ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1574.001
DLL
MalwareWEBC2

Variants of WEBC2 achieve persistence by using DLL search order hijacking, usually by copying the DLL file to %SYSTEMROOT% (C:\WINDOWS\ntshrui.dll).

T1574.001
DLL
MalwareNebulae

Nebulae can use DLL side-loading to gain execution.

T1574.001
DLL
MalwareROAMINGHOUSE

ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1574.001
DLL
MalwareRainyDay

RainyDay can use side-loading to run malicious executables.

T1574.001
DLL
MalwareEcipekac

Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL.

T1574.001
DLL
MalwareBOOKWORM

BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`.

T1574.001
DLL
MalwarePrikormka

Prikormka uses DLL search order hijacking for persistence by saving itself as ntshrui.dll to the Windows directory so it will load before the legitimate ntshrui.dll saved in the System32 subdirectory.

T1574.001
DLL
MalwarePUBLOAD

PUBLOAD has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareCANONSTAGER

CANONSTAGER has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareLoFiSe

LoFiSe has been executed as a file named DsNcDiag.dll through side-loading.

T1574.001
DLL
MalwareWastedLocker

WastedLocker has performed DLL hijacking before execution.

T1574.001
DLL
MalwareInvisiMole

InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library.

T1574.001
DLL
MalwareCLAIMLOADER

CLAIMLOADER has used a legitimately signed executable to execute a malicious payload within a DLL file.

T1574.001
DLL
MalwareZeroT

ZeroT has used DLL side-loading to load malicious payloads.

T1574.001
DLL
MalwareRaspberry Robin

Raspberry Robin can use legitimate, signed EXE files paired with malicious DLL files to load and run malicious payloads while bypassing defenses.

T1574.001
DLL
MalwareHUI Loader

HUI Loader can be deployed to targeted systems via legitimate programs that are vulnerable to DLL search order hijacking.

T1574.001
DLL
MalwareBOOSTWRITE

BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll.

T1574.001
DLL
MalwareHyperBro

HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload.

T1574.001
DLL
MalwareSplatDropper

SplatDropper has leveraged legitimate binaries to conduct DLL side-loading.

T1574.001
DLL
MalwareJavali

Javali can use DLL side-loading to load malicious DLLs into legitimate executables.

T1574.001
DLL
MalwareBBSRAT

DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1574.001
DLL
MalwareNOOPLDR

NOOPLDR can be executed via sideloading.

T1574.001
DLL
MalwareLumma Stealer

Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution.

T1574.001
DLL
MalwareClambling

Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution.

T1574.001
DLL
MalwareDarkGate

DarkGate includes one infection vector that leverages a malicious "KeyScramblerE.DLL" library that will load during the execution of the legitimate KeyScrambler application.

T1574.001
DLL
MalwareFoggyWeb

FoggyWeb's loader has used DLL Search Order Hijacking to load malicious code instead of the legitimate `version.dll` during the `Microsoft.IdentityServer.ServiceHost.exe` execution process.

T1574.001
DLL
MalwareChaes

Chaes has used search order hijacking to load a malicious DLL.

T1574.001
DLL
MalwareLODEINFO

LODEINFO can use legitimate EXE files to sideload malicious DLLs.

T1574.001
DLL
MalwareMetamorfo

Metamorfo has side-loaded its malicious DLL file.

T1574.001
DLL
MalwareT9000

During the T9000 installation process, it drops a copy of the legitimate Microsoft binary igfxtray.exe. The executable contains a side-loading weakness which is used to load a portion of the malware.

T1574.001
DLL
Malwaregh0st RAT

A gh0st RAT variant has used DLL side-loading.

T1574.001
DLL
MalwareKerrdown

Kerrdown can use DLL side-loading to load malicious DLLs.

T1574.001
DLL
MalwareCrutch

Crutch can persist via DLL search order hijacking on Google Chrome, Mozilla Firefox, or Microsoft OneDrive.

T1574.001
DLL
MalwareHikit

Hikit has used DLL to load oci.dll as a persistence mechanism.

T1574.001
DLL
MalwareStrelaStealer

StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable.

T1574.001
DLL
MalwareSakula

Sakula uses DLL side-loading, typically using a digitally signed sample of Kaspersky Anti-Virus (AV) 6.0 for Windows Workstations or McAfee's Outlook Scan About Box to load malicious DLL files.

T1574.001
DLL
MalwareCorKLOG

CorKLOG has leveraged legitimate binaries to conduct DLL side-loading.

T1574.001
DLL
MalwarePandora

Pandora can use DLL side-loading to execute malicious payloads.

T1574.001
DLL
MalwareFinFisher

FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking.

T1574.001
DLL
MalwareWingbird

Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service.

T1574.001
DLL
MalwareRamsay

Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload.

T1574.001
DLL
MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

T1574.001
DLL
MalwareSysUpdate

SysUpdate can load DLLs through vulnerable legitimate executables.

T1574.001
DLL
MalwarePowGoop

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

T1574.001
DLL
MalwareANELLDR

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

T1574.001
DLL
MalwareLookBack

LookBack side loads its communications module as a DLL into the libcurl.dll loader.

T1574.001
DLL
MalwareEgregor

Egregor has used DLL side-loading to execute its payload.

T1574.001
DLL
MalwareMelcoz

Melcoz can use DLL hijacking to bypass security controls.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.