ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1574.001
DLL
MalwarePandora

Pandora can use DLL side-loading to execute malicious payloads.

T1574.001
DLL
MalwareFinFisher

FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking.

T1574.001
DLL
MalwareWingbird

Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service.

T1574.001
DLL
MalwareRamsay

Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload.

T1574.001
DLL
MalwareAshTag

AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32.

T1574.001
DLL
MalwareSysUpdate

SysUpdate can load DLLs through vulnerable legitimate executables.

T1574.001
DLL
MalwarePowGoop

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

T1574.001
DLL
MalwareANELLDR

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

T1574.001
DLL
MalwareLookBack

LookBack side loads its communications module as a DLL into the libcurl.dll loader.

T1574.001
DLL
MalwareEgregor

Egregor has used DLL side-loading to execute its payload.

T1574.001
DLL
MalwareMelcoz

Melcoz can use DLL hijacking to bypass security controls.

T1574.001
DLL
MalwareHIUPAN

HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe.

T1574.001
DLL
MalwaremetaMain

metaMain can support an HKCMD sideloading start method.

T1574.001
DLL
MalwareHTTPBrowser

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading.

T1574.001
DLL
MalwareMirageFox

MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary.

T1574.001
DLL
MalwarePcexter

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.

T1574.001
DLL
MalwareStarProxy

StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe.

T1574.001
DLL
MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

T1574.001
DLL
MalwareGoopy

Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google.

T1574.001
DLL
MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

T1574.001
DLL
MalwareQakBot

QakBot has the ability to use DLL side-loading for execution.

T1574.001
DLL
MalwareDridex

Dridex can abuse legitimate Windows executables to side-load malicious DLL files.

T1574.001
DLL
MalwareDenis

Denis exploits a security vulnerability to load a fake DLL and execute its code.

T1574.001
DLL
MalwareWaterbear

Waterbear has used DLL side loading to import and load a malicious DLL loader.

T1574.001
DLL
MalwareUPPERCUT

UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation.

T1574.001
DLL
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.

T1574.001
DLL
ToolEmpire

Empire contains modules that can discover and exploit various DLL hijacking opportunities.

T1574.001
DLL
ToolBrute Ratel C4

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.

T1574.004
Dylib Hijacking
ToolEmpire

Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application.

T1574.005
Executable Installer File Permissions Weakness
GroupMustang Panda

Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload.

T1574.006
Dynamic Linker Hijacking
GroupAPT41

APT41 has configured payloads to load via LD_PRELOAD.

T1574.006
Dynamic Linker Hijacking
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1574.006
Dynamic Linker Hijacking
GroupAquatic Panda

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.

T1574.006
Dynamic Linker Hijacking
MalwareMEDUSA

MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library.

T1574.006
Dynamic Linker Hijacking
MalwareCOATHANGER

COATHANGER copies the malicious file /data2/.bd.key/preload.so to /lib/preload.so, then launches a child process that executes the malicious file /data2/.bd.key/authd as /bin/authd with the arguments /lib/preload.so reboot newreboot 1. This injects the malicious preload.so file into the process with PID 1, and replaces its reboot function with the malicious newreboot function for persistence.

T1574.006
Dynamic Linker Hijacking
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to intercept shared library import functions.

T1574.006
Dynamic Linker Hijacking
MalwareSPAWNCHIMERA

SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection.

T1574.006
Dynamic Linker Hijacking
MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

T1574.006
Dynamic Linker Hijacking
MalwareXCSSET

XCSSET adds malicious file paths to the DYLD_FRAMEWORK_PATH and DYLD_LIBRARY_PATH environment variables to execute malicious code.

T1574.006
Dynamic Linker Hijacking
MalwareHiddenWasp

HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable.

T1574.007
Path Interception by PATH Environment Variable
MalwareBRICKSTORM

BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path.

T1574.007
Path Interception by PATH Environment Variable
MalwareDarkGate

DarkGate overrides the %windir% environment variable by setting a Registry key, HKEY_CURRENT_User\Environment\windir, to an alternate command to execute a malicious AutoIt script. This allows DarkGate to run every time the scheduled task DiskCleanup is executed as this uses the path value %windir%\system32\cleanmgr.exe for execution.

T1574.007
Path Interception by PATH Environment Variable
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.007
Path Interception by PATH Environment Variable
ToolEmpire

Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.008
Path Interception by Search Order Hijacking
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities.

T1574.008
Path Interception by Search Order Hijacking
ToolEmpire

Empire contains modules that can discover and exploit search order hijacking vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolEmpire

Empire contains modules that can discover and exploit unquoted path vulnerabilities.

T1574.010
Services File Permissions Weakness
MalwareBlackEnergy

One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence.

T1574.011
Services Registry Permissions Weakness
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.