Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareStuxnet | Stuxnet uses a Windows rootkit to mask its binaries and other relevant files. |
| T1014 Rootkit |
MalwareMEDUSA | MEDUSA is a rootkit with command execution and credential logging capabilities. |
| T1014 Rootkit |
MalwareCOATHANGER | COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices. |
| T1014 Rootkit |
MalwareUmbreon | Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware. |
| T1014 Rootkit |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64(). |
| T1014 Rootkit |
MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| T1014 Rootkit |
MalwareSkidmap | Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low. |
| T1014 Rootkit |
MalwareLine Dancer | Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms. |
| T1014 Rootkit |
MalwareREPTILE | REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections. |
| T1014 Rootkit |
MalwareZeroaccess | Zeroaccess is a kernel-mode rootkit. |
| T1014 Rootkit |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a rootkit on a system. |
| T1014 Rootkit |
MalwareUroburos | Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components. |
| T1014 Rootkit |
MalwareWinnti for Linux | Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity. |
| T1014 Rootkit |
MalwareHikit | |
| T1014 Rootkit |
MalwareDrovorub | Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view. |
| T1014 Rootkit |
MalwarePoisonIvy | PoisonIvy starts a rootkit from a malicious file dropped to disk. |
| T1014 Rootkit |
MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| T1014 Rootkit |
MalwareRamsay | Ramsay has included a rootkit to evade defenses. |
| T1014 Rootkit |
MalwareCarberp | Carberp has used user mode rootkit techniques to remain hidden on the system. |
| T1014 Rootkit |
MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| T1014 Rootkit |
MalwareHIDEDRV | HIDEDRV is a rootkit that hides certain operating system artifacts. |
| T1014 Rootkit |
MalwareHiddenWasp | HiddenWasp uses a rootkit to hook and implement functions on the system. |
| T1014 Rootkit |
MalwareWarzoneRAT | WarzoneRAT can include a rootkit to hide processes, files, and startup. |
| T1014 Rootkit |
ToolHTRAN | HTRAN can install a rootkit to hide network connections from the host OS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.