ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1106×

203 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareInvisiMole

InvisiMole can use winapiexec tool for indirect execution of ShellExecuteW and CreateProcessA.

T1106
Native API
MalwareCLAIMLOADER

CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`.

T1106
Native API
MalwareVolgmer

Volgmer executes payloads using the Windows API call CreateProcessW().

T1106
Native API
MalwareWhisperGate

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.

T1106
Native API
MalwareConti

Conti has used API calls during execution.

T1106
Native API
MalwareMispadu

Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory.

T1106
Native API
MalwareDiavol

Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack.

T1106
Native API
MalwareSiloscape

Siloscape makes various native API calls.

T1106
Native API
MalwareRustyWater

RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object.  Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe.

T1106
Native API
MalwareIcedID

IcedID has called ZwWriteVirtualMemory, ZwProtectVirtualMemory, ZwQueueApcThread, and NtResumeThread to inject itself into a remote process.

T1106
Native API
MalwareHTTPTroy

HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory.

T1106
Native API
MalwareMarkiRAT

MarkiRAT can run the ShellExecuteW API via the Windows Command Shell.

T1106
Native API
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`.

T1106
Native API
MalwareFatDuke

FatDuke can call ShellExecuteW to open the default browser on the URL localhost.

T1106
Native API
MalwareDCSrv

DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process.

T1106
Native API
MalwareDRATzarus

DRATzarus can use various API calls to see if it is running in a sandbox.

T1106
Native API
MalwareRising Sun

Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`.

T1106
Native API
MalwareShimRat

ShimRat has used Windows API functions to install the service and shim.

T1106
Native API
MalwareChrommme

Chrommme can use Windows API including `WinExec` for execution.

T1106
Native API
MalwareAvaddon

Avaddon has used the Windows Crypto API to generate an AES key.

T1106
Native API
MalwareFlagpro

Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`.

T1106
Native API
MalwareXAgentOSX

XAgentOSX contains the execFile function to execute a specified file on the system using the NSTask:launch method.

T1106
Native API
MalwareCostaBricks

CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`.

T1106
Native API
MalwareHyperBro

HyperBro has the ability to run an application (CreateProcessW) or script/file (ShellExecuteW) via API.

T1106
Native API
MalwarePteranodon

Pteranodon has used various API calls.

T1106
Native API
MalwareDarkTortilla

DarkTortilla can use a variety of API calls for persistence and defense evasion.

T1106
Native API
MalwareROKRAT

ROKRAT can use a variety of API calls to execute shellcode.

T1106
Native API
MalwareSplatDropper

SplatDropper has utilized hashed Native Windows API calls.

T1106
Native API
MalwareBabuk

Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution.

T1106
Native API
MalwareExbyte

Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges.

T1106
Native API
MalwarePlugX

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.

T1106
Native API
MalwareBisonal

Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread.

T1106
Native API
MalwareNOOPLDR

NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection.

T1106
Native API
MalwareS-Type

S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`.

T1106
Native API
MalwareExplosive

Explosive has a function to call the OpenClipboard wrapper.

T1106
Native API
MalwareLightNeuron

LightNeuron is capable of starting a process using CreateProcess.

T1106
Native API
MalwareCuba

Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.

T1106
Native API
MalwareAkira

Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.

T1106
Native API
MalwareDarkGate

DarkGate uses the native Windows API CallWindowProc() to decode and launch encoded shellcode payloads during execution. DarkGate can call kernel mode functions directly to hide the use of process hollowing methods during execution. DarkGate has also used the `CreateToolhelp32Snapshot`, `GetFileAttributesA` and `CreateProcessA` functions to obtain a list of running processes, to check for security products and to execute its malware.

T1106
Native API
MalwareLockBit 3.0

LockBit 3.0 has the ability to directly call native Windows API items during execution.

T1106
Native API
MalwareSVCReady

SVCReady can use Windows API calls to gather information from an infected host.

T1106
Native API
MalwareThiefQuest

ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration.

T1106
Native API
MalwareFoggyWeb

FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed.

T1106
Native API
MalwareNetwalker

Netwalker can use Windows API functions to inject the ransomware DLL.

T1106
Native API
MalwareLatrodectus

Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`.

T1106
Native API
MalwareSaint Bot

Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`.

T1106
Native API
MalwareChaes

Chaes used the CreateFileW() API function with read permissions to access downloaded payloads.

T1106
Native API
MalwareLODEINFO

LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode.

T1106
Native API
MalwareMuddyViper

MuddyViper has the ability to relaunch itself using the `CreateProcessW` API.

T1106
Native API
MalwareFooder

Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.