ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1678×

17 examples

TechniqueUsed byProcedure example
T1678
Delay Execution
MalwareBRICKSTORM

BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.

T1678
Delay Execution
MalwareTONESHELL

TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities.

T1678
Delay Execution
MalwareDynoWiper

DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot.

T1678
Delay Execution
MalwareSystemBC

SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds.

T1678
Delay Execution
MalwareRustyWater

RustyWater has generated random sleep intervals between C2 communication.

T1678
Delay Execution
MalwarePureCrypter

PureCrypter has the ability to delay for a specified number of seconds before execution.

T1678
Delay Execution
MalwareMuddyViper

MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute.

T1678
Delay Execution
MalwareFooder

Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution.

T1678
Delay Execution
MalwareGlassWorm

GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection.

T1678
Delay Execution
MalwareAshTag

AshTag can use a set sleep time to delay C2 beaconing.

T1678
Delay Execution
MalwarePHASEJAM

PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process.

T1678
Delay Execution
MalwareSPAWNCHIMERA

SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution.

T1678
Delay Execution
MalwareHIUPAN

HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available.

T1678
Delay Execution
MalwareShai-Hulud

Shai-Hulud has delayed execution of its larger payloads by forking itself into background process.

T1678
Delay Execution
MalwareQilin

Qilin has the ability to delay execution.

T1678
Delay Execution
MalwareUPPERCUT

UPPERCUT can use a sleep function to delay execution.

T1678
Delay Execution
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.