Real-world descriptions of how a group, tool or campaign used a technique.
203 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareBackConfig | BackConfig can leverage API functions such as |
| T1106 Native API |
MalwareANELLDR | ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion. |
| T1106 Native API |
MalwareDEADEYE | DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions. |
| T1106 Native API |
MalwareMango | Mango has the ability to use Native APIs. |
| T1106 Native API |
MalwareInnaputRAT | InnaputRAT uses the API call ShellExecuteW for execution. |
| T1106 Native API |
MalwareGrimAgent | GrimAgent can use Native API including |
| T1106 Native API |
MalwareClop | Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc(). |
| T1106 Native API |
MalwareLokibot | Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode. |
| T1106 Native API |
MalwareEgregor | Egregor has used the Windows API to make detection more difficult. |
| T1106 Native API |
MalwareStealBit | StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes. |
| T1106 Native API |
MalwareZxShell | ZxShell can leverage native API including |
| T1106 Native API |
Malwarebuild_downer | build_downer has the ability to use the |
| T1106 Native API |
MalwareWinnti for Windows | Winnti for Windows can use Native API to create a new process and to start services. |
| T1106 Native API |
MalwareMeteor | Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain. |
| T1106 Native API |
MalwarenjRAT | njRAT has used the ShellExecute() function within a script. |
| T1106 Native API |
MalwareMaze | Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others. |
| T1106 Native API |
MalwareComRAT | ComRAT can load a PE file from memory or the file system and execute it with |
| T1106 Native API |
MalwaremetaMain | metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`. |
| T1106 Native API |
MalwareSideTwist | SideTwist can use |
| T1106 Native API |
MalwareKOCTOPUS | KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution. |
| T1106 Native API |
MalwareMis-Type | Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`. |
| T1106 Native API |
MalwareKillDisk | KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine. |
| T1106 Native API |
MalwareQilin | Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery. |
| T1106 Native API |
MalwareKevin | Kevin can use the `ShowWindow` API to avoid detection. |
| T1106 Native API |
MalwareStarProxy | StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data. |
| T1106 Native API |
MalwareBADNEWS | BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute. |
| T1106 Native API |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name via |
| T1106 Native API |
MalwareQakBot | QakBot can use |
| T1106 Native API |
MalwareDOWNIISSA | DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources. |
| T1106 Native API |
MalwareHancitor | Hancitor has used |
| T1106 Native API |
MalwareGelsemium | Gelsemium has the ability to use various Windows API functions to perform tasks. |
| T1106 Native API |
MalwareDridex | Dridex has used the |
| T1106 Native API |
MalwareBBK | BBK has the ability to use the |
| T1106 Native API |
MalwareDenis | Denis used the |
| T1106 Native API |
MalwareINC Ransomware | INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots. |
| T1106 Native API |
MalwareSplatCloak | SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`. |
| T1106 Native API |
MalwareWaterbear | Waterbear can leverage API functions for execution. |
| T1106 Native API |
MalwareLizar | Lizar has used various Windows API functions on a victim's machine. |
| T1106 Native API |
MalwareBitPaymer | BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including |
| T1106 Native API |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of starting a process using CreateProcess. |
| T1106 Native API |
MalwareStrifeWater | StrifeWater can use a variety of APIs for execution. |
| T1106 Native API |
MalwareWarzoneRAT | WarzoneRAT can use a variety of API calls on a compromised host. |
| T1106 Native API |
MalwareHermeticWizard | HermeticWizard can connect to remote shares using `WNetAddConnection2W`. |
| T1106 Native API |
ToolBloodHound | BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data. |
| T1106 Native API |
ToolShimRatReporter | ShimRatReporter used several Windows API functions to gather information from the infected system. |
| T1106 Native API |
ToolSILENTTRINITY | SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`. |
| T1106 Native API |
ToolEmpire | Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks. |
| T1106 Native API |
ToolPcShare | PcShare has used a variety of Windows API functions. |
| T1106 Native API |
ToolAsyncRAT | AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| T1106 Native API |
ToolBrute Ratel C4 | Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.