ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1622×

24 examples

TechniqueUsed byProcedure example
T1622
Debugger Evasion
MalwarePikabot

Pikabot features several methods to evade debugging by analysts, including checks for active debuggers, the use of breakpoints during execution, and checking various system information items such as system memory and the number of processors.

T1622
Debugger Evasion
MalwareBumblebee

Bumblebee can search for tools used in static analysis.

T1622
Debugger Evasion
MalwareTONESHELL

TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger.

T1622
Debugger Evasion
MalwarePUBLOAD

PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions.

T1622
Debugger Evasion
MalwareMafalda

Mafalda can search for debugging tools on a compromised host.

T1622
Debugger Evasion
MalwareRaspberry Robin

Raspberry Robin leverages anti-debugging mechanisms through the use of ThreadHideFromDebugger.

T1622
Debugger Evasion
MalwareRustyWater

RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts.

T1622
Debugger Evasion
MalwareDRATzarus

DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim.

T1622
Debugger Evasion
MalwareDarkTortilla

DarkTortilla can detect debuggers by using functions such as `DebuggerIsAttached` and `DebuggerIsLogging`. DarkTortilla can also detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active.

T1622
Debugger Evasion
MalwareROKRAT

ROKRAT can check for debugging tools.

T1622
Debugger Evasion
MalwarePlugX

PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.

T1622
Debugger Evasion
MalwareLumma Stealer

Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”.

T1622
Debugger Evasion
MalwarePureCrypter

PureCrypter has the ability to call `CheckRemoteDebuggerPresent`.

T1622
Debugger Evasion
MalwareDarkGate

DarkGate checks the BeingDebugged flag in the PEB structure during execution to identify if the malware is being debugged.

T1622
Debugger Evasion
MalwareLockBit 3.0

LockBit 3.0 can check heap memory parameters for indications of a debugger and stop the flow of events to the attached debugger in order to hinder dynamic analysis.

T1622
Debugger Evasion
MalwareThiefQuest

ThiefQuest uses a function named is_debugging to perform anti-debugging logic. The function invokes sysctl checking the returned value of P_TRACED. ThiefQuest also calls ptrace with the PTRACE_DENY_ATTACH flag to prevent debugging.

T1622
Debugger Evasion
MalwareLatrodectus

Latrodectus has the ability to check for the presence of debuggers.

T1622
Debugger Evasion
MalwareSaint Bot

Saint Bot has used `is_debugger_present` as part of its environmental checks.

T1622
Debugger Evasion
MalwareBlack Basta

The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present.

T1622
Debugger Evasion
MalwareStrelaStealer

StrelaStealer variants include functionality to identify and evade debuggers.

T1622
Debugger Evasion
MalwareXLoader

XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed.

T1622
Debugger Evasion
MalwareANELLDR

ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged.

T1622
Debugger Evasion
MalwareStealBit

StealBit can detect it is being run in the context of a debugger.

T1622
Debugger Evasion
ToolAsyncRAT

AsyncRAT can use the `CheckRemoteDebuggerPresent` function to detect the presence of a debugger.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.