ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareFlagpro

Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`.

T1106
Native API
MalwareXAgentOSX

XAgentOSX contains the execFile function to execute a specified file on the system using the NSTask:launch method.

T1106
Native API
MalwareCostaBricks

CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`.

T1106
Native API
MalwareHyperBro

HyperBro has the ability to run an application (CreateProcessW) or script/file (ShellExecuteW) via API.

T1106
Native API
MalwarePteranodon

Pteranodon has used various API calls.

T1106
Native API
MalwareDarkTortilla

DarkTortilla can use a variety of API calls for persistence and defense evasion.

T1106
Native API
MalwareROKRAT

ROKRAT can use a variety of API calls to execute shellcode.

T1106
Native API
MalwareSplatDropper

SplatDropper has utilized hashed Native Windows API calls.

T1106
Native API
MalwareBabuk

Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution.

T1106
Native API
MalwareExbyte

Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges.

T1106
Native API
MalwarePlugX

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.

T1106
Native API
MalwareBisonal

Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread.

T1106
Native API
MalwareNOOPLDR

NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection.

T1106
Native API
MalwareS-Type

S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`.

T1106
Native API
MalwareExplosive

Explosive has a function to call the OpenClipboard wrapper.

T1106
Native API
MalwareLightNeuron

LightNeuron is capable of starting a process using CreateProcess.

T1106
Native API
MalwareCuba

Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.

T1106
Native API
MalwareAkira

Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.

T1106
Native API
MalwareDarkGate

DarkGate uses the native Windows API CallWindowProc() to decode and launch encoded shellcode payloads during execution. DarkGate can call kernel mode functions directly to hide the use of process hollowing methods during execution. DarkGate has also used the `CreateToolhelp32Snapshot`, `GetFileAttributesA` and `CreateProcessA` functions to obtain a list of running processes, to check for security products and to execute its malware.

T1106
Native API
MalwareLockBit 3.0

LockBit 3.0 has the ability to directly call native Windows API items during execution.

T1106
Native API
MalwareSVCReady

SVCReady can use Windows API calls to gather information from an infected host.

T1106
Native API
MalwareThiefQuest

ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration.

T1106
Native API
MalwareFoggyWeb

FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed.

T1106
Native API
MalwareNetwalker

Netwalker can use Windows API functions to inject the ransomware DLL.

T1106
Native API
MalwareLatrodectus

Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`.

T1106
Native API
MalwareSaint Bot

Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`.

T1106
Native API
MalwareChaes

Chaes used the CreateFileW() API function with read permissions to access downloaded payloads.

T1106
Native API
MalwareLODEINFO

LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode.

T1106
Native API
MalwareMuddyViper

MuddyViper has the ability to relaunch itself using the `CreateProcessW` API.

T1106
Native API
MalwareFooder

Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution.

T1106
Native API
MalwareSagerunex

Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic.

T1106
Native API
MalwareLP-Notes

LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials.

T1106
Native API
MalwareRoyal

Royal can use multiple APIs for discovery, communication, and execution.

T1106
Native API
MalwareBendyBear

BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing.

T1106
Native API
MalwareUroburos

Uroburos can use native Windows APIs including `GetHostByName`.

T1106
Native API
MalwareMetamorfo

Metamorfo has used native WINAPI calls.

T1106
Native API
MalwareEmbargo

Embargo has leveraged Windows Native API functions to execute its operations.

T1106
Native API
MalwareBandook

Bandook has used the ShellExecuteW() function call.

T1106
Native API
MalwarePipeMon

PipeMon's first stage has been executed by a call to CreateProcess with the decryption password in an argument. PipeMon has used a call to LoadLibrary to load its installer.

T1106
Native API
MalwareKONNI

KONNI has hardcoded API calls within its functions to use on the victim's machine.

T1106
Native API
Malwaregh0st RAT

gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions.

T1106
Native API
MalwareBlack Basta

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1106
Native API
MalwareAttor

Attor's dispatcher has used CreateProcessW API for execution.

T1106
Native API
MalwareLitePower

LitePower can use various API calls.

T1106
Native API
MalwareMegaCortex

After escalating privileges, MegaCortex calls TerminateProcess(), CreateRemoteThread, and other Win32 APIs.

T1106
Native API
MalwareBoxCaon

BoxCaon has used Windows API calls to obtain information about the compromised host.

T1106
Native API
MalwareNightClub

NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`.

T1106
Native API
MalwareMosquito

Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions.

T1106
Native API
MalwareRTM

RTM can use the FindNextUrlCacheEntryA and FindFirstUrlCacheEntryA functions to search for specific strings within browser history.

T1106
Native API
MalwareQUIETCANARY

QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.