Technique.View on attack.mitre.org
Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with benign activity, and avoid scrutiny. Adversaries can perform this behavior within virtualization/sandbox environments or natively on host systems.
Adversaries may utilize programmatic `sleep` commands or native system scheduling functionality, for example Scheduled Task/Job. Benign commands or other operations may also be used to delay malware execution or ensure prior commands have had time to execute properly. Loops or otherwise needless repetitions of commands, such as `ping`, may be used to delay malware execution and potentially exceed time thresholds of automated analysis environments. Another variation, commonly referred to as API hammering, involves making various calls to Native API functions in order to delay execution (while also potentially overloading analysis environments with junk data).
Rules on DetectionCode tagged with T1678.
| Used by | Procedure example |
|---|---|
| GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
| GroupMustang Panda | Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |
| Used by | Procedure example |
|---|---|
| MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| MalwareBRICKSTORM | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain. |
| MalwareDynoWiper | DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot. |
| MalwareFooder | Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
| MalwareGlassWorm | GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection. |
| MalwareHIUPAN | HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available. |
| MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
| MalwarePHASEJAM | PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's software generates a randomly selected date that is between 1-4 weeks in the future. This timestamp is then checked against the current time of the compromised machine, and the malware will sleep until that time is encountered. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.