Malware.View on attack.mitre.org
Stuxnet was the first publicly reported malware to specifically target industrial control systems devices. Stuxnet is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines. Stuxnet was discovered in 2010, with some components being used as early as November 2008.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
Stuxnet has the ability to generate new C2 domains. |
| T1012 Query Registry |
Stuxnet searches the Registry for indicators of security programs. |
| T1014 Rootkit |
Stuxnet uses a Windows rootkit to mask its binaries and other relevant files. |
| T1016 System Network Configuration Discovery |
Stuxnet collects the IP address of a compromised system. |
| T1021 Remote Services |
Stuxnet can propagate via peer-to-peer communication and updates using RPC. |
| T1021.002 SMB/Windows Admin Shares |
Stuxnet propagates to available network shares. |
| T1027.013 Encrypted/Encoded File |
Stuxnet uses encrypted configuration blocks and writes encrypted files to disk. |
| T1041 Exfiltration Over C2 Channel |
Stuxnet sends compromised victim information via HTTP. |
| T1047 Windows Management Instrumentation |
Stuxnet used WMI with an |
| T1053.005 Scheduled Task |
Stuxnet schedules a network job to execute two minutes after host infection. |
| T1055.001 Dynamic-link Library Injection |
Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process. |
| T1068 Exploitation for Privilege Escalation |
Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines. |
| T1070 Indicator Removal |
Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads. |
| T1070.004 File Deletion |
Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files. |
| T1070.006 Timestomp |
Stuxnet extracts and writes driver files that match the times of other legitimate files. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.