ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0584×

20 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1041
Exfiltration Over C2 Channel
MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

T1053.005
Scheduled Task
MalwareAppleJeus

AppleJeus has created a scheduled SYSTEM task that runs when a user logs in.

T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1070.004
File Deletion
MalwareAppleJeus

AppleJeus has deleted the MSI file after installation.

T1071.001
Web Protocols
MalwareAppleJeus

AppleJeus has sent data to its C2 server via POST requests.

T1082
System Information Discovery
MalwareAppleJeus

AppleJeus has collected the victim host information after infection.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleJeus

AppleJeus has decoded files received from a C2.

T1204.001
Malicious Link
MalwareAppleJeus

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

T1204.002
Malicious File
MalwareAppleJeus

AppleJeus has required user execution of a malicious MSI installer.

T1218.007
Msiexec
MalwareAppleJeus

AppleJeus has been installed via MSI installer.

T1497.003
Time Based Checks
MalwareAppleJeus

AppleJeus has waited a specified time before downloading a second stage payload.

T1543.003
Windows Service
MalwareAppleJeus

AppleJeus can install itself as a service.

T1543.004
Launch Daemon
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1546.016
Installer Packages
MalwareAppleJeus

During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions.

T1548.002
Bypass User Account Control
MalwareAppleJeus

AppleJeus has presented the user with a UAC prompt to elevate privileges while installing.

T1553.002
Code Signing
MalwareAppleJeus

AppleJeus has used a valid digital signature from Sectigo to appear legitimate.

T1564.001
Hidden Files and Directories
MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

T1566.002
Spearphishing Link
MalwareAppleJeus

AppleJeus has been distributed via spearphishing link.

T1569.001
Launchctl
MalwareAppleJeus

AppleJeus has loaded a plist file using the launchctl command.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.