ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep.

T1106
Native API
MalwareSodaMaster

SodaMaster can use RegOpenKeyW to access the Registry.

T1106
Native API
MalwareGrandoreiro

Grandoreiro can execute through the WinExec API.

T1106
Native API
MalwareZxxZ

ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`.

T1106
Native API
MalwareCaminho

Caminho can use `System.Net.WebClient.downloadString()` for file download.

T1106
Native API
MalwareBazar

Bazar can use various APIs to allocate memory and facilitate code execution/injection.

T1106
Native API
MalwareXLoader

XLoader uses the native Windows API for functionality, including defense evasion.

T1106
Native API
MalwareRyuk

Ryuk has used multiple native APIs including ShellExecuteW to run executables,GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1106
Native API
MalwareKapeka

Kapeka utilizes WinAPI calls to gather victim system information.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1106
Native API
MalwareEvilBunny

EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox.

T1106
Native API
MalwareHotCroissant

HotCroissant can perform dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings.

T1106
Native API
MalwareREvil

REvil can use Native API for execution and to retrieve active services.

T1106
Native API
MalwareSamurai

Samurai has the ability to call Windows APIs.

T1106
Native API
MalwareMilan

Milan can use the API `DnsQuery_A` for DNS resolution.

T1106
Native API
MalwareOilBooster

OilBooster has used the `ShowWindow` and `CreateProcessW` APIs.

T1106
Native API
MalwareTaidoor

Taidoor has the ability to use native APIs for execution including GetProcessHeap, GetProcAddress, and LoadLibrary.

T1106
Native API
MalwareCaddyWiper

CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`.

T1106
Native API
MalwareCyclops Blink

Cyclops Blink can use various Linux API functions including those for execution and discovery.

T1106
Native API
MalwarePLEAD

PLEAD can use `ShellExecute` to execute applications.

T1106
Native API
MalwareTRAILBLAZE

TRAILBLAZE has leveraged raw syscalls to execute commands.

T1106
Native API
MalwareGoldenSpy

GoldenSpy can execute remote commands in the Windows command shell using the WinExec() API.

T1106
Native API
MalwareRamsay

Ramsay can use Windows API functions such as WriteFile, CloseHandle, and GetCurrentHwProfile during its collection and file storage operations. Ramsay can execute its embedded components via CreateProcessA and ShellExecute.

T1106
Native API
MalwareCarberp

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.

T1106
Native API
MalwarePillowmint

Pillowmint has used multiple native Windows APIs to execute and conduct process injections.

T1106
Native API
MalwareMacMa

MacMa has used macOS API functions to perform tasks.

T1106
Native API
MalwareFunnyDream

FunnyDream can use Native API for defense evasion, discovery, and collection.

T1106
Native API
MalwareSUNSPOT

SUNSPOT used Windows API functions such as MoveFileEx and NtQueryInformationProcess as part of the SUNBURST injection process.

T1106
Native API
MalwareSysUpdate

SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process.

T1106
Native API
MalwareBackConfig

BackConfig can leverage API functions such as ShellExecuteA and HttpOpenRequestA in the process of downloading and executing files.

T1106
Native API
MalwareANELLDR

ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion.

T1106
Native API
MalwareDEADEYE

DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions.

T1106
Native API
MalwareMango

Mango has the ability to use Native APIs.

T1106
Native API
MalwareInnaputRAT

InnaputRAT uses the API call ShellExecuteW for execution.

T1106
Native API
MalwareGrimAgent

GrimAgent can use Native API including GetProcAddress and ShellExecuteW.

T1106
Native API
MalwareClop

Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc().

T1106
Native API
MalwareLokibot

Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode.

T1106
Native API
MalwareEgregor

Egregor has used the Windows API to make detection more difficult.

T1106
Native API
MalwareStealBit

StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes.

T1106
Native API
MalwareZxShell

ZxShell can leverage native API including RegisterServiceCtrlHandler to register a service.RegisterServiceCtrlHandler

T1106
Native API
Malwarebuild_downer

build_downer has the ability to use the WinExec API to execute malware on a compromised host.

T1106
Native API
MalwareWinnti for Windows

Winnti for Windows can use Native API to create a new process and to start services.

T1106
Native API
MalwareMeteor

Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain.

T1106
Native API
MalwarenjRAT

njRAT has used the ShellExecute() function within a script.

T1106
Native API
MalwareMaze

Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others.

T1106
Native API
MalwareComRAT

ComRAT can load a PE file from memory or the file system and execute it with CreateProcessW.

T1106
Native API
MalwaremetaMain

metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`.

T1106
Native API
MalwareSideTwist

SideTwist can use GetUserNameW, GetComputerNameW, and GetComputerNameExW to gather information.

T1106
Native API
MalwareKOCTOPUS

KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.