Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwarePrestige | Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection. |
| T1106 Native API |
MalwareBankshot | Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA(). |
| T1106 Native API |
MalwareSharpDisco | SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`. |
| T1106 Native API |
MalwarexCaon | xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API. |
| T1106 Native API |
MalwarePony | Pony has used several Windows functions for various purposes. |
| T1106 Native API |
MalwareNebulae | Nebulae has the ability to use |
| T1106 Native API |
MalwareTONESHELL | TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
| T1106 Native API |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged Windows Native API functions to execute payloads. |
| T1106 Native API |
MalwareRainyDay | The file collection tool used by RainyDay can utilize native API including |
| T1106 Native API |
MalwareAppleSeed | AppleSeed has the ability to use multiple dynamically resolved API calls. |
| T1106 Native API |
MalwareNETWIRE | NETWIRE can use Native API including |
| T1106 Native API |
MalwareTinyTurla | TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions. |
| T1106 Native API |
MalwareBOOKWORM | BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareHyperStack | HyperStack can use Windows API's |
| T1106 Native API |
MalwareBad Rabbit | Bad Rabbit has used various Windows API calls. |
| T1106 Native API |
MalwareIMAPLoader | IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`. |
| T1106 Native API |
MalwareAria-body | Aria-body has the ability to launch files using |
| T1106 Native API |
MalwareEmotet | Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares. |
| T1106 Native API |
MalwareDynoWiper | DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion. |
| T1106 Native API |
MalwareBADHATCH | BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine. |
| T1106 Native API |
MalwarePUBLOAD | PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareSystemBC | SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities. |
| T1106 Native API |
MalwareWoody RAT | Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection. |
| T1106 Native API |
MalwareMafalda | Mafalda can use a variety of API calls. |
| T1106 Native API |
MalwareCANONSTAGER | CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload. |
| T1106 Native API |
MalwarePolyglotDuke | PolyglotDuke can use |
| T1106 Native API |
MalwareSombRAT | SombRAT has the ability to respawn itself using |
| T1106 Native API |
MalwareODAgent | ODAgent can pass commands using native APIs. |
| T1106 Native API |
MalwareGuLoader | GuLoader can use a number of different APIs for discovery and execution. |
| T1106 Native API |
MalwareWastedLocker | WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload. |
| T1106 Native API |
MalwareInvisiMole | InvisiMole can use winapiexec tool for indirect execution of |
| T1106 Native API |
MalwareCLAIMLOADER | CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`. |
| T1106 Native API |
MalwareVolgmer | Volgmer executes payloads using the Windows API call CreateProcessW(). |
| T1106 Native API |
MalwareWhisperGate | WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls. |
| T1106 Native API |
MalwareConti | Conti has used API calls during execution. |
| T1106 Native API |
MalwareMispadu | Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory. |
| T1106 Native API |
MalwareDiavol | Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack. |
| T1106 Native API |
MalwareSiloscape | Siloscape makes various native API calls. |
| T1106 Native API |
MalwareRustyWater | RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object. Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe. |
| T1106 Native API |
MalwareIcedID | IcedID has called |
| T1106 Native API |
MalwareHTTPTroy | HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory. |
| T1106 Native API |
MalwareMarkiRAT | MarkiRAT can run the ShellExecuteW API via the Windows Command Shell. |
| T1106 Native API |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`. |
| T1106 Native API |
MalwareFatDuke | FatDuke can call |
| T1106 Native API |
MalwareDCSrv | DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process. |
| T1106 Native API |
MalwareDRATzarus | DRATzarus can use various API calls to see if it is running in a sandbox. |
| T1106 Native API |
MalwareRising Sun | Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`. |
| T1106 Native API |
MalwareShimRat | ShimRat has used Windows API functions to install the service and shim. |
| T1106 Native API |
MalwareChrommme | Chrommme can use Windows API including `WinExec` for execution. |
| T1106 Native API |
MalwareAvaddon | Avaddon has used the Windows Crypto API to generate an AES key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.