Meta tags:
Headings (most frequently used words):
event, triggered, execution, installer, packages, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of, 18,
Text of the page (most frequently used words):
the (26), t1546 (22), scripts (17), #installer (17), retrieved (16), and (15), 2026 (13), installation (11), att (10), all (10), packages (10), for (10), execution (10), shai (9), hulud (9), september (9), with (9), package (8), 2022 (8), enterprise (7), supply (7), chain (7), attack (7), may (7), event (7), malicious (7), detection (6), april (6), 2025 (6), application (6), can (6), ics (5), mobile (5), none (5), techniques (5), teampcp (5), applejeus (5), macos (5), executed (5), postinstall (5), triggered (5), permissions (5), mitre (4), are (4), resources (4), data (4), sub (4), november (4), august (4), that (4), modified (4), content (4), install (4), 016 (4), execute (4), include (4), file (4), elevated (4), version (4), applications (4), these (4), adversaries (4), use (3), software (3), cti (3), components (3), mitigations (3), defenses (3), tactics (3), march (3), security (3), again (3), more (3), npm (3), microsoft (3), team (3), procedure (3), maintainer (3), persistence (3), process (3), dlls (3), during (3), name (3), technique (3), system (3), has (3), 3cx (3), windows (3), when (3), corporation (2), policy (2), domains (2), reference (2), campaigns (2), groups (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), july (2), mccarthy (2), strikes (2), research (2), worm (2), malware (2), patrick (2), wardle (2), 2019 (2), october (2), 2023 (2), 2021 (2), brandon (2), dalton (2), bundle (2), controls (2), msiexec (2), look (2), binaries (2), postinst (2), preinst (2), script (2), additional (2), processes (2), from (2), strategy (2), analytic (2), description (2), features (2), post (2), cloud (2), stealer (2), preinstall (2), download (2), lifecycle (2), hook (2), also (2), uses (2), plist (2), launch (2), daemon (2), linux (2), files (2), run (2), using (2), legitimate (2), such (2), other (2), after (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, unit, weaponizing, protectors, multi, stage, infrastructure, cohen, read, mini, tanstack, compromised, defender, guidance, detecting, investigating, defending, against, gianpietro, cutolo, aggressive, automated, fast, spreading, socket, merav, bar, rami, barak, sharoni, ongoing, delivering, stealing, justin, moore, compromises, ecosystem, updated, charlie, eriksen, s1ngularity, attackers, strike, pass, robert, falcone, josh, grunzweig, threat, brief, 3cxdesktopapp, january, tables, group, december, debian, manual, global, analysis, kaspersky, lab, great, 2018, operation, lazarus, hits, cryptocurrency, exchange, fake, 2020, june, osx, evilquest, uncovered, part, infection, nerves, tweaking, thwart, manipulation, rich, trouton, scripting, making, your, deployments, easier, one, time, references, exe, running, result, anomalous, creation, unexpected, custom, action, temp, directory, an0940, being, dpkg, rpm, operations, watch, spawns, writes, outside, scope, an0939, correlation, containing, unknown, abnormal, cli, usage, followed, child, originating, usr, sbin, an0938, via, det0330, this, type, cannot, easily, mitigated, preventive, since, based, abuse, inject, pre, within, json, payload, s9041, payloads, g1056, inserted, new, leveraged, s9008, extract, hidden, folder, s0584, added, dylib, dmg, c0057, examples, live, permalink, last, created, partyd0lphin, rodchenko, aleksandr, contributors, platforms, privilege, escalation, services, manage, installing, updating, uninstalling, routines, instructions, perform, actions, abused, msi, depending, distribution, versions, sometimes, called, root, postrm, prerm, have, distributed, user, installs, they, required, grant, administrative, allow, end, inherited, executable, establish, elevate, privileges, trigger, specific, contain, operating, needs, prior, well, complete, inherit, developers, often, prepare, environment, check, requirements, dependencies, remove, python, startup, hooks, 018, udev, rules, 017, component, object, model, hijacking, 015, emond, 014, powershell, profile, 013, image, options, injection, 012, shimming, 011, appinit, 010, appcert, 009, accessibility, 008, netsh, helper, dll, 007, lc_load_dylib, addition, 006, trap, 005, unix, shell, configuration, modification, 004, management, instrumentation, subscription, 003, screensaver, 002, change, default, association, 001, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, about, get, started, detections,
Text of the page (random words):
event triggered execution installer packages sub technique t1546 016 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise event triggered execution installer packages event triggered execution installer packages other sub techniques of event triggered execution 18 id name t1546 001 change default file association t1546 002 screensaver t1546 003 windows management instrumentation event subscription t1546 004 unix shell configuration modification t1546 005 trap t1546 006 lc_load_dylib addition t1546 007 netsh helper dll t1546 008 accessibility features t1546 009 appcert dlls t1546 010 appinit dlls t1546 011 application shimming t1546 012 image file execution options injection t1546 013 powershell profile t1546 014 emond t1546 015 component object model hijacking t1546 016 installer packages t1546 017 udev rules t1546 018 python startup hooks adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content