Real-world descriptions of how a group, tool or campaign used a technique.
65 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareTrickBot | TrickBot has used |
| T1055 Process Injection |
MalwareNinja | Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes. |
| T1055 Process Injection |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can inject files into running processes. |
| T1055 Process Injection |
MalwareBumblebee | Bumblebee can inject code into multiple processes on infected endpoints. |
| T1055 Process Injection |
MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| T1055 Process Injection |
MalwareCOATHANGER | COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library. |
| T1055 Process Injection |
MalwareSmoke Loader | Smoke Loader injects into the Internet Explorer process. |
| T1055 Process Injection |
MalwareAuditCred | AuditCred can inject code from files to other running processes. |
| T1055 Process Injection |
MalwareNETWIRE | NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe. |
| T1055 Process Injection |
MalwareDUSTTRAP | DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins. |
| T1055 Process Injection |
MalwareBADHATCH | BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| T1055 Process Injection |
MalwareAvenger | Avenger has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareWoody RAT | Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread. |
| T1055 Process Injection |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption. |
| T1055 Process Injection |
MalwareHOPLIGHT | HOPLIGHT has injected into running processes. |
| T1055 Process Injection |
MalwareGuLoader | GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process. |
| T1055 Process Injection |
MalwareInvisiMole | InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure. |
| T1055 Process Injection |
MalwareMispadu | Mispadu's binary is injected into memory via `WriteProcessMemory`. |
| T1055 Process Injection |
MalwareNavRAT | NavRAT copies itself into a running Internet Explorer process to evade detection. |
| T1055 Process Injection |
MalwareCostaBricks | CostaBricks can inject a payload into the memory of a compromised host. |
| T1055 Process Injection |
MalwareHyperBro | HyperBro can run shellcode it injects into a newly created process. |
| T1055 Process Injection |
MalwareROKRAT | ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`. |
| T1055 Process Injection |
MalwareDyre | Dyre has the ability to directly inject its code into the web browser process. |
| T1055 Process Injection |
MalwareNOOPLDR | NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe. |
| T1055 Process Injection |
MalwareClambling | Clambling can inject into the `svchost.exe` process for execution. |
| T1055 Process Injection |
MalwarePureCrypter | PureCrypter can inject its final stage into another process on the targeted system. |
| T1055 Process Injection |
MalwareGazer | Gazer injects its communication module into an Internet accessible process through which it performs C2. |
| T1055 Process Injection |
MalwareTSCookie | TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes. |
| T1055 Process Injection |
MalwareLODEINFO | LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1055 Process Injection |
Malwaregh0st RAT | gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function. |
| T1055 Process Injection |
MalwareJHUHUGIT | JHUHUGIT performs code injection injecting its own functions to browser processes. |
| T1055 Process Injection |
MalwareStoneDrill | StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser. |
| T1055 Process Injection |
MalwareAttor | Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection. |
| T1055 Process Injection |
MalwareBazar | Bazar can inject code through calling |
| T1055 Process Injection |
MalwareHiddenFace | HiddenFace can inject code directly into legitimate applications. |
| T1055 Process Injection |
MalwareRyuk | Ryuk has injected itself into remote processes to encrypt files using a combination of |
| T1055 Process Injection |
MalwareABK | ABK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwarePandora | Pandora can start and inject code into a new `svchost` process. |
| T1055 Process Injection |
MalwareCobalt Strike | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary. |
| T1055 Process Injection |
MalwareWingbird | Wingbird performs multiple process injections to hijack system processes and execute malicious code. |
| T1055 Process Injection |
MalwareREvil | REvil can inject itself into running processes on a compromised host. |
| T1055 Process Injection |
MalwareCardinal RAT | Cardinal RAT injects into a newly spawned process created from a native Windows executable. |
| T1055 Process Injection |
MalwareEgregor | Egregor can inject its payload into iexplore.exe process. |
| T1055 Process Injection |
MalwareANDROMEDA | ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| T1055 Process Injection |
MalwareJPIN | JPIN can inject content into lsass.exe to load a module. |
| T1055 Process Injection |
MalwaremetaMain | metaMain can inject the loader file, Speech02.db, into a process. |
| T1055 Process Injection |
MalwareMis-Type | Mis-Type has been injected directly into a running process, including `explorer.exe`. |
| T1055 Process Injection |
MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055 Process Injection |
MalwareShadowPad | ShadowPad has injected an install module into a newly created process. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.