ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1559
Inter-Process Communication
MalwareSPAWNCHIMERA

SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process.

T1559
Inter-Process Communication
MalwarePITSTOP

PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`.

T1559
Inter-Process Communication
MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

T1559
Inter-Process Communication
MalwareMini Shai-Hulud

Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.

T1559.001
Component Object Model
MalwareTrickBot

TrickBot used COM to setup scheduled task for persistence.

T1559.001
Component Object Model
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

T1559.001
Component Object Model
MalwareUrsnif

Ursnif droppers have used COM objects to execute the malware's full executable payload.

T1559.001
Component Object Model
MalwareSTATICPLUGIN

STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file.

T1559.001
Component Object Model
MalwareInvisiMole

InvisiMole can use the ITaskService, ITaskDefinition and ITaskSettings COM interfaces to schedule a task.

T1559.001
Component Object Model
MalwareCLAIMLOADER

CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface.

T1559.001
Component Object Model
MalwareNeoichor

Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2.

T1559.001
Component Object Model
MalwareRaspberry Robin

Raspberry Robin creates an elevated COM object for CMLuaUtil and uses this to set a registry value that points to the malicious LNK file during execution.

T1559.001
Component Object Model
MalwareRustyWater

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

T1559.001
Component Object Model
MalwareDarkTortilla

DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1559.001
Component Object Model
MalwareMilan

Milan can use a COM component to generate scheduled tasks.

T1559.001
Component Object Model
MalwareRamsay

Ramsay can use the Windows COM API to schedule tasks and maintain persistence.

T1559.001
Component Object Model
MalwareFunnyDream

FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms.

T1559.001
Component Object Model
MalwarePOWERSTATS

POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts.

T1559.001
Component Object Model
MalwareGelsemium

Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process.

T1559.001
Component Object Model
MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

T1559.001
Component Object Model
ToolSILENTTRINITY

SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object.

T1559.002
Dynamic Data Exchange
MalwareHAWKBALL

HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode.

T1559.002
Dynamic Data Exchange
MalwareGravityRAT

GravityRAT has been delivered via Word documents using DDE for execution.

T1559.002
Dynamic Data Exchange
MalwareKeyBoy

KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads.

T1559.002
Dynamic Data Exchange
MalwareRTM

RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism.

T1559.002
Dynamic Data Exchange
MalwareValak

Valak can execute tasks via OLE.

T1559.002
Dynamic Data Exchange
MalwareRamsay

Ramsay has been delivered using OLE objects in malicious documents.

T1559.002
Dynamic Data Exchange
MalwarePoetRAT

PoetRAT was delivered with documents using DDE to execute malicious code.

T1559.002
Dynamic Data Exchange
MalwarePOWERSTATS

POWERSTATS can use DDE to execute additional payloads on compromised hosts.

T1560
Archive Collected Data
MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

T1560
Archive Collected Data
MalwareExaramel for Windows

Exaramel for Windows automatically encrypts files before sending them to the C2 server.

T1560
Archive Collected Data
MalwareJumbledPath

JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices.

T1560
Archive Collected Data
MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

T1560
Archive Collected Data
MalwareLurid

Lurid can compress data before sending it.

T1560
Archive Collected Data
MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

T1560
Archive Collected Data
MalwareNETWIRE

NETWIRE has the ability to compress archived screenshots.

T1560
Archive Collected Data
MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

T1560
Archive Collected Data
MalwareMachete

Machete stores zipped files with profile data from installed web browsers.

T1560
Archive Collected Data
MalwarePowerLess

PowerLess can encrypt browser database files prior to exfiltration.

T1560
Archive Collected Data
MalwarePrikormka

After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish.

T1560
Archive Collected Data
MalwareLoFiSe

LoFiSe can collect files into password-protected ZIP-archives for exfiltration.

T1560
Archive Collected Data
MalwareVERMIN

VERMIN encrypts the collected files using 3-DES.

T1560
Archive Collected Data
MalwareChrommme

Chrommme can encrypt and store on disk collected data before exfiltration.

T1560
Archive Collected Data
MalwareRunningRAT

RunningRAT contains code to compress files.

T1560
Archive Collected Data
MalwareEpic

Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.

T1560
Archive Collected Data
MalwareLightNeuron

LightNeuron contains a function to encrypt and store emails that it collects.

T1560
Archive Collected Data
MalwareMuddyViper

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

T1560
Archive Collected Data
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.

T1560
Archive Collected Data
MalwareLP-Notes

LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC
and the initialization vector 91A4E6F6D51DAEE773A8F00279792578.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.