ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055.001×

56 examples

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareBumblebee

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.001
Dynamic-link Library Injection
MalwareStuxnet

Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.

T1055.001
Dynamic-link Library Injection
MalwareGet2

Get2 has the ability to inject DLLs into processes.

T1055.001
Dynamic-link Library Injection
MalwareEmissary

Emissary injects its DLL file into a newly spawned Internet Explorer process.

T1055.001
Dynamic-link Library Injection
MalwarePS1

PS1 can inject its payload DLL Into memory.

T1055.001
Dynamic-link Library Injection
MalwareHavoc

Havoc has DLL spawn and injection modules.

T1055.001
Dynamic-link Library Injection
MalwareMatryoshka

Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT.

T1055.001
Dynamic-link Library Injection
MalwareTONESHELL

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1055.001
Dynamic-link Library Injection
MalwareAria-body

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1055.001
Dynamic-link Library Injection
MalwareEmotet

Emotet has been observed injecting in to Explorer.exe and other processes.

T1055.001
Dynamic-link Library Injection
MalwareBADHATCH

BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine.

T1055.001
Dynamic-link Library Injection
MalwareSombRAT

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1055.001
Dynamic-link Library Injection
MalwareConti

Conti has loaded an encrypted DLL into memory and then executes it.

T1055.001
Dynamic-link Library Injection
MalwareKazuar

If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes.

T1055.001
Dynamic-link Library Injection
MalwareBlackEnergy

BlackEnergy injects its DLL component into svchost.exe.

T1055.001
Dynamic-link Library Injection
MalwareDarkTortilla

DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection.

T1055.001
Dynamic-link Library Injection
MalwareDyre

Dyre injects into other processes to load modules.

T1055.001
Dynamic-link Library Injection
MalwareRemsec

Remsec can perform DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareSykipot

Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe.

T1055.001
Dynamic-link Library Injection
MalwareMongall

Mongall can inject a DLL into `rundll32.exe` for execution.

T1055.001
Dynamic-link Library Injection
MalwareNetwalker

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1055.001
Dynamic-link Library Injection
MalwareSaint Bot

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.001
Dynamic-link Library Injection
MalwareSagerunex

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1055.001
Dynamic-link Library Injection
MalwareUroburos

Uroburos can use DLL injection to load embedded files and modules.

T1055.001
Dynamic-link Library Injection
MalwareMetamorfo

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1055.001
Dynamic-link Library Injection
MalwarePipeMon

PipeMon can inject its modules into various processes using reflective DLL loading.

T1055.001
Dynamic-link Library Injection
MalwareRARSTONE

After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system.

T1055.001
Dynamic-link Library Injection
MalwareMegaCortex

MegaCortex loads injecthelper.dll into a newly created rundll32.exe process.

T1055.001
Dynamic-link Library Injection
MalwareSDBbot

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

T1055.001
Dynamic-link Library Injection
MalwareDerusbi

Derusbi injects itself into the secure shell (SSH) process.

T1055.001
Dynamic-link Library Injection
MalwareRATANKBA

RATANKBA performs a reflective DLL injection using a given pid.

T1055.001
Dynamic-link Library Injection
MalwareFinFisher

FinFisher injects itself into various processes depending on whether it is low integrity or high integrity.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1055.001
Dynamic-link Library Injection
MalwareTaidoor

Taidoor can perform DLL loading.

T1055.001
Dynamic-link Library Injection
MalwarePoisonIvy

PoisonIvy can inject a malicious DLL into a process.

T1055.001
Dynamic-link Library Injection
MalwareTajMahal

TajMahal has the ability to inject DLLs for malicious plugins into running processes.

T1055.001
Dynamic-link Library Injection
MalwareCarbon

Carbon has a command to inject code into a process.

T1055.001
Dynamic-link Library Injection
MalwareRamsay

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.

T1055.001
Dynamic-link Library Injection
MalwareCarberp

Carberp's bootkit can inject a malicious DLL into the address space of running processes.

T1055.001
Dynamic-link Library Injection
MalwareFunnyDream

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1055.001
Dynamic-link Library Injection
MalwareZxShell

ZxShell is injected into a shared SVCHOST process.

T1055.001
Dynamic-link Library Injection
MalwareMaze

Maze has injected the malware DLL into a target process.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1055.001
Dynamic-link Library Injection
MalwareHeyoka Backdoor

Heyoka Backdoor can inject a DLL into rundll32.exe for execution.

T1055.001
Dynamic-link Library Injection
MalwareQilin

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1055.001
Dynamic-link Library Injection
MalwareSocksbot

Socksbot creates a suspended svchost process and injects its DLL into it.

T1055.001
Dynamic-link Library Injection
MalwareHIDEDRV

HIDEDRV injects a DLL for Downdelph into the explorer.exe process.

T1055.001
Dynamic-link Library Injection
MalwareShadowPad

ShadowPad has injected a DLL into svchost.exe.

T1055.001
Dynamic-link Library Injection
MalwareGelsemium

Gelsemium has the ability to inject DLLs into specific processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.