ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1559×

16 examples

TechniqueUsed byProcedure example
T1559
Inter-Process Communication
MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

T1559
Inter-Process Communication
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID.

T1559
Inter-Process Communication
MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

T1559
Inter-Process Communication
MalwareTONESHELL

TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr.

T1559
Inter-Process Communication
MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

T1559
Inter-Process Communication
MalwareHyperStack

HyperStack can connect to the IPC$ share on remote machines.

T1559
Inter-Process Communication
MalwareRaspberry Robin

Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory.

T1559
Inter-Process Communication
MalwareUroburos

Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes.

T1559
Inter-Process Communication
MalwareOilBooster

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

T1559
Inter-Process Communication
MalwareCyclops Blink

Cyclops Blink has the ability to create a pipe to enable inter-process communication.

T1559
Inter-Process Communication
MalwareROADSWEEP

ROADSWEEP can pipe command output to a targeted process.

T1559
Inter-Process Communication
MalwareStealBit

StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner.

T1559
Inter-Process Communication
MalwareSPAWNCHIMERA

SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process.

T1559
Inter-Process Communication
MalwarePITSTOP

PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`.

T1559
Inter-Process Communication
MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

T1559
Inter-Process Communication
MalwareMini Shai-Hulud

Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.