ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1490
Inhibit System Recovery
MalwareH1N1

H1N1 disable recovery options and deletes shadow copies from the victim.

T1490
Inhibit System Recovery
MalwareBitPaymer

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

T1491.001
Internal Defacement
MalwareRansomHub

RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data.

T1491.001
Internal Defacement
MalwareShrinkLocker

ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation.

T1491.001
Internal Defacement
MalwareSameCoin

SameCoin can alter the victim’s background to display an image showing the name of Hamas’s military wing.

T1491.001
Internal Defacement
MalwareDiavol

After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt".

T1491.001
Internal Defacement
MalwareBlackCat

BlackCat can change the desktop wallpaper on compromised hosts.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1491.001
Internal Defacement
MalwareROADSWEEP

ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files.

T1491.001
Internal Defacement
MalwareMeteor

Meteor can change both the desktop wallpaper and the lock screen image to a custom image.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1491.001
Internal Defacement
MalwareINC Ransomware

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

T1491.001
Internal Defacement
ToolRemcos

Remcos has the ability to modify the desktop wallpaper.

T1495
Firmware Corruption
MalwareTrickBot

TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device.

T1495
Firmware Corruption
MalwareBad Rabbit

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.

T1496.001
Compute Hijacking
MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

T1496.001
Compute Hijacking
MalwareSkidmap

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

T1496.001
Compute Hijacking
MalwareBonadan

Bonadan can download an additional module which has a cryptocurrency mining extension.

T1496.001
Compute Hijacking
MalwareLucifer

Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero.

T1496.001
Compute Hijacking
MalwareDarkGate

DarkGate can deploy follow-on cryptocurrency mining payloads.

T1496.001
Compute Hijacking
MalwareKinsing

Kinsing has created and run a Bitcoin cryptocurrency miner.

T1496.001
Compute Hijacking
MalwareCookieMiner

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency.

T1496.001
Compute Hijacking
MalwareLoudMiner

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

T1496.001
Compute Hijacking
ToolImminent Monitor

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

T1497
Virtualization/Sandbox Evasion
MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareSquirrelwaffle

Squirrelwaffle has contained a hardcoded list of IP addresses to block that belong to sandboxes and analysis platforms.

T1497
Virtualization/Sandbox Evasion
MalwareRaspberry Robin

Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment.

T1497
Virtualization/Sandbox Evasion
MalwareIcedID

IcedID has manipulated Keitaro Traffic Direction System to filter researcher and sandbox traffic.

T1497
Virtualization/Sandbox Evasion
MalwarePteranodon

Pteranodon has the ability to use anti-detection functions to identify sandbox environments.

T1497
Virtualization/Sandbox Evasion
MalwareBisonal

Bisonal can check to determine if the compromised system is running on VMware.

T1497
Virtualization/Sandbox Evasion
MalwareMetamorfo

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.

T1497
Virtualization/Sandbox Evasion
MalwareRedLine Stealer

RedLine Stealer has an anti-sandbox technique that requires the malware to consistently check with the C2 server, if the communication fails RedLine Stealer will not continue execution.

T1497
Virtualization/Sandbox Evasion
MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

T1497
Virtualization/Sandbox Evasion
MalwareStoneDrill

StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareRTM

RTM can detect if it is running within a sandbox or other virtualized analysis environment.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

T1497
Virtualization/Sandbox Evasion
MalwareBazar

Bazar can attempt to overload sandbox analysis by sending 1550 calls to printf.

T1497
Virtualization/Sandbox Evasion
MalwareXLoader

XLoader can utilize decoy command and control domains within the malware configuration to circumvent sandbox analysis.

T1497
Virtualization/Sandbox Evasion
MalwareCarberp

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.

T1497
Virtualization/Sandbox Evasion
MalwareEgregor

Egregor has used multiple anti-analysis and anti-sandbox techniques to prevent automated analysis by sandboxes.

T1497
Virtualization/Sandbox Evasion
MalwareCHOPSTICK

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

T1497
Virtualization/Sandbox Evasion
MalwareCozyCar

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

T1497
Virtualization/Sandbox Evasion
MalwareKevin

Kevin can sleep for a time interval between C2 communication attempts.

T1497
Virtualization/Sandbox Evasion
MalwareAgent Tesla

Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks.

T1497
Virtualization/Sandbox Evasion
MalwareHancitor

Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads.

T1497
Virtualization/Sandbox Evasion
MalwareGelsemium

Gelsemium can use junk code to generate random activity to obscure malware behavior.

T1497
Virtualization/Sandbox Evasion
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded sandbox detection by applying a 1-in-6 probability gate that generates a random number which will only trigger the wiper functionality when the set number outcome is met even in environments that match parameters of a geopolitical target.

T1497.001
System Checks
MalwarePikabot

Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB).

T1497.001
System Checks
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1497.001
System Checks
MalwareBumblebee

Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.