Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep. |
| T1106 Native API |
MalwareSodaMaster | SodaMaster can use |
| T1106 Native API |
MalwareGrandoreiro | Grandoreiro can execute through the |
| T1106 Native API |
MalwareZxxZ | ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`. |
| T1106 Native API |
MalwareCaminho | Caminho can use `System.Net.WebClient.downloadString()` for file download. |
| T1106 Native API |
MalwareBazar | Bazar can use various APIs to allocate memory and facilitate code execution/injection. |
| T1106 Native API |
MalwareXLoader | XLoader uses the native Windows API for functionality, including defense evasion. |
| T1106 Native API |
MalwareRyuk | Ryuk has used multiple native APIs including |
| T1106 Native API |
MalwareHermeticWiper | HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1106 Native API |
MalwareKapeka | Kapeka utilizes WinAPI calls to gather victim system information. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1106 Native API |
MalwareEvilBunny | EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox. |
| T1106 Native API |
MalwareHotCroissant | HotCroissant can perform dynamic DLL importing and API lookups using |
| T1106 Native API |
MalwareREvil | REvil can use Native API for execution and to retrieve active services. |
| T1106 Native API |
MalwareSamurai | Samurai has the ability to call Windows APIs. |
| T1106 Native API |
MalwareMilan | Milan can use the API `DnsQuery_A` for DNS resolution. |
| T1106 Native API |
MalwareOilBooster | OilBooster has used the `ShowWindow` and `CreateProcessW` APIs. |
| T1106 Native API |
MalwareTaidoor | Taidoor has the ability to use native APIs for execution including |
| T1106 Native API |
MalwareCaddyWiper | CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`. |
| T1106 Native API |
MalwareCyclops Blink | Cyclops Blink can use various Linux API functions including those for execution and discovery. |
| T1106 Native API |
MalwarePLEAD | PLEAD can use `ShellExecute` to execute applications. |
| T1106 Native API |
MalwareTRAILBLAZE | TRAILBLAZE has leveraged raw syscalls to execute commands. |
| T1106 Native API |
MalwareGoldenSpy | GoldenSpy can execute remote commands in the Windows command shell using the |
| T1106 Native API |
MalwareRamsay | Ramsay can use Windows API functions such as |
| T1106 Native API |
MalwareCarberp | Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories. |
| T1106 Native API |
MalwarePillowmint | Pillowmint has used multiple native Windows APIs to execute and conduct process injections. |
| T1106 Native API |
MalwareMacMa | MacMa has used macOS API functions to perform tasks. |
| T1106 Native API |
MalwareFunnyDream | FunnyDream can use Native API for defense evasion, discovery, and collection. |
| T1106 Native API |
MalwareSUNSPOT | SUNSPOT used Windows API functions such as |
| T1106 Native API |
MalwareSysUpdate | SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process. |
| T1106 Native API |
MalwareBackConfig | BackConfig can leverage API functions such as |
| T1106 Native API |
MalwareANELLDR | ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion. |
| T1106 Native API |
MalwareDEADEYE | DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions. |
| T1106 Native API |
MalwareMango | Mango has the ability to use Native APIs. |
| T1106 Native API |
MalwareInnaputRAT | InnaputRAT uses the API call ShellExecuteW for execution. |
| T1106 Native API |
MalwareGrimAgent | GrimAgent can use Native API including |
| T1106 Native API |
MalwareClop | Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc(). |
| T1106 Native API |
MalwareLokibot | Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode. |
| T1106 Native API |
MalwareEgregor | Egregor has used the Windows API to make detection more difficult. |
| T1106 Native API |
MalwareStealBit | StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes. |
| T1106 Native API |
MalwareZxShell | ZxShell can leverage native API including |
| T1106 Native API |
Malwarebuild_downer | build_downer has the ability to use the |
| T1106 Native API |
MalwareWinnti for Windows | Winnti for Windows can use Native API to create a new process and to start services. |
| T1106 Native API |
MalwareMeteor | Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain. |
| T1106 Native API |
MalwarenjRAT | njRAT has used the ShellExecute() function within a script. |
| T1106 Native API |
MalwareMaze | Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others. |
| T1106 Native API |
MalwareComRAT | ComRAT can load a PE file from memory or the file system and execute it with |
| T1106 Native API |
MalwaremetaMain | metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`. |
| T1106 Native API |
MalwareSideTwist | SideTwist can use |
| T1106 Native API |
MalwareKOCTOPUS | KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.