Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.003 Archive via Custom Method |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content. |
| T1560.003 Archive via Custom Method |
MalwaremetaMain | metaMain has used XOR-based encryption for collected files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
| T1560.003 Archive via Custom Method |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| T1561.001 Disk Content Wipe |
MalwareAcidRain | AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it. |
| T1561.001 Disk Content Wipe |
MalwareApostle | Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity. |
| T1561.001 Disk Content Wipe |
MalwareWhisperGate | WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets. |
| T1561.001 Disk Content Wipe |
MalwareAcidPour | AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content. |
| T1561.001 Disk Content Wipe |
MalwareBlackCat | BlackCat has the ability to wipe VM snapshots on compromised networks. |
| T1561.001 Disk Content Wipe |
MalwareVPNFilter | VPNFilter has the capability to wipe a portion of an infected device's firmware. |
| T1561.001 Disk Content Wipe |
MalwareDarkGate | DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`. |
| T1561.001 Disk Content Wipe |
MalwareStoneDrill | StoneDrill can wipe the accessible physical or logical drives of the infected machine. |
| T1561.001 Disk Content Wipe |
MalwareMegaCortex | MegaCortex can wipe deleted data from all drives using |
| T1561.001 Disk Content Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data. |
| T1561.001 Disk Content Wipe |
MalwareDEADWOOD | DEADWOOD deletes files following overwriting them with random data. |
| T1561.001 Disk Content Wipe |
ToolRawDisk | RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content. |
| T1561.001 Disk Content Wipe |
Toolcipher.exe | cipher.exe can be used to overwrite deleted data in specified folders. |
| T1561.002 Disk Structure Wipe |
MalwareShrinkLocker | ShrinkLocker has used Diskpart to format newly-created partitions. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1561.002 Disk Structure Wipe |
MalwareMultiLayer Wiper | MultiLayer Wiper opens a handle to |
| T1561.002 Disk Structure Wipe |
MalwareShamoon | Shamoon has been seen overwriting features of disk structure such as the MBR. |
| T1561.002 Disk Structure Wipe |
MalwareStoneDrill | StoneDrill can wipe the master boot record of an infected computer. |
| T1561.002 Disk Structure Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| T1561.002 Disk Structure Wipe |
MalwareCaddyWiper | CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries. |
| T1561.002 Disk Structure Wipe |
MalwareBFG Agonizer | BFG Agonizer retrieves a device handle to |
| T1561.002 Disk Structure Wipe |
MalwareKillDisk | KillDisk overwrites the first sector of the Master Boot Record with “0x00”. |
| T1561.002 Disk Structure Wipe |
MalwareDEADWOOD | DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| T1561.002 Disk Structure Wipe |
ToolDiskpart | Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk. |
| T1561.002 Disk Structure Wipe |
ToolRawDisk | RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. |
| T1561.002 Disk Structure Wipe |
MalwareZeroCleare | ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
| T1563.001 SSH Hijacking |
MalwareMEDUSA | MEDUSA can be configured to capture SSH credentials via SSH hijacking. |
| T1563.002 RDP Hijacking |
MalwareWannaCry | WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session. |
| T1564 Hide Artifacts |
MalwareDarkTortilla | DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry. |
| T1564 Hide Artifacts |
MalwareNOOPLDR | NOOPLDR can hide services used to aid execution. |
| T1564 Hide Artifacts |
MalwareBundlore | Bundlore uses the |
| T1564 Hide Artifacts |
MalwareTarrask | Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value. |
| T1564 Hide Artifacts |
MalwareOSX/Shlayer | OSX/Shlayer has used the |
| T1564 Hide Artifacts |
MalwareWarzoneRAT | WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`. |
| T1564 Hide Artifacts |
ToolRemcos | Remcos can modify file attributes to hide the file. |
| T1564.001 Hidden Files and Directories |
MalwareCOATHANGER | COATHANGER creates and installs itself to a hidden installation directory. |
| T1564.001 Hidden Files and Directories |
MalwareNETWIRE | NETWIRE can copy itself to and launch itself from hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareiKitten | iKitten saves itself with a leading "." so that it's hidden from users by default. |
| T1564.001 Hidden Files and Directories |
MalwareEnvyScout | EnvyScout can use hidden directories and files to hide malicious executables. |
| T1564.001 Hidden Files and Directories |
MalwareMachete | Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive. |
| T1564.001 Hidden Files and Directories |
MalwareDacls | Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
| T1564.001 Hidden Files and Directories |
MalwareCuckoo Stealer | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory. |
| T1564.001 Hidden Files and Directories |
MalwareWastedLocker | WastedLocker has copied a random file from the Windows System32 folder to the |
| T1564.001 Hidden Files and Directories |
MalwareInvisiMole | InvisiMole can create hidden system directories. |
| T1564.001 Hidden Files and Directories |
MalwareCLAIMLOADER | CLAIMLOADER has modified file attributes to remain hidden to a standard user. |
| T1564.001 Hidden Files and Directories |
MalwareFruitFly | FruitFly saves itself with a leading "." to make it a hidden file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.