Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1568 Dynamic Resolution |
MalwareGelsemium | Gelsemium can use dynamic DNS domain names in C2. |
| T1568 Dynamic Resolution |
ToolAsyncRAT | AsyncRAT can be configured to use dynamic DNS. |
| T1568 Dynamic Resolution |
ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
| T1568.001 Fast Flux DNS |
MalwareAmadey | Amadey has used fast flux DNS for its C2. |
| T1568.001 Fast Flux DNS |
Malwaregh0st RAT | gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses. |
| T1568.001 Fast Flux DNS |
MalwarenjRAT | njRAT has used a fast flux DNS for C2 IP resolution. |
| T1568.002 Domain Generation Algorithms |
MalwareUrsnif | Ursnif has used a DGA to generate domain names for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareAria-body | Aria-body has the ability to use a DGA for C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareSombRAT | SombRAT can use a custom DGA to generate a subdomain for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDoki | Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains. |
| T1568.002 Domain Generation Algorithms |
MalwareConficker | Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
| T1568.002 Domain Generation Algorithms |
MalwarePOSHSPY | POSHSPY uses a DGA to derive command and control URLs from a word list. |
| T1568.002 Domain Generation Algorithms |
MalwareMiniDuke | MiniDuke can use DGA to generate new Twitter URLs for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDarkWatchman | DarkWatchman has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareGrandoreiro | Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
| T1568.002 Domain Generation Algorithms |
MalwareBazar | Bazar can implement DGA using the current date as a seed variable. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1568.002 Domain Generation Algorithms |
MalwareMilan | Milan can use hardcoded domains as an input for domain generation algorithms. |
| T1568.002 Domain Generation Algorithms |
MalwareCCBkdr | CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost. |
| T1568.002 Domain Generation Algorithms |
MalwareCHOPSTICK | CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists. |
| T1568.002 Domain Generation Algorithms |
MalwareBONDUPDATER | BONDUPDATER uses a DGA to communicate with command and control servers. |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
| T1568.002 Domain Generation Algorithms |
MalwareAstaroth | Astaroth has used a DGA in C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareQakBot | QakBot can use domain generation algorithms in C2 communication. |
| T1568.002 Domain Generation Algorithms |
Toolngrok | ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours. |
| T1568.002 Domain Generation Algorithms |
ToolAsyncRAT | AsyncRAT use a DGA to generate a C2 domains. |
| T1569.001 Launchctl |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `launchctl` to restart the Launch Agent. |
| T1569.001 Launchctl |
MalwareCuckoo Stealer | Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence. |
| T1569.001 Launchctl |
MalwareCalisto | Calisto uses launchctl to enable screen sharing on the victim’s machine. |
| T1569.001 Launchctl |
MalwareXCSSET | XCSSET loads a system level launchdaemon using the |
| T1569.001 Launchctl |
MalwareAppleJeus | AppleJeus has loaded a plist file using the |
| T1569.001 Launchctl |
MalwareLoudMiner | LoudMiner launched the QEMU services in the |
| T1569.002 Service Execution |
MalwareProxysvc | Proxysvc registers itself as a service on the victim’s machine to run as a standalone process. |
| T1569.002 Service Execution |
MalwareStrongPity | StrongPity can install a service to execute itself as a service. |
| T1569.002 Service Execution |
MalwareTinyTurla | TinyTurla can install itself as a service on compromised machines. |
| T1569.002 Service Execution |
MalwareBad Rabbit | Bad Rabbit drops a file named |
| T1569.002 Service Execution |
MalwareOlympic Destroyer | Olympic Destroyer utilizes PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareMafalda | Mafalda can create a remote service, let it run once, and then delete it. |
| T1569.002 Service Execution |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware executes as a service when deployed. |
| T1569.002 Service Execution |
MalwareHOPLIGHT | HOPLIGHT has used svchost.exe to execute a malicious DLL . |
| T1569.002 Service Execution |
MalwareWastedLocker | WastedLocker can execute itself as a service. |
| T1569.002 Service Execution |
MalwareInvisiMole | InvisiMole has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1569.002 Service Execution |
MalwareOkrum | Okrum's loader can create a new service named NtmsSvc to execute the payload. |
| T1569.002 Service Execution |
MalwareRemoteCMD | RemoteCMD can execute commands remotely by creating a new service on the remote system. |
| T1569.002 Service Execution |
MalwareRagnar Locker | Ragnar Locker has used sc.exe to execute a service that it creates. |
| T1569.002 Service Execution |
MalwareNotPetya | NotPetya can use PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareHyperBro | HyperBro has the ability to start and stop a specified service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.