ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1242×

52 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareQilin

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1012
Query Registry
MalwareQilin

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1016
System Network Configuration Discovery
MalwareQilin

Qilin can accept a command line argument identifying specific IPs.

T1018
Remote System Discovery
MalwareQilin

Qilin can enumerate domain-connected hosts during its discovery phase.

T1021.002
SMB/Windows Admin Shares
MalwareQilin

Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.

T1021.004
SSH
MalwareQilin

Qilin can enable SSH access on ESXi hosts.

T1027.013
Encrypted/Encoded File
MalwareQilin

Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.

T1036.004
Masquerade Task or Service
MalwareQilin

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.005
Match Legitimate Resource Name or Location
MalwareQilin

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1047
Windows Management Instrumentation
MalwareQilin

Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.

T1053.005
Scheduled Task
MalwareQilin

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1055.001
Dynamic-link Library Injection
MalwareQilin

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1059.003
Windows Command Shell
MalwareQilin

Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i
C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.

T1069.002
Domain Groups
MalwareQilin

Qilin can run PowerShell cmdlets to discover domain groups.

T1070.004
File Deletion
MalwareQilin

Qilin can delete itself from infected hosts after execution.

T1071.002
File Transfer Protocols
MalwareQilin

Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.

T1082
System Information Discovery
MalwareQilin

Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.

T1083
File and Directory Discovery
MalwareQilin

Qilin can exclude specific directories and files from encryption.

T1087.001
Local Account
MalwareQilin

Qilin can list all local users found on a targeted system.

T1087.002
Domain Account
MalwareQilin

Qilin can use PowerShell cmdlets to enumerate domain users.

T1106
Native API
MalwareQilin

Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.

T1112
Modify Registry
MalwareQilin

Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.

T1134
Access Token Manipulation
MalwareQilin

Qilin can use an embedded Mimikatz module for token manipulation.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1190
Exploit Public-Facing Application
MalwareQilin

Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.

T1204.001
Malicious Link
MalwareQilin

Qilin has been executed by luring victims into clicking links in spearphishing emails.

T1204.002
Malicious File
MalwareQilin

Qilin has been delivered to victims through spearphishing emails with malicious attachments.

T1219.002
Remote Desktop Software
MalwareQilin

Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.

T1222
File and Directory Permissions Modification
MalwareQilin

Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.

T1480
Execution Guardrails
MalwareQilin

Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.

T1480.002
Mutual Exclusion
MalwareQilin

Qilin can create a mutex to ensure only one instance is running.

T1484.001
Group Policy Modification
MalwareQilin

Qilin has pushed a scheduled task via a Group Policy Object for payload execution.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1489
Service Stop
MalwareQilin

Qilin can terminate specific services on compromised hosts.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1491.001
Internal Defacement
MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

T1529
System Shutdown/Reboot
MalwareQilin

Qilin can initiate a reboot of the backup server to hinder recovery.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1547.004
Winlogon Helper DLL
MalwareQilin

Qilin can configure a Winlogon registry entry.

T1548.002
Bypass User Account Control
MalwareQilin

Qilin can bypass standard user access controls by using stolen tokens to launch processes at an elevated security context.

T1566.001
Spearphishing Attachment
MalwareQilin

Qilin has been delivered to victims through malicious email attachments.

T1566.002
Spearphishing Link
MalwareQilin

Qilin has been delivered via malicious links in spearphishing emails.

T1570
Lateral Tool Transfer
MalwareQilin

Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.

T1673
Virtual Machine Discovery
MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

T1678
Delay Execution
MalwareQilin

Qilin has the ability to delay execution.

T1680
Local Storage Discovery
MalwareQilin

Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.