ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1568
Dynamic Resolution
MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

T1568
Dynamic Resolution
ToolAsyncRAT

AsyncRAT can be configured to use dynamic DNS.

T1568
Dynamic Resolution
ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

T1568.001
Fast Flux DNS
MalwareAmadey

Amadey has used fast flux DNS for its C2.

T1568.001
Fast Flux DNS
Malwaregh0st RAT

gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses.

T1568.001
Fast Flux DNS
MalwarenjRAT

njRAT has used a fast flux DNS for C2 IP resolution.

T1568.002
Domain Generation Algorithms
MalwareUrsnif

Ursnif has used a DGA to generate domain names for C2.

T1568.002
Domain Generation Algorithms
MalwareAria-body

Aria-body has the ability to use a DGA for C2 communications.

T1568.002
Domain Generation Algorithms
MalwareSombRAT

SombRAT can use a custom DGA to generate a subdomain for C2.

T1568.002
Domain Generation Algorithms
MalwareDoki

Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains.

T1568.002
Domain Generation Algorithms
MalwareConficker

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

T1568.002
Domain Generation Algorithms
MalwarePOSHSPY

POSHSPY uses a DGA to derive command and control URLs from a word list.

T1568.002
Domain Generation Algorithms
MalwareMiniDuke

MiniDuke can use DGA to generate new Twitter URLs for C2.

T1568.002
Domain Generation Algorithms
MalwareDarkWatchman

DarkWatchman has used a DGA to generate a domain name for C2.

T1568.002
Domain Generation Algorithms
MalwareGrandoreiro

Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily.

T1568.002
Domain Generation Algorithms
MalwareShark

Shark can send DNS C2 communications using a unique domain generation algorithm.

T1568.002
Domain Generation Algorithms
MalwareBazar

Bazar can implement DGA using the current date as a seed variable.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1568.002
Domain Generation Algorithms
MalwareMilan

Milan can use hardcoded domains as an input for domain generation algorithms.

T1568.002
Domain Generation Algorithms
MalwareCCBkdr

CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost.

T1568.002
Domain Generation Algorithms
MalwareCHOPSTICK

CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists.

T1568.002
Domain Generation Algorithms
MalwareBONDUPDATER

BONDUPDATER uses a DGA to communicate with command and control servers.

T1568.002
Domain Generation Algorithms
MalwareEbury

Ebury has used a DGA to generate a domain name for C2.

T1568.002
Domain Generation Algorithms
MalwareShadowPad

ShadowPad uses a DGA that is based on the day of the month for C2 servers.

T1568.002
Domain Generation Algorithms
MalwareAstaroth

Astaroth has used a DGA in C2 communications.

T1568.002
Domain Generation Algorithms
MalwareQakBot

QakBot can use domain generation algorithms in C2 communication.

T1568.002
Domain Generation Algorithms
Toolngrok

ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours.

T1568.002
Domain Generation Algorithms
ToolAsyncRAT

AsyncRAT use a DGA to generate a C2 domains.

T1569.001
Launchctl
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `launchctl` to restart the Launch Agent.

T1569.001
Launchctl
MalwareCuckoo Stealer

Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence.

T1569.001
Launchctl
MalwareCalisto

Calisto uses launchctl to enable screen sharing on the victim’s machine.

T1569.001
Launchctl
MalwareXCSSET

XCSSET loads a system level launchdaemon using the launchctl load -w command from /System/Librarby/LaunchDaemons/ssh.plist.

T1569.001
Launchctl
MalwareAppleJeus

AppleJeus has loaded a plist file using the launchctl command.

T1569.001
Launchctl
MalwareLoudMiner

LoudMiner launched the QEMU services in the /Library/LaunchDaemons/ folder using launchctl. It also uses launchctl to unload all Launch Daemons when updating to a newer version of LoudMiner.

T1569.002
Service Execution
MalwareProxysvc

Proxysvc registers itself as a service on the victim’s machine to run as a standalone process.

T1569.002
Service Execution
MalwareStrongPity

StrongPity can install a service to execute itself as a service.

T1569.002
Service Execution
MalwareTinyTurla

TinyTurla can install itself as a service on compromised machines.

T1569.002
Service Execution
MalwareBad Rabbit

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

T1569.002
Service Execution
MalwareOlympic Destroyer

Olympic Destroyer utilizes PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareMafalda

Mafalda can create a remote service, let it run once, and then delete it.

T1569.002
Service Execution
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware executes as a service when deployed.

T1569.002
Service Execution
MalwareHOPLIGHT

HOPLIGHT has used svchost.exe to execute a malicious DLL .

T1569.002
Service Execution
MalwareWastedLocker

WastedLocker can execute itself as a service.

T1569.002
Service Execution
MalwareInvisiMole

InvisiMole has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1569.002
Service Execution
MalwareOkrum

Okrum's loader can create a new service named NtmsSvc to execute the payload.

T1569.002
Service Execution
MalwareRemoteCMD

RemoteCMD can execute commands remotely by creating a new service on the remote system.

T1569.002
Service Execution
MalwareRagnar Locker

Ragnar Locker has used sc.exe to execute a service that it creates.

T1569.002
Service Execution
MalwareNotPetya

NotPetya can use PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareHyperBro

HyperBro has the ability to start and stop a specified service.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.