Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1490 Inhibit System Recovery |
MalwareH1N1 | H1N1 disable recovery options and deletes shadow copies from the victim. |
| T1490 Inhibit System Recovery |
MalwareBitPaymer | BitPaymer attempts to remove the backup shadow files from the host using |
| T1491.001 Internal Defacement |
MalwareRansomHub | RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data. |
| T1491.001 Internal Defacement |
MalwareShrinkLocker | ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation. |
| T1491.001 Internal Defacement |
MalwareSameCoin | SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing. |
| T1491.001 Internal Defacement |
MalwareDiavol | After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt". |
| T1491.001 Internal Defacement |
MalwareBlackCat | BlackCat can change the desktop wallpaper on compromised hosts. |
| T1491.001 Internal Defacement |
MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| T1491.001 Internal Defacement |
MalwareROADSWEEP | ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files. |
| T1491.001 Internal Defacement |
MalwareMeteor | Meteor can change both the desktop wallpaper and the lock screen image to a custom image. |
| T1491.001 Internal Defacement |
MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| T1491.001 Internal Defacement |
MalwareINC Ransomware | INC Ransomware has the ability to change the background wallpaper image to display the ransom note. |
| T1491.001 Internal Defacement |
ToolRemcos | Remcos has the ability to modify the desktop wallpaper. |
| T1495 Firmware Corruption |
MalwareTrickBot | TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device. |
| T1495 Firmware Corruption |
MalwareBad Rabbit | Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up. |
| T1496.001 Compute Hijacking |
MalwareHildegard | Hildegard has used xmrig to mine cryptocurrency. |
| T1496.001 Compute Hijacking |
MalwareSkidmap | Skidmap is a kernel-mode rootkit used for cryptocurrency mining. |
| T1496.001 Compute Hijacking |
MalwareBonadan | Bonadan can download an additional module which has a cryptocurrency mining extension. |
| T1496.001 Compute Hijacking |
MalwareLucifer | Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero. |
| T1496.001 Compute Hijacking |
MalwareDarkGate | DarkGate can deploy follow-on cryptocurrency mining payloads. |
| T1496.001 Compute Hijacking |
MalwareKinsing | Kinsing has created and run a Bitcoin cryptocurrency miner. |
| T1496.001 Compute Hijacking |
MalwareCookieMiner | CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency. |
| T1496.001 Compute Hijacking |
MalwareLoudMiner | LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero. |
| T1496.001 Compute Hijacking |
ToolImminent Monitor | Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBumblebee | Bumblebee has the ability to perform anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareSquirrelwaffle | Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRaspberry Robin | Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareIcedID | IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic. |
| T1497 Virtualization/Sandbox Evasion |
MalwarePteranodon | Pteranodon has the ability to use anti-detection functions to identify sandbox environments. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBisonal | Bisonal can check to determine if the compromised system is running on VMware. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMetamorfo | Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRedLine Stealer | RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBlack Basta | Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStoneDrill | StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRTM | RTM can detect if it is running within a sandbox or other virtualized analysis environment. |
| T1497 Virtualization/Sandbox Evasion |
MalwareStrelaStealer | StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBazar | Bazar can attempt to overload sandbox analysis by sending 1550 calls to |
| T1497 Virtualization/Sandbox Evasion |
MalwareXLoader | XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCarberp | Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software. |
| T1497 Virtualization/Sandbox Evasion |
MalwareEgregor | Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCHOPSTICK | CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCozyCar | Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit. |
| T1497 Virtualization/Sandbox Evasion |
MalwareKevin | Kevin can sleep for a time interval between C2 communication attempts. |
| T1497 Virtualization/Sandbox Evasion |
MalwareAgent Tesla | Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. |
| T1497 Virtualization/Sandbox Evasion |
MalwareHancitor | Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads. |
| T1497 Virtualization/Sandbox Evasion |
MalwareGelsemium | Gelsemium can use junk code to generate random activity to obscure malware behavior. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target. |
| T1497.001 System Checks |
MalwarePikabot | Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB). |
| T1497.001 System Checks |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1497.001 System Checks |
MalwareBumblebee | Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.