ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1014×

24 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareStuxnet

Stuxnet uses a Windows rootkit to mask its binaries and other relevant files.

T1014
Rootkit
MalwareMEDUSA

MEDUSA is a rootkit with command execution and credential logging capabilities.

T1014
Rootkit
MalwareCOATHANGER

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

T1014
Rootkit
MalwareUmbreon

Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware.

T1014
Rootkit
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1014
Rootkit
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareSkidmap

Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.

T1014
Rootkit
MalwareLine Dancer

Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms.

T1014
Rootkit
MalwareREPTILE

REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections.

T1014
Rootkit
MalwareZeroaccess

Zeroaccess is a kernel-mode rootkit.

T1014
Rootkit
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a rootkit on a system.

T1014
Rootkit
MalwareUroburos

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

T1014
Rootkit
MalwareWinnti for Linux

Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity.

T1014
Rootkit
MalwareHikit

Hikit is a Rootkit that has been used by Axiom.

T1014
Rootkit
MalwareDrovorub

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

T1014
Rootkit
MalwarePoisonIvy

PoisonIvy starts a rootkit from a malicious file dropped to disk.

T1014
Rootkit
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareRamsay

Ramsay has included a rootkit to evade defenses.

T1014
Rootkit
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1014
Rootkit
MalwareHIDEDRV

HIDEDRV is a rootkit that hides certain operating system artifacts.

T1014
Rootkit
MalwareHiddenWasp

HiddenWasp uses a rootkit to hook and implement functions on the system.

T1014
Rootkit
MalwareWarzoneRAT

WarzoneRAT can include a rootkit to hide processes, files, and startup.

T1014
Rootkit
ToolHTRAN

HTRAN can install a rootkit to hide network connections from the host OS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.