Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1620 Reflective Code Loading |
MalwareBADHATCH | BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`. |
| T1620 Reflective Code Loading |
MalwareSystemBC | SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call. |
| T1620 Reflective Code Loading |
MalwareWhisperGate | WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly. |
| T1620 Reflective Code Loading |
MalwareLunarLoader | LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
| T1620 Reflective Code Loading |
MalwareLumma Stealer | Lumma Stealer has used reflective loading techniques to load content into memory during execution. |
| T1620 Reflective Code Loading |
MalwareCuba | Cuba loaded the payload into memory using PowerShell. |
| T1620 Reflective Code Loading |
MalwareThiefQuest | ThiefQuest uses various API functions such as |
| T1620 Reflective Code Loading |
MalwareFoggyWeb | FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory. |
| T1620 Reflective Code Loading |
MalwareMuddyViper | MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread. |
| T1620 Reflective Code Loading |
MalwareFooder | Fooder has reflectively loaded a payload into memory. |
| T1620 Reflective Code Loading |
MalwareUroburos | Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command. |
| T1620 Reflective Code Loading |
MalwareCobalt Strike | Cobalt Strike's |
| T1620 Reflective Code Loading |
MalwareLokibot | Lokibot has reflectively loaded the decoded DLL into memory. |
| T1620 Reflective Code Loading |
MalwareIceApple | IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers. |
| T1620 Reflective Code Loading |
MalwaremetaMain | metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file. |
| T1620 Reflective Code Loading |
MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| T1620 Reflective Code Loading |
MalwareGelsemium | Gelsemium can use custom shellcode to map embedded DLLs into memory. |
| T1620 Reflective Code Loading |
MalwareLizar | Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory. |
| T1620 Reflective Code Loading |
ToolSILENTTRINITY | SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR. |
| T1620 Reflective Code Loading |
ToolPowerSploit | PowerSploit reflectively loads a Windows PE file into a process. |
| T1620 Reflective Code Loading |
ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| T1620 Reflective Code Loading |
ToolDonut | Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
| T1622 Debugger Evasion |
MalwarePikabot | Pikabot features several methods to evade debugging by analysts, including checks for active debuggers, the use of breakpoints during execution, and checking various system information items such as system memory and the number of processors. |
| T1622 Debugger Evasion |
MalwareBumblebee | Bumblebee can search for tools used in static analysis. |
| T1622 Debugger Evasion |
MalwareTONESHELL | TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger. |
| T1622 Debugger Evasion |
MalwarePUBLOAD | PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions. |
| T1622 Debugger Evasion |
MalwareMafalda | Mafalda can search for debugging tools on a compromised host. |
| T1622 Debugger Evasion |
MalwareRaspberry Robin | Raspberry Robin leverages anti-debugging mechanisms through the use of |
| T1622 Debugger Evasion |
MalwareRustyWater | RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts. |
| T1622 Debugger Evasion |
MalwareDRATzarus | DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim. |
| T1622 Debugger Evasion |
MalwareDarkTortilla | DarkTortilla can detect debuggers by using functions such as `DebuggerIsAttached` and `DebuggerIsLogging`. DarkTortilla can also detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
| T1622 Debugger Evasion |
MalwareROKRAT | ROKRAT can check for debugging tools. |
| T1622 Debugger Evasion |
MalwarePlugX | PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1622 Debugger Evasion |
MalwareLumma Stealer | Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”. |
| T1622 Debugger Evasion |
MalwarePureCrypter | PureCrypter has the ability to call `CheckRemoteDebuggerPresent`. |
| T1622 Debugger Evasion |
MalwareDarkGate | DarkGate checks the |
| T1622 Debugger Evasion |
MalwareLockBit 3.0 | LockBit 3.0 can check heap memory parameters for indications of a debugger and stop the flow of events to the attached debugger in order to hinder dynamic analysis. |
| T1622 Debugger Evasion |
MalwareThiefQuest | ThiefQuest uses a function named |
| T1622 Debugger Evasion |
MalwareLatrodectus | Latrodectus has the ability to check for the presence of debuggers. |
| T1622 Debugger Evasion |
MalwareSaint Bot | Saint Bot has used `is_debugger_present` as part of its environmental checks. |
| T1622 Debugger Evasion |
MalwareBlack Basta | The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present. |
| T1622 Debugger Evasion |
MalwareStrelaStealer | StrelaStealer variants include functionality to identify and evade debuggers. |
| T1622 Debugger Evasion |
MalwareXLoader | XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed. |
| T1622 Debugger Evasion |
MalwareANELLDR | ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged. |
| T1622 Debugger Evasion |
MalwareStealBit | StealBit can detect it is being run in the context of a debugger. |
| T1622 Debugger Evasion |
ToolAsyncRAT | AsyncRAT can use the `CheckRemoteDebuggerPresent` function to detect the presence of a debugger. |
| T1647 Plist File Modification |
MalwareCuckoo Stealer | Cuckoo Stealer can create and populate property list (plist) files to enable execution. |
| T1647 Plist File Modification |
MalwareXCSSET | In older versions, XCSSET uses the |
| T1648 Serverless Execution |
ToolPacu | Pacu can create malicious Lambda functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.