ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1106×

203 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareSagerunex

Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic.

T1106
Native API
MalwareLP-Notes

LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials.

T1106
Native API
MalwareRoyal

Royal can use multiple APIs for discovery, communication, and execution.

T1106
Native API
MalwareBendyBear

BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing.

T1106
Native API
MalwareUroburos

Uroburos can use native Windows APIs including `GetHostByName`.

T1106
Native API
MalwareMetamorfo

Metamorfo has used native WINAPI calls.

T1106
Native API
MalwareEmbargo

Embargo has leveraged Windows Native API functions to execute its operations.

T1106
Native API
MalwareBandook

Bandook has used the ShellExecuteW() function call.

T1106
Native API
MalwarePipeMon

PipeMon's first stage has been executed by a call to CreateProcess with the decryption password in an argument. PipeMon has used a call to LoadLibrary to load its installer.

T1106
Native API
MalwareKONNI

KONNI has hardcoded API calls within its functions to use on the victim's machine.

T1106
Native API
Malwaregh0st RAT

gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions.

T1106
Native API
MalwareBlack Basta

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1106
Native API
MalwareAttor

Attor's dispatcher has used CreateProcessW API for execution.

T1106
Native API
MalwareLitePower

LitePower can use various API calls.

T1106
Native API
MalwareMegaCortex

After escalating privileges, MegaCortex calls TerminateProcess(), CreateRemoteThread, and other Win32 APIs.

T1106
Native API
MalwareBoxCaon

BoxCaon has used Windows API calls to obtain information about the compromised host.

T1106
Native API
MalwareNightClub

NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`.

T1106
Native API
MalwareMosquito

Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions.

T1106
Native API
MalwareRTM

RTM can use the FindNextUrlCacheEntryA and FindFirstUrlCacheEntryA functions to search for specific strings within browser history.

T1106
Native API
MalwareQUIETCANARY

QUIETCANARY can call `System.Net.HttpWebRequest` to identify the default proxy configured on the victim computer.

T1106
Native API
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep.

T1106
Native API
MalwareSodaMaster

SodaMaster can use RegOpenKeyW to access the Registry.

T1106
Native API
MalwareGrandoreiro

Grandoreiro can execute through the WinExec API.

T1106
Native API
MalwareZxxZ

ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`.

T1106
Native API
MalwareCaminho

Caminho can use `System.Net.WebClient.downloadString()` for file download.

T1106
Native API
MalwareBazar

Bazar can use various APIs to allocate memory and facilitate code execution/injection.

T1106
Native API
MalwareXLoader

XLoader uses the native Windows API for functionality, including defense evasion.

T1106
Native API
MalwareRyuk

Ryuk has used multiple native APIs including ShellExecuteW to run executables,GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1106
Native API
MalwareKapeka

Kapeka utilizes WinAPI calls to gather victim system information.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1106
Native API
MalwareEvilBunny

EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox.

T1106
Native API
MalwareHotCroissant

HotCroissant can perform dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings.

T1106
Native API
MalwareREvil

REvil can use Native API for execution and to retrieve active services.

T1106
Native API
MalwareSamurai

Samurai has the ability to call Windows APIs.

T1106
Native API
MalwareMilan

Milan can use the API `DnsQuery_A` for DNS resolution.

T1106
Native API
MalwareOilBooster

OilBooster has used the `ShowWindow` and `CreateProcessW` APIs.

T1106
Native API
MalwareTaidoor

Taidoor has the ability to use native APIs for execution including GetProcessHeap, GetProcAddress, and LoadLibrary.

T1106
Native API
MalwareCaddyWiper

CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`.

T1106
Native API
MalwareCyclops Blink

Cyclops Blink can use various Linux API functions including those for execution and discovery.

T1106
Native API
MalwarePLEAD

PLEAD can use `ShellExecute` to execute applications.

T1106
Native API
MalwareTRAILBLAZE

TRAILBLAZE has leveraged raw syscalls to execute commands.

T1106
Native API
MalwareGoldenSpy

GoldenSpy can execute remote commands in the Windows command shell using the WinExec() API.

T1106
Native API
MalwareRamsay

Ramsay can use Windows API functions such as WriteFile, CloseHandle, and GetCurrentHwProfile during its collection and file storage operations. Ramsay can execute its embedded components via CreateProcessA and ShellExecute.

T1106
Native API
MalwareCarberp

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.

T1106
Native API
MalwarePillowmint

Pillowmint has used multiple native Windows APIs to execute and conduct process injections.

T1106
Native API
MalwareMacMa

MacMa has used macOS API functions to perform tasks.

T1106
Native API
MalwareFunnyDream

FunnyDream can use Native API for defense evasion, discovery, and collection.

T1106
Native API
MalwareSUNSPOT

SUNSPOT used Windows API functions such as MoveFileEx and NtQueryInformationProcess as part of the SUNBURST injection process.

T1106
Native API
MalwareSysUpdate

SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.