ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1106×

203 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareBackConfig

BackConfig can leverage API functions such as ShellExecuteA and HttpOpenRequestA in the process of downloading and executing files.

T1106
Native API
MalwareANELLDR

ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion.

T1106
Native API
MalwareDEADEYE

DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions.

T1106
Native API
MalwareMango

Mango has the ability to use Native APIs.

T1106
Native API
MalwareInnaputRAT

InnaputRAT uses the API call ShellExecuteW for execution.

T1106
Native API
MalwareGrimAgent

GrimAgent can use Native API including GetProcAddress and ShellExecuteW.

T1106
Native API
MalwareClop

Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc().

T1106
Native API
MalwareLokibot

Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode.

T1106
Native API
MalwareEgregor

Egregor has used the Windows API to make detection more difficult.

T1106
Native API
MalwareStealBit

StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes.

T1106
Native API
MalwareZxShell

ZxShell can leverage native API including RegisterServiceCtrlHandler to register a service.RegisterServiceCtrlHandler

T1106
Native API
Malwarebuild_downer

build_downer has the ability to use the WinExec API to execute malware on a compromised host.

T1106
Native API
MalwareWinnti for Windows

Winnti for Windows can use Native API to create a new process and to start services.

T1106
Native API
MalwareMeteor

Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain.

T1106
Native API
MalwarenjRAT

njRAT has used the ShellExecute() function within a script.

T1106
Native API
MalwareMaze

Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others.

T1106
Native API
MalwareComRAT

ComRAT can load a PE file from memory or the file system and execute it with CreateProcessW.

T1106
Native API
MalwaremetaMain

metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`.

T1106
Native API
MalwareSideTwist

SideTwist can use GetUserNameW, GetComputerNameW, and GetComputerNameExW to gather information.

T1106
Native API
MalwareKOCTOPUS

KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution.

T1106
Native API
MalwareMis-Type

Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`.

T1106
Native API
MalwareKillDisk

KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine.

T1106
Native API
MalwareQilin

Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.

T1106
Native API
MalwareKevin

Kevin can use the `ShowWindow` API to avoid detection.

T1106
Native API
MalwareStarProxy

StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data.

T1106
Native API
MalwareBADNEWS

BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute.

T1106
Native API
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name via GetUserNameW.

T1106
Native API
MalwareQakBot

QakBot can use GetProcAddress to help delete malicious strings from memory.

T1106
Native API
MalwareDOWNIISSA

DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources.

T1106
Native API
MalwareHancitor

Hancitor has used CallWindowProc and EnumResourceTypesA to interpret and execute shellcode.

T1106
Native API
MalwareGelsemium

Gelsemium has the ability to use various Windows API functions to perform tasks.

T1106
Native API
MalwareDridex

Dridex has used the OutputDebugStringW function to avoid malware analysis as part of its anti-debugging technique.

T1106
Native API
MalwareBBK

BBK has the ability to use the CreatePipe API to add a sub-process for execution via cmd.

T1106
Native API
MalwareDenis

Denis used the IsDebuggerPresent, OutputDebugString, and SetLastError APIs to avoid debugging. Denis used GetProcAddress and LoadLibrary to dynamically resolve APIs. Denis also used the Wow64SetThreadContext API as part of a process hollowing process.

T1106
Native API
MalwareINC Ransomware

INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.

T1106
Native API
MalwareSplatCloak

SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`.

T1106
Native API
MalwareWaterbear

Waterbear can leverage API functions for execution.

T1106
Native API
MalwareLizar

Lizar has used various Windows API functions on a victim's machine.

T1106
Native API
MalwareBitPaymer

BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.

T1106
Native API
MalwareADVSTORESHELL

ADVSTORESHELL is capable of starting a process using CreateProcess.

T1106
Native API
MalwareStrifeWater

StrifeWater can use a variety of APIs for execution.

T1106
Native API
MalwareWarzoneRAT

WarzoneRAT can use a variety of API calls on a compromised host.

T1106
Native API
MalwareHermeticWizard

HermeticWizard can connect to remote shares using `WNetAddConnection2W`.

T1106
Native API
ToolBloodHound

BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data.

T1106
Native API
ToolShimRatReporter

ShimRatReporter used several Windows API functions to gather information from the infected system.

T1106
Native API
ToolSILENTTRINITY

SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`.

T1106
Native API
ToolEmpire

Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks.

T1106
Native API
ToolPcShare

PcShare has used a variety of Windows API functions.

T1106
Native API
ToolAsyncRAT

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

T1106
Native API
ToolBrute Ratel C4

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.