ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1554×

19 examples

TechniqueUsed byProcedure example
T1554
Compromise Host Software Binary
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset.

T1554
Compromise Host Software Binary
MalwareBUSHWALK

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
MalwareBOLDMOVE

BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades.

T1554
Compromise Host Software Binary
MalwareBonadan

Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1554
Compromise Host Software Binary
MalwareLIGHTWIRE

LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution.

T1554
Compromise Host Software Binary
MalwareThiefQuest

ThiefQuest searches through the /Users/ folder looking for executable files. For each executable, ThiefQuest prepends a copy of itself to the beginning of the file. When the file is executed, the ThiefQuest code is executed first. ThiefQuest creates a hidden file, copies the original target executable to the file, then executes the new hidden file to maintain the appearance of normal behavior.

T1554
Compromise Host Software Binary
MalwareGlassWorm

GlassWorm can modify hardware wallet applications.

T1554
Compromise Host Software Binary
MalwareKobalos

Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems.

T1554
Compromise Host Software Binary
MalwareWARPWIRE

WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
MalwareFRAMESTING

FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.`

T1554
Compromise Host Software Binary
MalwareWIREFIRE

WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution.

T1554
Compromise Host Software Binary
MalwareKessel

Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1554
Compromise Host Software Binary
MalwarePHASEJAM

PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided.

T1554
Compromise Host Software Binary
MalwareBFG Agonizer

BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use.

T1554
Compromise Host Software Binary
MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1554
Compromise Host Software Binary
MalwareXCSSET

XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules.

T1554
Compromise Host Software Binary
MalwareIndustroyer

Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism.

T1554
Compromise Host Software Binary
MalwareSLOWPULSE

SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files.

T1554
Compromise Host Software Binary
MalwareMini Shai-Hulud

Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.