ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1055
Process Injection
GroupTA2541

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1055
Process Injection
GroupAPT37

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

T1055
Process Injection
GroupTurla

Turla has also used PowerSploit's Invoke-ReflectivePEInjection.ps1 to reflectively load a PowerShell payload into a random process on the victim system.

T1055
Process Injection
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

T1055
Process Injection
GroupSilence

Silence has injected a DLL library containing a Trojan into the fwmain32.exe process.

T1055
Process Injection
GroupCobalt Group

Cobalt Group has injected code into trusted processes.

T1055
Process Injection
GroupWizard Spider

Wizard Spider has used process injection to execute payloads to escalate privileges.

T1055
Process Injection
GroupVelvet Ant

Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them.

T1055
Process Injection
GroupPLATINUM

PLATINUM has used various methods of process injection including hot patching.

T1055.001
Dynamic-link Library Injection
GroupKimsuky

Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1055.001
Dynamic-link Library Injection
GroupPutter Panda

An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe).

T1055.001
Dynamic-link Library Injection
GroupLeviathan

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1055.001
Dynamic-link Library Injection
GroupTurla

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

T1055.001
Dynamic-link Library Injection
GroupTA505

TA505 has been seen injecting a DLL into winword.exe.

T1055.001
Dynamic-link Library Injection
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs.

T1055.001
Dynamic-link Library Injection
GroupMalteiro

Malteiro has injected Mispadu’s DLL into a process.

T1055.001
Dynamic-link Library Injection
GroupLazarus Group

A Lazarus Group malware sample performs reflective DLL injection.

T1055.001
Dynamic-link Library Injection
GroupWizard Spider

Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions.

T1055.002
Portable Executable Injection
GroupGorgon Group

Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.

T1055.002
Portable Executable Injection
GroupRocke

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

T1055.004
Asynchronous Procedure Call
GroupFIN8

FIN8 has injected malicious code into a new svchost.exe process.

T1055.012
Process Hollowing
GroupBlackByte

BlackByte used process hollowing for defense evasion purposes.

T1055.012
Process Hollowing
GroupKimsuky

Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing.

T1055.012
Process Hollowing
GroupPatchwork

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.

T1055.012
Process Hollowing
GroupGorgon Group

Gorgon Group malware can use process hollowing to inject one of its trojans into another process.

T1055.012
Process Hollowing
GroupmenuPass

menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant.

T1055.012
Process Hollowing
GroupTA2541

TA2541 has used process hollowing to execute CyberGate malware.

T1055.012
Process Hollowing
GroupAPT-C-36

APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes.

T1055.012
Process Hollowing
GroupThreat Group-3390

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.

T1055.013
Process Doppelgänging
GroupLeafminer

Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems.

T1056
Input Capture
GroupStorm-1811

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

T1056
Input Capture
GroupAPT39

APT39 has utilized tools to capture mouse movements.

T1056
Input Capture
GroupAPT42

APT42 has used credential harvesting websites.

T1056.001
Keylogging
GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1056.001
Keylogging
GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1056.001
Keylogging
GroupVolt Typhoon

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.

T1056.001
Keylogging
GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

T1056.001
Keylogging
GroupmenuPass

menuPass has used key loggers to steal usernames and passwords.

T1056.001
Keylogging
GroupAPT32

APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes.

T1056.001
Keylogging
GroupSandworm Team

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1056.001
Keylogging
GroupGroup5

Malware used by Group5 is capable of capturing keystrokes.

T1056.001
Keylogging
GroupDarkhotel

Darkhotel has used a keylogger.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1056.001
Keylogging
GroupAPT42

APT42 has used custom malware to log keystrokes.

T1056.001
Keylogging
GroupAPT5

APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.