Service Stop

T1489

Technique.View on attack.mitre.org

About this technique

Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.

Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. In some cases, adversaries may stop or disable many or all services to render systems unusable. Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct Data Destruction or Data Encrypted for Impact on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure.

Threat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.

Detection rules39

Rules on DetectionCode tagged with T1489.

Sigma19

Splunk20

RuleTypeRiskData source
Excessive Attempt To Disable ServicesAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Excessive Service Stop AttemptAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Linux Auditd Auditd Service StopAnomalyNULLLinux Auditd Service Stop
Linux Auditd Osquery Service StopAnomalyNULLLinux Auditd Service Stop
Linux Auditd Stop ServicesHuntingNULLLinux Auditd Service Stop
Linux Auditd Sysmon Service StopAnomalyNULLLinux Auditd Service Stop
Linux Disable ServicesTTPNULLSysmon for Linux EventID 1
Linux Magic SysRq Key AbuseTTPNULLLinux Auditd Path, Linux Auditd Cwd
Linux Stop ServicesTTPNULLSysmon for Linux EventID 1
Ollama Abnormal Service Crash Availability AttackAnomalyNULLOllama Server
Windows Excessive Service Stop AttemptTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Processes Killed By Industroyer2 MalwareAnomalyNULLSysmon EventID 5
Windows Security Account Manager StoppedTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Service Deletion In RegistryAnomalyNULLSysmon EventID 13
Windows Service Stop AttemptHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups7

Software47

Show 23 more

Campaigns0

None recorded.

Procedure examples54

Groups7

Used byProcedure example
GroupIndrik Spider

Indrik Spider has used PsExec to stop services prior to the execution of ransomware.

GroupKimsuky

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.

GroupLAPSUS$

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.

GroupLazarus Group

Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users.

GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

GroupSandworm Team

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.

GroupWizard Spider

Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.

Software47

Used byProcedure example
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

MalwareAvaddon

Avaddon looks for and attempts to stop database processes.

MalwareAvosLocker

AvosLocker has terminated specific processes before encryption.

MalwareBabuk

Babuk can stop specific services related to backups.

MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can terminate running services.

MalwareBlackCat

BlackCat has the ability to stop VM services on compromised networks.

MalwareBRICKSTORM

BRICKSTORM has terminated an existing process to ensure that its own new process can execute.

MalwareCheerscrypt

Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`.

View all 47 software examples

References6

  1. AWS DisableAWSServiceAccess Open source
    AWS. (n.d.). DisableAWSServiceAccess. Retrieved May 22, 2025.
  2. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  3. Datadog Security Labs Cloud Persistence 2025 Open source
    Martin McCloskey. (2025, May 13). Tales from the cloud trenches: The Attacker doth persist too much, methinks. Retrieved May 22, 2025.
  4. Novetta Blockbuster Open source
    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.
  5. SecureWorks WannaCry Analysis Open source
    Counter Threat Unit Research Team. (2017, May 18). WCry Ransomware Analysis. Retrieved March 26, 2019.
  6. Talos Olympic Destroyer 2018 Open source
    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.