Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1678 Delay Execution |
MalwareBRICKSTORM | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain. |
| T1678 Delay Execution |
MalwareTONESHELL | TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities. |
| T1678 Delay Execution |
MalwareDynoWiper | DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot. |
| T1678 Delay Execution |
MalwareSystemBC | SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds. |
| T1678 Delay Execution |
MalwareRustyWater | RustyWater has generated random sleep intervals between C2 communication. |
| T1678 Delay Execution |
MalwarePureCrypter | PureCrypter has the ability to delay for a specified number of seconds before execution. |
| T1678 Delay Execution |
MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
| T1678 Delay Execution |
MalwareFooder | Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
| T1678 Delay Execution |
MalwareGlassWorm | GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection. |
| T1678 Delay Execution |
MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| T1678 Delay Execution |
MalwarePHASEJAM | PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| T1678 Delay Execution |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution. |
| T1678 Delay Execution |
MalwareHIUPAN | HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available. |
| T1678 Delay Execution |
MalwareShai-Hulud | Shai-Hulud has delayed execution of its larger payloads by forking itself into background process. |
| T1678 Delay Execution |
MalwareQilin | Qilin has the ability to delay execution. |
| T1678 Delay Execution |
MalwareUPPERCUT | UPPERCUT can use a sleep function to delay execution. |
| T1678 Delay Execution |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.