Execution Guardrails

T1480

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.

Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within. This use of guardrails is distinct from typical Virtualization/Sandbox Evasion. While use of Virtualization/Sandbox Evasion may involve checking for known sandbox values and continuing with execution only if there is no match, the use of guardrails will involve checking for an expected target-specific value and only continuing with execution if there is such a match.

Adversaries may identify and block certain user-agents to evade defenses and narrow the scope of their attack to victims and platforms on which it will be most effective. A user-agent self-identifies data such as a user's software application, operating system, vendor, and version. Adversaries may check user-agents for operating system identification and then only serve malware for the exploitable software while ignoring all other operating systems.

Detection rules1

Rules on DetectionCode tagged with T1480 or one of its sub-techniques.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData sourceTechnique
Linux Auditd AI CLI Permission Override ActivatedAnomalyNULLLinux Auditd ProctitleT1480

Sub-techniques2

IDNameExamples
T1480.001Environmental Keying10
T1480.002Mutual Exclusion20

Groups4

Software45

Show 21 more

Campaigns1

Procedure examples50

Groups4

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites.

GroupBlackByte

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.

GroupContagious Interview

Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads.

GroupGamaredon Group

Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations.

Software45

Used byProcedure example
MalwareAkira _v2

Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.

MalwareAnchor

Anchor can terminate itself if specific execution flags are not present.

MalwareApostle

Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function.

MalwareBitPaymer

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

MalwareBlackByte Ransomware

BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate.

MalwareBOLDMOVE

BOLDMOVE verifies it is executing from a specific path during execution.

MalwareBoomBox

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

MalwareBPFDoor

BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time.

View all 45 software examples

Campaigns1

Used byProcedure example
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations.

References3

  1. FireEye Kevin Mandia Guardrails Open source
    Shoorbajee, Z. (2018, June 1). Playing nice? FireEye CEO says U.S. malware is more restrained than adversaries'. Retrieved January 17, 2019.
  2. FireEye Outlook Dec 2019 Open source
    McWhirt, M., Carr, N., Bienstock, D. (2019, December 4). Breaking the Rules: A Tough Outlook for Home Page Attacks (CVE-2017-11774). Retrieved June 23, 2020.
  3. Trellix-Qakbot Open source
    Pham Duy Phuc, John Fokker J.E., Alejandro Houspanossian and Mathanraj Thangaraju. (2023, March 7). Qakbot Evolves to OneNote Malware Distribution. Retrieved June 7, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.