installer packages are os specific and contain the resources an operating system needs to install applications on a system installer packages can include scripts that run prior to installation as well as after installation is complete installer scripts may inherit elevated permissions when executed developers often use these scripts to prepare the environment for installation check requirements download dependencies and remove files after installation 1 using legitimate applications adversaries have distributed applications with modified installer scripts to execute malicious content when a user installs the application they may be required to grant administrative permissions to allow the installation at the end of the installation process of the legitimate application content such as macos postinstall scripts can be executed with the inherited elevated permissions adversaries can use these scripts to execute a malicious executable or install other malicious components such as a launch daemon with the elevated permissions 2 3 4 5 depending on the distribution linux versions of package installer scripts are sometimes called maintainer scripts or post installation scripts these scripts can include preinst postinst prerm postrm scripts and run as root when executed for windows the microsoft installer services uses msi files to manage the installing updating and uninstalling of applications these installation routines may also include instructions to perform additional actions that may be abused by adversaries 6 id t1546 016 sub technique of t1546 ⓘ tactics privilege escalation persistence ⓘ platforms linux windows macos contributors brandon dalton partyd0lphin rodchenko aleksandr version 1 2 created 27 september 2022 last modified 12 may 2026 version permalink live version procedure examples id name description c0057 3cx supply chain attack during the 3cx supply chain attack applejeus added a malicious dylib file to a dmg installer package for the macos 3cx application 7 s0584 applejeus during applejeus s installation process it uses postinstall scripts to extract a hidden plist from the application s resources folder and execute the plist file as a launch daemon with elevated permissions 8 s9008 shai hulud shai hulud has inserted a new lifecycle hook to include postinstall 9 10 11 12 shai hulud has also leveraged the npm lifecycle hook preinstall 13 10 14 12 g1056 teampcp teampcp has modified software packages with preinstall scripts to download and execute malicious payloads 15 s9041 teampcp cloud stealer teampcp cloud stealer can inject malicious pre or post install scripts within package json for payload execution 16 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0330 detection strategy for t1546 016 event triggered execution via installer packages an0938 correlation of package install event with execution of postinstall scripts containing unknown binaries or abnormal cli usage look for usr sbin installer execution followed by child processes originating from postinstall script an0939 detection of maintainer scripts e g postinst preinst being modified or executed during dpkg or rpm operations watch for script content that spawns additional processes or writes outside package scope an0940 detection of msiexec exe running installer packages that result in anomalous process creation look for unexpected binaries executed by msiexec or custom action dlls in the temp directory references rich trouton 2019 august 9 installer package scripting making your deployments easier one at a time retrieved september 27 2022 brandon dalton 2022 august 9 a bundle of nerves tweaking macos security controls to thwart application bundle manipulation retrieved september 27 2022 patrick wardle 2020 june 29 osx evilquest uncovered part i infection persistence and more retrieved march 18 2021 global research analysis team kaspersky lab great 2018 august 23 operation applejeus lazarus hits cryptocurrency exchange with fake installer and macos malware retrieved september 27 2022 debian policy manual v4 6 1 1 2022 august 14 package maintainer scripts and installation procedure retrieved september 27 2022 microsoft 2021 january 7 installation procedure tables group retrieved december 27 2023 robert falcone josh grunzweig 2023 march 30 threat brief 3cxdesktopapp supply chain attack retrieved september 15 2025 patrick wardle 2019 october 12 pass the applejeus retrieved september 28 2022 charlie eriksen 2025 september 16 s1ngularity nx attackers strike again retrieved april 9 2026 justin moore 2025 november 25 shai hulud worm compromises npm ecosystem in supply chain attack updated november 26 retrieved april 9 2026 merav bar rami mccarthy barak sharoni 2025 september 16 shai hulud ongoing package supply chain worm delivering data stealing malware retrieved april 9 2026 socket research team 2025 november 24 shai hulud strikes again v2 retrieved april 9 2026 gianpietro cutolo 2025 november 26 shai hulud 2 0 aggressive automated and fast spreading retrieved april 9 2026 microsoft defender security team n d shai hulud 2 0 guidance for detecting investigating and defending against the supply chain attack retrieved april 9 2026 mccarthy r cohen a and read b 2026 may 12 mini shai hulud strikes again tanstack more npm packages compromised retrieved july 16 2026 unit 42 2026 march 31 weaponizing the protectors teampcp s multi stage supply chain attack on security infrastructure retrieved july 1 2026 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|