ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1560.003
Archive via Custom Method
GroupFIN6

FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation.

T1560.003
Archive via Custom Method
GroupMustang Panda

Mustang Panda has encrypted documents with RC4 prior to exfiltration.

T1560.003
Archive via Custom Method
GroupUNC3886

UNC3886 has XOR encrypted and Gzip compressed captured credentials.

T1560.003
Archive via Custom Method
GroupLotus Blossom

Lotus Blossom has used custom tools to compress and archive data on victim systems.

T1560.003
Archive via Custom Method
GroupLazarus Group

A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration.

T1560.003
Archive via Custom Method
GroupCopyKittens

CopyKittens encrypts data with a substitute cipher prior to exfiltration.

T1561.001
Disk Content Wipe
GroupGamaredon Group

Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles.

T1561.001
Disk Content Wipe
GroupLazarus Group

Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. A similar process is then used to wipe content in logical drives and, finally, attempt to wipe every byte of every sector on every drive. WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.

T1561.001
Disk Content Wipe
GroupVOID MANTICORE

VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers. VOID MANTICORE has also utilized legitimate remote disk wiping commands.

T1561.002
Disk Structure Wipe
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable.

T1561.002
Disk Structure Wipe
GroupSandworm Team

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.

T1561.002
Disk Structure Wipe
GroupAPT37

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR).

T1561.002
Disk Structure Wipe
GroupEmber Bear

Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine.

T1561.002
Disk Structure Wipe
GroupLazarus Group

Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009.

T1561.002
Disk Structure Wipe
GroupVOID MANTICORE

VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.

T1563.002
RDP Hijacking
GroupAxiom

Axiom has targeted victims with remote administration tools including RDP.

T1564.001
Hidden Files and Directories
GroupAPT32

APT32's macOS backdoor hides the clientID file via a chflags function.

T1564.001
Hidden Files and Directories
GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

T1564.001
Hidden Files and Directories
GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1564.001
Hidden Files and Directories
GroupRedCurl

RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files.

T1564.001
Hidden Files and Directories
GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

T1564.001
Hidden Files and Directories
GroupAPT28

APT28 has saved files with hidden file attributes.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1564.001
Hidden Files and Directories
GroupTransparent Tribe

Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1564.001
Hidden Files and Directories
GroupTeamPCP

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.

T1564.002
Hidden Users
GroupKimsuky

Kimsuky has run reg add ‘HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList’ /v to hide a newly created user.

T1564.002
Hidden Users
GroupDragonfly

Dragonfly has modified the Registry to hide created user accounts.

T1564.003
Hidden Window
GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupKimsuky

Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGorgon Group

Gorgon Group has used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1564.003
Hidden Window
GroupFIN7

FIN7 has used .txt files to conceal PowerShell commands.

T1564.003
Hidden Window
GroupHigaisa

Higaisa used a payload that creates a hidden window.

T1564.003
Hidden Window
GroupDarkHydrus

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupMedusa Group

Medusa Group has utilized the `ShowWindow` API function to hide the current window.

T1564.003
Hidden Window
GroupDeep Panda

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupToddyCat

ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`.

T1564.003
Hidden Window
GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

T1564.003
Hidden Window
GroupCopyKittens

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.

T1564.003
Hidden Window
GroupMagic Hound

Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window.

T1564.003
Hidden Window
GroupAPT19

APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupNomadic Octopus

Nomadic Octopus executed PowerShell in a hidden window.

T1564.004
NTFS File Attributes
GroupAPT32

APT32 used NTFS alternate data streams to hide their payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.