ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwarePrestige

Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection.

T1106
Native API
MalwareBankshot

Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA().

T1106
Native API
MalwareSharpDisco

SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`.

T1106
Native API
MalwarexCaon

xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API.

T1106
Native API
MalwarePony

Pony has used several Windows functions for various purposes.

T1106
Native API
MalwareNebulae

Nebulae has the ability to use CreateProcess to execute a process.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1106
Native API
MalwareMedusa Ransomware

Medusa Ransomware has leveraged Windows Native API functions to execute payloads.

T1106
Native API
MalwareRainyDay

The file collection tool used by RainyDay can utilize native API including ReadDirectoryChangeW for folder monitoring.

T1106
Native API
MalwareAppleSeed

AppleSeed has the ability to use multiple dynamically resolved API calls.

T1106
Native API
MalwareNETWIRE

NETWIRE can use Native API including CreateProcess GetProcessById, and WriteProcessMemory.

T1106
Native API
MalwareTinyTurla

TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions.

T1106
Native API
MalwareBOOKWORM

BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareHyperStack

HyperStack can use Windows API's ConnectNamedPipe and WNetAddConnection2 to detect incoming connections and connect to remote shares.

T1106
Native API
MalwareBad Rabbit

Bad Rabbit has used various Windows API calls.

T1106
Native API
MalwareIMAPLoader

IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`.

T1106
Native API
MalwareAria-body

Aria-body has the ability to launch files using ShellExecute.

T1106
Native API
MalwareEmotet

Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares.

T1106
Native API
MalwareDynoWiper

DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion.

T1106
Native API
MalwareBADHATCH

BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine.

T1106
Native API
MalwarePUBLOAD

PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareSystemBC

SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities.

T1106
Native API
MalwareWoody RAT

Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection.

T1106
Native API
MalwareMafalda

Mafalda can use a variety of API calls.

T1106
Native API
MalwareCANONSTAGER

CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload.

T1106
Native API
MalwarePolyglotDuke

PolyglotDuke can use LoadLibraryW and CreateProcess to load and execute code.

T1106
Native API
MalwareSombRAT

SombRAT has the ability to respawn itself using ShellExecuteW and CreateProcessW.

T1106
Native API
MalwareODAgent

ODAgent can pass commands using native APIs.

T1106
Native API
MalwareGuLoader

GuLoader can use a number of different APIs for discovery and execution.

T1106
Native API
MalwareWastedLocker

WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.

T1106
Native API
MalwareInvisiMole

InvisiMole can use winapiexec tool for indirect execution of ShellExecuteW and CreateProcessA.

T1106
Native API
MalwareCLAIMLOADER

CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`.

T1106
Native API
MalwareVolgmer

Volgmer executes payloads using the Windows API call CreateProcessW().

T1106
Native API
MalwareWhisperGate

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.

T1106
Native API
MalwareConti

Conti has used API calls during execution.

T1106
Native API
MalwareMispadu

Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory.

T1106
Native API
MalwareDiavol

Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack.

T1106
Native API
MalwareSiloscape

Siloscape makes various native API calls.

T1106
Native API
MalwareRustyWater

RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object.  Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe.

T1106
Native API
MalwareIcedID

IcedID has called ZwWriteVirtualMemory, ZwProtectVirtualMemory, ZwQueueApcThread, and NtResumeThread to inject itself into a remote process.

T1106
Native API
MalwareHTTPTroy

HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory.

T1106
Native API
MalwareMarkiRAT

MarkiRAT can run the ShellExecuteW API via the Windows Command Shell.

T1106
Native API
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`.

T1106
Native API
MalwareFatDuke

FatDuke can call ShellExecuteW to open the default browser on the URL localhost.

T1106
Native API
MalwareDCSrv

DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process.

T1106
Native API
MalwareDRATzarus

DRATzarus can use various API calls to see if it is running in a sandbox.

T1106
Native API
MalwareRising Sun

Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`.

T1106
Native API
MalwareShimRat

ShimRat has used Windows API functions to install the service and shim.

T1106
Native API
MalwareChrommme

Chrommme can use Windows API including `WinExec` for execution.

T1106
Native API
MalwareAvaddon

Avaddon has used the Windows Crypto API to generate an AES key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.