Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.006 Run Virtual Instance |
MalwareLoudMiner | LoudMiner has used QEMU and VirtualBox to run a Tiny Core Linux virtual machine, which runs XMRig and makes connections to the C2 server for updates. |
| T1564.008 Email Hiding Rules |
MalwareKali365 | Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them. |
| T1564.009 Resource Forking |
MalwareKeydnap | Keydnap uses a resource fork to present a macOS JPEG or text file icon rather than the executable's icon assigned by the operating system. |
| T1564.009 Resource Forking |
MalwareOSX/Shlayer | OSX/Shlayer has used a resource fork to hide a compressed binary file of itself from the terminal, Finder, and potentially evade traditional scanners. |
| T1564.010 Process Argument Spoofing |
MalwareSombRAT | SombRAT has the ability to modify its process memory to hide process command-line arguments. |
| T1564.010 Process Argument Spoofing |
MalwareCobalt Strike | Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands. |
| T1564.011 Ignore Process Interrupts |
MalwareBOLDMOVE | BOLDMOVE calls the signal function to ignore the signals SIGCHLD, SIGHIP, and SIGPIPE prior to starting primary logic. |
| T1564.011 Ignore Process Interrupts |
MalwareGoldMax | The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated. |
| T1564.011 Ignore Process Interrupts |
MalwareBPFDoor | BPFDoor sets its process to ignore the following signals; `SIGHUP`, `SIGINT`, `SIGQUIT`, `SIGPIPE`, `SIGCHLD`, `SIGTTIN`, and `SIGTTOU`. |
| T1564.011 Ignore Process Interrupts |
MalwareShai-Hulud | Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`. |
| T1564.011 Ignore Process Interrupts |
MalwareOSX/Shlayer | OSX/Shlayer has used the `nohup` command to instruct executed payloads to ignore hangup signals. |
| T1564.011 Ignore Process Interrupts |
MalwareMini Shai-Hulud | Mini Shai-Hulud has suppressed output so that nothing is printed to terminal and has utilized silent exiting when environmental variables match restricted values. |
| T1565 Data Manipulation |
MalwarePHASEJAM | PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version. |
| T1565.001 Stored Data Manipulation |
MalwareMultiLayer Wiper | MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult. |
| T1565.001 Stored Data Manipulation |
MalwareSUNSPOT | SUNSPOT created a copy of the SolarWinds Orion software source file with a |
| T1565.002 Transmitted Data Manipulation |
MalwareLightNeuron | LightNeuron is capable of modifying email content, headers, and attachments during transit. |
| T1565.002 Transmitted Data Manipulation |
MalwareGlassWorm | GlassWorm can intercept and modify transaction details associated with hardware wallet applications before signing. |
| T1565.002 Transmitted Data Manipulation |
MalwareMetamorfo | Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address. |
| T1565.002 Transmitted Data Manipulation |
MalwareMelcoz | Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary. |
| T1566 Phishing |
MalwareRoyal | Royal has been spread through the use of phishing campaigns including "call back phishing" where victims are lured into calling a number provided through email. |
| T1566 Phishing |
MalwareHikit | Hikit has been spread through spear phishing. |
| T1566 Phishing |
MalwareINC Ransomware | INC Ransomware campaigns have used spearphishing emails for initial access. |
| T1566.001 Spearphishing Attachment |
MalwareTrickBot | TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware |
| T1566.001 Spearphishing Attachment |
MalwareBLINDINGCAN | BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareKOPILUWAK | KOPILUWAK has been delivered to victims as a malicious email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareThreatNeedle | ThreatNeedle has been distributed via a malicious Word document within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwarePony | Pony has been delivered via spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOceanSalt | OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments. |
| T1566.001 Spearphishing Attachment |
MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareEnvyScout | EnvyScout has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareEmotet | Emotet has been delivered by phishing emails containing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareWoody RAT | Woody RAT has been delivered via malicious Word documents and archive files. |
| T1566.001 Spearphishing Attachment |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails. |
| T1566.001 Spearphishing Attachment |
MalwareSnip3 | Snip3 has been delivered to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareRifdoor | Rifdoor has been distributed in e-mails with malicious Excel or Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareRustyWater | RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage. |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareFlagpro | Flagpro has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareDarkTortilla | DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents. |
| T1566.001 Spearphishing Attachment |
MalwareROKRAT | ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
MalwareDarkWatchman | DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file. |
| T1566.001 Spearphishing Attachment |
MalwareJavali | Javali has been delivered as malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareBisonal | Bisonal has been delivered as malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareClambling | Clambling has been delivered to victim's machines through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareDarkGate | DarkGate can be distributed through emails with malicious attachments from a spoofed email address. |
| T1566.001 Spearphishing Attachment |
MalwareSVCReady | SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareLatrodectus | Latrodectus has been distributed through reply-chain phishing emails with malicious attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.