Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.
Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within. This use of guardrails is distinct from typical Virtualization/Sandbox Evasion. While use of Virtualization/Sandbox Evasion may involve checking for known sandbox values and continuing with execution only if there is no match, the use of guardrails will involve checking for an expected target-specific value and only continuing with execution if there is such a match.
Adversaries may identify and block certain user-agents to evade defenses and narrow the scope of their attack to victims and platforms on which it will be most effective. A user-agent self-identifies data such as a user's software application, operating system, vendor, and version. Adversaries may check user-agents for operating system identification and then only serve malware for the exploitable software while ignoring all other operating systems.
Rules on DetectionCode tagged with T1480 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Linux Auditd AI CLI Permission Override Activated | Anomaly | NULL | Linux Auditd Proctitle | T1480 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites. |
| GroupBlackByte | BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute. |
| GroupContagious Interview | Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads. |
| GroupGamaredon Group | Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations. |
| Used by | Procedure example |
|---|---|
| MalwareAkira _v2 | Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined. |
| MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| MalwareApostle | Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| MalwareBitPaymer | BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| MalwareBlackByte Ransomware | BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| MalwareBOLDMOVE | BOLDMOVE verifies it is executing from a specific path during execution. |
| MalwareBoomBox | BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found. |
| MalwareBPFDoor | BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time. |
| Used by | Procedure example |
|---|---|
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.