Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareFlagpro | Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`. |
| T1106 Native API |
MalwareXAgentOSX | XAgentOSX contains the execFile function to execute a specified file on the system using the NSTask:launch method. |
| T1106 Native API |
MalwareCostaBricks | CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`. |
| T1106 Native API |
MalwareHyperBro | HyperBro has the ability to run an application ( |
| T1106 Native API |
MalwarePteranodon | Pteranodon has used various API calls. |
| T1106 Native API |
MalwareDarkTortilla | DarkTortilla can use a variety of API calls for persistence and defense evasion. |
| T1106 Native API |
MalwareROKRAT | ROKRAT can use a variety of API calls to execute shellcode. |
| T1106 Native API |
MalwareSplatDropper | SplatDropper has utilized hashed Native Windows API calls. |
| T1106 Native API |
MalwareBabuk | Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution. |
| T1106 Native API |
MalwareExbyte | Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges. |
| T1106 Native API |
MalwarePlugX | PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process. |
| T1106 Native API |
MalwareBisonal | Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread. |
| T1106 Native API |
MalwareNOOPLDR | NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection. |
| T1106 Native API |
MalwareS-Type | S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`. |
| T1106 Native API |
MalwareExplosive | Explosive has a function to call the OpenClipboard wrapper. |
| T1106 Native API |
MalwareLightNeuron | LightNeuron is capable of starting a process using CreateProcess. |
| T1106 Native API |
MalwareCuba | Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum. |
| T1106 Native API |
MalwareAkira | Akira executes native Windows functions such as |
| T1106 Native API |
MalwareDarkGate | DarkGate uses the native Windows API |
| T1106 Native API |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to directly call native Windows API items during execution. |
| T1106 Native API |
MalwareSVCReady | SVCReady can use Windows API calls to gather information from an infected host. |
| T1106 Native API |
MalwareThiefQuest | ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration. |
| T1106 Native API |
MalwareFoggyWeb | FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed. |
| T1106 Native API |
MalwareNetwalker | Netwalker can use Windows API functions to inject the ransomware DLL. |
| T1106 Native API |
MalwareLatrodectus | Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`. |
| T1106 Native API |
MalwareSaint Bot | Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`. |
| T1106 Native API |
MalwareChaes | Chaes used the |
| T1106 Native API |
MalwareLODEINFO | LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode. |
| T1106 Native API |
MalwareMuddyViper | MuddyViper has the ability to relaunch itself using the `CreateProcessW` API. |
| T1106 Native API |
MalwareFooder | Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution. |
| T1106 Native API |
MalwareSagerunex | Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic. |
| T1106 Native API |
MalwareLP-Notes | LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials. |
| T1106 Native API |
MalwareRoyal | Royal can use multiple APIs for discovery, communication, and execution. |
| T1106 Native API |
MalwareBendyBear | BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing. |
| T1106 Native API |
MalwareUroburos | Uroburos can use native Windows APIs including `GetHostByName`. |
| T1106 Native API |
MalwareMetamorfo | Metamorfo has used native WINAPI calls. |
| T1106 Native API |
MalwareEmbargo | Embargo has leveraged Windows Native API functions to execute its operations. |
| T1106 Native API |
MalwareBandook | Bandook has used the ShellExecuteW() function call. |
| T1106 Native API |
MalwarePipeMon | PipeMon's first stage has been executed by a call to |
| T1106 Native API |
MalwareKONNI | KONNI has hardcoded API calls within its functions to use on the victim's machine. |
| T1106 Native API |
Malwaregh0st RAT | gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions. |
| T1106 Native API |
MalwareBlack Basta | Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion. |
| T1106 Native API |
MalwareAttor | Attor's dispatcher has used CreateProcessW API for execution. |
| T1106 Native API |
MalwareLitePower | LitePower can use various API calls. |
| T1106 Native API |
MalwareMegaCortex | After escalating privileges, MegaCortex calls |
| T1106 Native API |
MalwareBoxCaon | BoxCaon has used Windows API calls to obtain information about the compromised host. |
| T1106 Native API |
MalwareNightClub | NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`. |
| T1106 Native API |
MalwareMosquito | Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions. |
| T1106 Native API |
MalwareRTM | RTM can use the |
| T1106 Native API |
MalwareQUIETCANARY | QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.