ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1574.001
DLL
MalwareHIUPAN

HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe.

T1574.001
DLL
MalwaremetaMain

metaMain can support an HKCMD sideloading start method.

T1574.001
DLL
MalwareHTTPBrowser

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading.

T1574.001
DLL
MalwareMirageFox

MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary.

T1574.001
DLL
MalwarePcexter

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.

T1574.001
DLL
MalwareStarProxy

StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe.

T1574.001
DLL
MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

T1574.001
DLL
MalwareGoopy

Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google.

T1574.001
DLL
MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

T1574.001
DLL
MalwareQakBot

QakBot has the ability to use DLL side-loading for execution.

T1574.001
DLL
MalwareDridex

Dridex can abuse legitimate Windows executables to side-load malicious DLL files.

T1574.001
DLL
MalwareDenis

Denis exploits a security vulnerability to load a fake DLL and execute its code.

T1574.001
DLL
MalwareWaterbear

Waterbear has used DLL side loading to import and load a malicious DLL loader.

T1574.001
DLL
MalwareUPPERCUT

UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation.

T1574.001
DLL
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.

T1574.001
DLL
ToolEmpire

Empire contains modules that can discover and exploit various DLL hijacking opportunities.

T1574.001
DLL
ToolBrute Ratel C4

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.

T1574.004
Dylib Hijacking
ToolEmpire

Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application.

T1574.006
Dynamic Linker Hijacking
MalwareMEDUSA

MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library.

T1574.006
Dynamic Linker Hijacking
MalwareCOATHANGER

COATHANGER copies the malicious file /data2/.bd.key/preload.so to /lib/preload.so, then launches a child process that executes the malicious file /data2/.bd.key/authd as /bin/authd with the arguments /lib/preload.so reboot newreboot 1. This injects the malicious preload.so file into the process with PID 1, and replaces its reboot function with the malicious newreboot function for persistence.

T1574.006
Dynamic Linker Hijacking
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to intercept shared library import functions.

T1574.006
Dynamic Linker Hijacking
MalwareSPAWNCHIMERA

SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection.

T1574.006
Dynamic Linker Hijacking
MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

T1574.006
Dynamic Linker Hijacking
MalwareXCSSET

XCSSET adds malicious file paths to the DYLD_FRAMEWORK_PATH and DYLD_LIBRARY_PATH environment variables to execute malicious code.

T1574.006
Dynamic Linker Hijacking
MalwareHiddenWasp

HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable.

T1574.007
Path Interception by PATH Environment Variable
MalwareBRICKSTORM

BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path.

T1574.007
Path Interception by PATH Environment Variable
MalwareDarkGate

DarkGate overrides the %windir% environment variable by setting a Registry key, HKEY_CURRENT_User\Environment\windir, to an alternate command to execute a malicious AutoIt script. This allows DarkGate to run every time the scheduled task DiskCleanup is executed as this uses the path value %windir%\system32\cleanmgr.exe for execution.

T1574.007
Path Interception by PATH Environment Variable
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.007
Path Interception by PATH Environment Variable
ToolEmpire

Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.008
Path Interception by Search Order Hijacking
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities.

T1574.008
Path Interception by Search Order Hijacking
ToolEmpire

Empire contains modules that can discover and exploit search order hijacking vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolEmpire

Empire contains modules that can discover and exploit unquoted path vulnerabilities.

T1574.010
Services File Permissions Weakness
MalwareBlackEnergy

One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence.

T1574.012
COR_PROFILER
MalwareDarkTortilla

DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active.

T1574.013
KernelCallbackTable
MalwareFinFisher

FinFisher has used the KernelCallbackTable to hijack the execution flow of a process by replacing the __fnDWORD function with the address of a created Asynchronous Procedure Call stub routine.

T1574.014
AppDomainManager
MalwareIMAPLoader

IMAPLoader is executed via the AppDomainManager injection technique.

T1578.001
Create Snapshot
ToolPacu

Pacu can create snapshots of EBS volumes and RDS instances.

T1580
Cloud Infrastructure Discovery
ToolPacu

Pacu can enumerate AWS infrastructure, such as EC2 instances.

T1580
Cloud Infrastructure Discovery
ToolTruffleHog

TruffleHog can enumerate AWS Infrastructure to include EC2 instances.

T1580
Cloud Infrastructure Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to search for generic GitHub runners.

T1583.001
Domains
MalwareRaspberry Robin

Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as "v0[.]cx".

T1583.001
Domains
MalwareDarkGate

DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services.

T1583.001
Domains
MalwareXLoader

XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap.

T1583.008
Malvertising
MalwareRaspberry Robin

Raspberry Robin variants have been delivered via malicious advertising items that, when interacted with, download a malicious archive file containing the initial payload, hosted on services such as Discord.

T1584.001
Domains
MalwareGootloader

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

T1584.006
Web Services
MalwareGootloader

Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS).

T1588.002
Tool
MalwareLizar

FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec.

T1588.003
Code Signing Certificates
MalwareMegaCortex

MegaCortex has used code signing certificates issued to fake companies to bypass security controls.

T1588.007
Artificial Intelligence
MalwareLazyWiper

LazyWiper is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.