Real-world descriptions of how a group, tool or campaign used a technique.
203 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareSagerunex | Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic. |
| T1106 Native API |
MalwareLP-Notes | LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials. |
| T1106 Native API |
MalwareRoyal | Royal can use multiple APIs for discovery, communication, and execution. |
| T1106 Native API |
MalwareBendyBear | BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing. |
| T1106 Native API |
MalwareUroburos | Uroburos can use native Windows APIs including `GetHostByName`. |
| T1106 Native API |
MalwareMetamorfo | Metamorfo has used native WINAPI calls. |
| T1106 Native API |
MalwareEmbargo | Embargo has leveraged Windows Native API functions to execute its operations. |
| T1106 Native API |
MalwareBandook | Bandook has used the ShellExecuteW() function call. |
| T1106 Native API |
MalwarePipeMon | PipeMon's first stage has been executed by a call to |
| T1106 Native API |
MalwareKONNI | KONNI has hardcoded API calls within its functions to use on the victim's machine. |
| T1106 Native API |
Malwaregh0st RAT | gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions. |
| T1106 Native API |
MalwareBlack Basta | Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion. |
| T1106 Native API |
MalwareAttor | Attor's dispatcher has used CreateProcessW API for execution. |
| T1106 Native API |
MalwareLitePower | LitePower can use various API calls. |
| T1106 Native API |
MalwareMegaCortex | After escalating privileges, MegaCortex calls |
| T1106 Native API |
MalwareBoxCaon | BoxCaon has used Windows API calls to obtain information about the compromised host. |
| T1106 Native API |
MalwareNightClub | NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`. |
| T1106 Native API |
MalwareMosquito | Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions. |
| T1106 Native API |
MalwareRTM | RTM can use the |
| T1106 Native API |
MalwareQUIETCANARY | QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer. |
| T1106 Native API |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep. |
| T1106 Native API |
MalwareSodaMaster | SodaMaster can use |
| T1106 Native API |
MalwareGrandoreiro | Grandoreiro can execute through the |
| T1106 Native API |
MalwareZxxZ | ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`. |
| T1106 Native API |
MalwareCaminho | Caminho can use `System.Net.WebClient.downloadString()` for file download. |
| T1106 Native API |
MalwareBazar | Bazar can use various APIs to allocate memory and facilitate code execution/injection. |
| T1106 Native API |
MalwareXLoader | XLoader uses the native Windows API for functionality, including defense evasion. |
| T1106 Native API |
MalwareRyuk | Ryuk has used multiple native APIs including |
| T1106 Native API |
MalwareHermeticWiper | HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1106 Native API |
MalwareKapeka | Kapeka utilizes WinAPI calls to gather victim system information. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1106 Native API |
MalwareEvilBunny | EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox. |
| T1106 Native API |
MalwareHotCroissant | HotCroissant can perform dynamic DLL importing and API lookups using |
| T1106 Native API |
MalwareREvil | REvil can use Native API for execution and to retrieve active services. |
| T1106 Native API |
MalwareSamurai | Samurai has the ability to call Windows APIs. |
| T1106 Native API |
MalwareMilan | Milan can use the API `DnsQuery_A` for DNS resolution. |
| T1106 Native API |
MalwareOilBooster | OilBooster has used the `ShowWindow` and `CreateProcessW` APIs. |
| T1106 Native API |
MalwareTaidoor | Taidoor has the ability to use native APIs for execution including |
| T1106 Native API |
MalwareCaddyWiper | CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`. |
| T1106 Native API |
MalwareCyclops Blink | Cyclops Blink can use various Linux API functions including those for execution and discovery. |
| T1106 Native API |
MalwarePLEAD | PLEAD can use `ShellExecute` to execute applications. |
| T1106 Native API |
MalwareTRAILBLAZE | TRAILBLAZE has leveraged raw syscalls to execute commands. |
| T1106 Native API |
MalwareGoldenSpy | GoldenSpy can execute remote commands in the Windows command shell using the |
| T1106 Native API |
MalwareRamsay | Ramsay can use Windows API functions such as |
| T1106 Native API |
MalwareCarberp | Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories. |
| T1106 Native API |
MalwarePillowmint | Pillowmint has used multiple native Windows APIs to execute and conduct process injections. |
| T1106 Native API |
MalwareMacMa | MacMa has used macOS API functions to perform tasks. |
| T1106 Native API |
MalwareFunnyDream | FunnyDream can use Native API for defense evasion, discovery, and collection. |
| T1106 Native API |
MalwareSUNSPOT | SUNSPOT used Windows API functions such as |
| T1106 Native API |
MalwareSysUpdate | SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.