Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.001 DLL |
MalwareHIUPAN | HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe. |
| T1574.001 DLL |
MalwaremetaMain | metaMain can support an HKCMD sideloading start method. |
| T1574.001 DLL |
MalwareHTTPBrowser | HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
| T1574.001 DLL |
MalwareMirageFox | MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary. |
| T1574.001 DLL |
MalwarePcexter | Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading. |
| T1574.001 DLL |
MalwareStarProxy | StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe. |
| T1574.001 DLL |
MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
| T1574.001 DLL |
MalwareGoopy | Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google. |
| T1574.001 DLL |
MalwareAstaroth | Astaroth can launch itself via DLL Search Order Hijacking. |
| T1574.001 DLL |
MalwareQakBot | QakBot has the ability to use DLL side-loading for execution. |
| T1574.001 DLL |
MalwareDridex | Dridex can abuse legitimate Windows executables to side-load malicious DLL files. |
| T1574.001 DLL |
MalwareDenis | Denis exploits a security vulnerability to load a fake DLL and execute its code. |
| T1574.001 DLL |
MalwareWaterbear | Waterbear has used DLL side loading to import and load a malicious DLL loader. |
| T1574.001 DLL |
MalwareUPPERCUT | UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation. |
| T1574.001 DLL |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes. |
| T1574.001 DLL |
ToolEmpire | Empire contains modules that can discover and exploit various DLL hijacking opportunities. |
| T1574.001 DLL |
ToolBrute Ratel C4 | Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe. |
| T1574.004 Dylib Hijacking |
ToolEmpire | Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application. |
| T1574.006 Dynamic Linker Hijacking |
MalwareMEDUSA | MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library. |
| T1574.006 Dynamic Linker Hijacking |
MalwareCOATHANGER | COATHANGER copies the malicious file |
| T1574.006 Dynamic Linker Hijacking |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to intercept shared library import functions. |
| T1574.006 Dynamic Linker Hijacking |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection. |
| T1574.006 Dynamic Linker Hijacking |
MalwareEbury | When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`. |
| T1574.006 Dynamic Linker Hijacking |
MalwareXCSSET | XCSSET adds malicious file paths to the |
| T1574.006 Dynamic Linker Hijacking |
MalwareHiddenWasp | HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable. |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareBRICKSTORM | BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path. |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareDarkGate | DarkGate overrides the |
| T1574.007 Path Interception by PATH Environment Variable |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.007 Path Interception by PATH Environment Variable |
ToolEmpire | Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolEmpire | Empire contains modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolEmpire | Empire contains modules that can discover and exploit unquoted path vulnerabilities. |
| T1574.010 Services File Permissions Weakness |
MalwareBlackEnergy | One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence. |
| T1574.012 COR_PROFILER |
MalwareDarkTortilla | DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
| T1574.013 KernelCallbackTable |
MalwareFinFisher | FinFisher has used the |
| T1574.014 AppDomainManager |
MalwareIMAPLoader | IMAPLoader is executed via the AppDomainManager injection technique. |
| T1578.001 Create Snapshot |
ToolPacu | Pacu can create snapshots of EBS volumes and RDS instances. |
| T1580 Cloud Infrastructure Discovery |
ToolPacu | Pacu can enumerate AWS infrastructure, such as EC2 instances. |
| T1580 Cloud Infrastructure Discovery |
ToolTruffleHog | TruffleHog can enumerate AWS Infrastructure to include EC2 instances. |
| T1580 Cloud Infrastructure Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to search for generic GitHub runners. |
| T1583.001 Domains |
MalwareRaspberry Robin | Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as " |
| T1583.001 Domains |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1583.001 Domains |
MalwareXLoader | XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap. |
| T1583.008 Malvertising |
MalwareRaspberry Robin | Raspberry Robin variants have been delivered via malicious advertising items that, when interacted with, download a malicious archive file containing the initial payload, hosted on services such as Discord. |
| T1584.001 Domains |
MalwareGootloader | Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads. |
| T1584.006 Web Services |
MalwareGootloader | Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS). |
| T1588.002 Tool |
MalwareLizar | FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec. |
| T1588.003 Code Signing Certificates |
MalwareMegaCortex | MegaCortex has used code signing certificates issued to fake companies to bypass security controls. |
| T1588.007 Artificial Intelligence |
MalwareLazyWiper | LazyWiper is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.