Real-world descriptions of how a group, tool or campaign used a technique.
203 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareInvisiMole | InvisiMole can use winapiexec tool for indirect execution of |
| T1106 Native API |
MalwareCLAIMLOADER | CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`. |
| T1106 Native API |
MalwareVolgmer | Volgmer executes payloads using the Windows API call CreateProcessW(). |
| T1106 Native API |
MalwareWhisperGate | WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls. |
| T1106 Native API |
MalwareConti | Conti has used API calls during execution. |
| T1106 Native API |
MalwareMispadu | Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory. |
| T1106 Native API |
MalwareDiavol | Diavol has used several API calls like `GetLogicalDriveStrings`, `SleepEx`, `SystemParametersInfoAPI`, `CryptEncrypt`, and others to execute parts of its attack. |
| T1106 Native API |
MalwareSiloscape | Siloscape makes various native API calls. |
| T1106 Native API |
MalwareRustyWater | RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object. Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe. |
| T1106 Native API |
MalwareIcedID | IcedID has called |
| T1106 Native API |
MalwareHTTPTroy | HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory. |
| T1106 Native API |
MalwareMarkiRAT | MarkiRAT can run the ShellExecuteW API via the Windows Command Shell. |
| T1106 Native API |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`. |
| T1106 Native API |
MalwareFatDuke | FatDuke can call |
| T1106 Native API |
MalwareDCSrv | DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process. |
| T1106 Native API |
MalwareDRATzarus | DRATzarus can use various API calls to see if it is running in a sandbox. |
| T1106 Native API |
MalwareRising Sun | Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`. |
| T1106 Native API |
MalwareShimRat | ShimRat has used Windows API functions to install the service and shim. |
| T1106 Native API |
MalwareChrommme | Chrommme can use Windows API including `WinExec` for execution. |
| T1106 Native API |
MalwareAvaddon | Avaddon has used the Windows Crypto API to generate an AES key. |
| T1106 Native API |
MalwareFlagpro | Flagpro can use Native API to enable obfuscation including `GetLastError` and `GetTickCount`. |
| T1106 Native API |
MalwareXAgentOSX | XAgentOSX contains the execFile function to execute a specified file on the system using the NSTask:launch method. |
| T1106 Native API |
MalwareCostaBricks | CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`. |
| T1106 Native API |
MalwareHyperBro | HyperBro has the ability to run an application ( |
| T1106 Native API |
MalwarePteranodon | Pteranodon has used various API calls. |
| T1106 Native API |
MalwareDarkTortilla | DarkTortilla can use a variety of API calls for persistence and defense evasion. |
| T1106 Native API |
MalwareROKRAT | ROKRAT can use a variety of API calls to execute shellcode. |
| T1106 Native API |
MalwareSplatDropper | SplatDropper has utilized hashed Native Windows API calls. |
| T1106 Native API |
MalwareBabuk | Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution. |
| T1106 Native API |
MalwareExbyte | Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges. |
| T1106 Native API |
MalwarePlugX | PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process. |
| T1106 Native API |
MalwareBisonal | Bisonal has used the Windows API to communicate with the Service Control Manager to execute a thread. |
| T1106 Native API |
MalwareNOOPLDR | NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection. |
| T1106 Native API |
MalwareS-Type | S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`. |
| T1106 Native API |
MalwareExplosive | Explosive has a function to call the OpenClipboard wrapper. |
| T1106 Native API |
MalwareLightNeuron | LightNeuron is capable of starting a process using CreateProcess. |
| T1106 Native API |
MalwareCuba | Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum. |
| T1106 Native API |
MalwareAkira | Akira executes native Windows functions such as |
| T1106 Native API |
MalwareDarkGate | DarkGate uses the native Windows API |
| T1106 Native API |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to directly call native Windows API items during execution. |
| T1106 Native API |
MalwareSVCReady | SVCReady can use Windows API calls to gather information from an infected host. |
| T1106 Native API |
MalwareThiefQuest | ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration. |
| T1106 Native API |
MalwareFoggyWeb | FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed. |
| T1106 Native API |
MalwareNetwalker | Netwalker can use Windows API functions to inject the ransomware DLL. |
| T1106 Native API |
MalwareLatrodectus | Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`. |
| T1106 Native API |
MalwareSaint Bot | Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`. |
| T1106 Native API |
MalwareChaes | Chaes used the |
| T1106 Native API |
MalwareLODEINFO | LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode. |
| T1106 Native API |
MalwareMuddyViper | MuddyViper has the ability to relaunch itself using the `CreateProcessW` API. |
| T1106 Native API |
MalwareFooder | Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.