ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1559.001×

18 examples

TechniqueUsed byProcedure example
T1559.001
Component Object Model
MalwareTrickBot

TrickBot used COM to setup scheduled task for persistence.

T1559.001
Component Object Model
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

T1559.001
Component Object Model
MalwareUrsnif

Ursnif droppers have used COM objects to execute the malware's full executable payload.

T1559.001
Component Object Model
MalwareSTATICPLUGIN

STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file.

T1559.001
Component Object Model
MalwareInvisiMole

InvisiMole can use the ITaskService, ITaskDefinition and ITaskSettings COM interfaces to schedule a task.

T1559.001
Component Object Model
MalwareCLAIMLOADER

CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface.

T1559.001
Component Object Model
MalwareNeoichor

Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2.

T1559.001
Component Object Model
MalwareRaspberry Robin

Raspberry Robin creates an elevated COM object for CMLuaUtil and uses this to set a registry value that points to the malicious LNK file during execution.

T1559.001
Component Object Model
MalwareRustyWater

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

T1559.001
Component Object Model
MalwareDarkTortilla

DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1559.001
Component Object Model
MalwareMilan

Milan can use a COM component to generate scheduled tasks.

T1559.001
Component Object Model
MalwareRamsay

Ramsay can use the Windows COM API to schedule tasks and maintain persistence.

T1559.001
Component Object Model
MalwareFunnyDream

FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms.

T1559.001
Component Object Model
MalwarePOWERSTATS

POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts.

T1559.001
Component Object Model
MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

T1559.001
Component Object Model
MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

T1559.001
Component Object Model
ToolSILENTTRINITY

SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.