Real-world descriptions of how a group, tool or campaign used a technique.
203 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareTrickBot | TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used |
| T1106 Native API |
MalwareNinja | The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption. |
| T1106 Native API |
MalwarePikabot | Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution. |
| T1106 Native API |
MalwareRCSession | RCSession can use WinSock API for communication including |
| T1106 Native API |
MalwareSynAck | SynAck parses the export tables of system DLLs to locate and call various Windows API functions. |
| T1106 Native API |
MalwareBumblebee | Bumblebee can use multiple Native APIs. |
| T1106 Native API |
MalwareAmadey | Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`. |
| T1106 Native API |
MalwareRDFSNIFFER | RDFSNIFFER has used several Win32 API functions to interact with the victim machine. |
| T1106 Native API |
MalwareTorisma | Torisma has used various Windows API calls. |
| T1106 Native API |
MalwareStuxnet | Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels. |
| T1106 Native API |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect". |
| T1106 Native API |
MalwareAvosLocker | AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`. |
| T1106 Native API |
MalwarePAKLOG | PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions. |
| T1106 Native API |
MalwareSardonic | Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running. |
| T1106 Native API |
MalwareWindTail | WindTail can invoke Apple APIs |
| T1106 Native API |
MalwareMisdat | Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`. |
| T1106 Native API |
MalwareHAWKBALL | HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity. |
| T1106 Native API |
MalwareHeartCrypt | HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources. |
| T1106 Native API |
MalwareUrsnif | Ursnif has used |
| T1106 Native API |
MalwareHavoc | Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection. |
| T1106 Native API |
MalwarePrestige | Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection. |
| T1106 Native API |
MalwareBankshot | Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA(). |
| T1106 Native API |
MalwareSharpDisco | SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`. |
| T1106 Native API |
MalwarexCaon | xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API. |
| T1106 Native API |
MalwarePony | Pony has used several Windows functions for various purposes. |
| T1106 Native API |
MalwareNebulae | Nebulae has the ability to use |
| T1106 Native API |
MalwareTONESHELL | TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
| T1106 Native API |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged Windows Native API functions to execute payloads. |
| T1106 Native API |
MalwareRainyDay | The file collection tool used by RainyDay can utilize native API including |
| T1106 Native API |
MalwareAppleSeed | AppleSeed has the ability to use multiple dynamically resolved API calls. |
| T1106 Native API |
MalwareNETWIRE | NETWIRE can use Native API including |
| T1106 Native API |
MalwareTinyTurla | TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions. |
| T1106 Native API |
MalwareBOOKWORM | BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareHyperStack | HyperStack can use Windows API's |
| T1106 Native API |
MalwareBad Rabbit | Bad Rabbit has used various Windows API calls. |
| T1106 Native API |
MalwareIMAPLoader | IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`. |
| T1106 Native API |
MalwareAria-body | Aria-body has the ability to launch files using |
| T1106 Native API |
MalwareEmotet | Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares. |
| T1106 Native API |
MalwareDynoWiper | DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion. |
| T1106 Native API |
MalwareBADHATCH | BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine. |
| T1106 Native API |
MalwarePUBLOAD | PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareSystemBC | SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities. |
| T1106 Native API |
MalwareWoody RAT | Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection. |
| T1106 Native API |
MalwareMafalda | Mafalda can use a variety of API calls. |
| T1106 Native API |
MalwareCANONSTAGER | CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload. |
| T1106 Native API |
MalwarePolyglotDuke | PolyglotDuke can use |
| T1106 Native API |
MalwareSombRAT | SombRAT has the ability to respawn itself using |
| T1106 Native API |
MalwareODAgent | ODAgent can pass commands using native APIs. |
| T1106 Native API |
MalwareGuLoader | GuLoader can use a number of different APIs for discovery and execution. |
| T1106 Native API |
MalwareWastedLocker | WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.