MalwarePAKLOG | PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading. |
| T1553.002 Code Signing |
MalwareStrongPity | StrongPity has been signed with self-signed certificates. |
| T1553.002 Code Signing |
MalwareJanicab | Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions. |
| T1553.002 Code Signing |
MalwareTONESHELL | TONESHELL has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
MalwareEcipekac | Ecipekac has used a valid, legitimate digital signature to evade detection. |
| T1553.002 Code Signing |
MalwareBOOKWORM | BOOKWORM has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
MalwareSTATICPLUGIN | STATICPLUGIN has been signed with a valid Certificate Authority(CA) to circumvent endpoint defenses. |
| T1553.002 Code Signing |
MalwareGreyEnergy | GreyEnergy digitally signs the malware with a code-signing certificate. |
| T1553.002 Code Signing |
MalwarePUBLOAD | PUBLOAD has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate. |
| T1553.002 Code Signing |
MalwareBOOSTWRITE | BOOSTWRITE has been signed by a valid CA. |
| T1553.002 Code Signing |
MalwareSpicyOmelette | SpicyOmelette has been signed with valid digital certificates. |
| T1553.002 Code Signing |
MalwareLockerGoga | LockerGoga has been signed with stolen certificates in order to make it look more legitimate. |
| T1553.002 Code Signing |
MalwareAnchor | Anchor has been signed with valid certificates to evade detection by security tools. |
| T1553.002 Code Signing |
MalwareSplatDropper | SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1553.002 Code Signing |
MalwareLumma Stealer | Lumma Stealer has used valid code signing digital certificates from ConsolHQ LTD and Verandah Green Limited to appear legitimate. |
| T1553.002 Code Signing |
MalwareEpic | Turla has used valid digital certificates from Sysprint AG to sign its Epic dropper. |
| T1553.002 Code Signing |
MalwareGazer | Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd." |
| T1553.002 Code Signing |
MalwareMetamorfo | Metamorfo has digitally signed executables using AVAST Software certificates. |
| T1553.002 Code Signing |
MalwareBandook | Bandook was signed with valid Certum certificates. |
| T1553.002 Code Signing |
MalwarePipeMon | PipeMon, its installer, and tools are signed with stolen code-signing certificates. |
| T1553.002 Code Signing |
MalwareRedLine Stealer | RedLine Stealer has used both valid certificates and self-signed digital certificates to appear legitimate. |
| T1553.002 Code Signing |
MalwareBlack Basta | The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives. |
| T1553.002 Code Signing |
MalwareRTM | RTM samples have been signed with a code-signing certificates. |
| T1553.002 Code Signing |
MalwareStrelaStealer | StrelaStealer variants have used valid code signing certificates. |
| T1553.002 Code Signing |
MalwareGoBear | GoBear uses stolen legitimate code signing certificates for defense evasion. |
| T1553.002 Code Signing |
MalwareBazar | Bazar has been signed with fake certificates including those appearing to be from VB CORPORATE PTY. LTD. |
| T1553.002 Code Signing |
MalwareCorKLOG | CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1553.002 Code Signing |
MalwareHermeticWiper | The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd. |
| T1553.002 Code Signing |
MalwareCobalt Strike | Cobalt Strike can use self signed Java applets to execute signed applet attacks. |
| T1553.002 Code Signing |
MalwareSUNBURST | SUNBURST was digitally signed by SolarWinds from March - May 2020. |
| T1553.002 Code Signing |
MalwareDaserf | Some Daserf samples were signed with a stolen digital certificate. |
| T1553.002 Code Signing |
MalwareMacMa | MacMa has been delivered using ad hoc Apple Developer code signing certificates. |
| T1553.002 Code Signing |
MalwareROADSWEEP | ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC. |
| T1553.002 Code Signing |
MalwareMore_eggs | More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell. |
| T1553.002 Code Signing |
MalwareSysUpdate | SysUpdate has been signed with stolen digital certificates. |
| T1553.002 Code Signing |
MalwareBackConfig | BackConfig has been signed with self signed digital certificates mimicking a legitimate software company. |
| T1553.002 Code Signing |
MalwareNerex | Nerex drops a signed Microsoft DLL to disk. |
| T1553.002 Code Signing |
MalwareClop | Clop can use code signing to evade detection. |
| T1553.002 Code Signing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate. |
| T1553.002 Code Signing |
MalwareTroll Stealer | Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates. |
| T1553.002 Code Signing |
MalwareEbury | Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems. |
| T1553.002 Code Signing |
MalwareChChes | ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked. |
| T1553.002 Code Signing |
MalwareAppleJeus | AppleJeus has used a valid digital signature from Sectigo to appear legitimate. |
| T1553.002 Code Signing |
MalwareQakBot | QakBot can use signed loaders to evade detection. |
| T1553.002 Code Signing |
MalwareHelminth | Helminth samples have been signed with legitimate, compromised code signing certificates owned by software company AI Squared. |
| T1553.002 Code Signing |
MalwareHermeticWizard | HermeticWizard has been signed by valid certificates assigned to Hermetica Digital. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.