Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1554 Compromise Host Software Binary |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset. |
| T1554 Compromise Host Software Binary |
MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareBOLDMOVE | BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| T1554 Compromise Host Software Binary |
MalwareBonadan | Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwareLIGHTWIRE | LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution. |
| T1554 Compromise Host Software Binary |
MalwareThiefQuest | ThiefQuest searches through the |
| T1554 Compromise Host Software Binary |
MalwareGlassWorm | GlassWorm can modify hardware wallet applications. |
| T1554 Compromise Host Software Binary |
MalwareKobalos | Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems. |
| T1554 Compromise Host Software Binary |
MalwareWARPWIRE | WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareFRAMESTING | FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.` |
| T1554 Compromise Host Software Binary |
MalwareWIREFIRE | WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1554 Compromise Host Software Binary |
MalwareKessel | Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwarePHASEJAM | PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided. |
| T1554 Compromise Host Software Binary |
MalwareBFG Agonizer | BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| T1554 Compromise Host Software Binary |
MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1554 Compromise Host Software Binary |
MalwareXCSSET | XCSSET uses a malicious browser application to replace the legitimate browser in order to continuously capture credentials, monitor web traffic, and download additional modules. |
| T1554 Compromise Host Software Binary |
MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| T1554 Compromise Host Software Binary |
MalwareSLOWPULSE | SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files. |
| T1554 Compromise Host Software Binary |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.