Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
GroupTA2541 | TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe. |
| T1055 Process Injection |
GroupAPT37 | APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| T1055 Process Injection |
GroupTurla | Turla has also used PowerSploit's |
| T1055 Process Injection |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality. |
| T1055 Process Injection |
GroupSilence | Silence has injected a DLL library containing a Trojan into the fwmain32.exe process. |
| T1055 Process Injection |
GroupCobalt Group | Cobalt Group has injected code into trusted processes. |
| T1055 Process Injection |
GroupWizard Spider | Wizard Spider has used process injection to execute payloads to escalate privileges. |
| T1055 Process Injection |
GroupVelvet Ant | Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them. |
| T1055 Process Injection |
GroupPLATINUM | PLATINUM has used various methods of process injection including hot patching. |
| T1055.001 Dynamic-link Library Injection |
GroupKimsuky | Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`. |
| T1055.001 Dynamic-link Library Injection |
GroupTropic Trooper | Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupPutter Panda | An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe). |
| T1055.001 Dynamic-link Library Injection |
GroupLeviathan | Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim. |
| T1055.001 Dynamic-link Library Injection |
GroupTurla | Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
| T1055.001 Dynamic-link Library Injection |
GroupTA505 | TA505 has been seen injecting a DLL into winword.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs. |
| T1055.001 Dynamic-link Library Injection |
GroupMalteiro | |
| T1055.001 Dynamic-link Library Injection |
GroupLazarus Group | A Lazarus Group malware sample performs reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
| T1055.002 Portable Executable Injection |
GroupGorgon Group | Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process. |
| T1055.002 Portable Executable Injection |
GroupRocke | Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe. |
| T1055.004 Asynchronous Procedure Call |
GroupFIN8 | FIN8 has injected malicious code into a new svchost.exe process. |
| T1055.012 Process Hollowing |
GroupBlackByte | BlackByte used process hollowing for defense evasion purposes. |
| T1055.012 Process Hollowing |
GroupKimsuky | Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing. |
| T1055.012 Process Hollowing |
GroupPatchwork | A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe. |
| T1055.012 Process Hollowing |
GroupGorgon Group | Gorgon Group malware can use process hollowing to inject one of its trojans into another process. |
| T1055.012 Process Hollowing |
GroupmenuPass | menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant. |
| T1055.012 Process Hollowing |
GroupTA2541 | TA2541 has used process hollowing to execute CyberGate malware. |
| T1055.012 Process Hollowing |
GroupAPT-C-36 | APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. |
| T1055.012 Process Hollowing |
GroupThreat Group-3390 | A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process. |
| T1055.013 Process Doppelgänging |
GroupLeafminer | Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems. |
| T1056 Input Capture |
GroupStorm-1811 | Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item. |
| T1056 Input Capture |
GroupAPT39 | APT39 has utilized tools to capture mouse movements. |
| T1056 Input Capture |
GroupAPT42 | APT42 has used credential harvesting websites. |
| T1056.001 Keylogging |
GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1056.001 Keylogging |
GroupVolt Typhoon | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution. |
| T1056.001 Keylogging |
GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| T1056.001 Keylogging |
GroupmenuPass | menuPass has used key loggers to steal usernames and passwords. |
| T1056.001 Keylogging |
GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| T1056.001 Keylogging |
GroupSandworm Team | Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1056.001 Keylogging |
GroupGroup5 | Malware used by Group5 is capable of capturing keystrokes. |
| T1056.001 Keylogging |
GroupDarkhotel | Darkhotel has used a keylogger. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1056.001 Keylogging |
GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| T1056.001 Keylogging |
GroupAPT5 | APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.