Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
Toolschtasks | schtasks is used to schedule tasks on a Windows system to run at a specific date and time. |
| T1053.005 Scheduled Task |
ToolQuasarRAT | QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot. |
| T1053.005 Scheduled Task |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1053.006 Systemd Timers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts. |
| T1053.006 Systemd Timers |
MalwareCanisterWorm | CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1055 Process Injection |
MalwareTrickBot | TrickBot has used |
| T1055 Process Injection |
MalwareNinja | Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes. |
| T1055 Process Injection |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can inject files into running processes. |
| T1055 Process Injection |
MalwareBumblebee | Bumblebee can inject code into multiple processes on infected endpoints. |
| T1055 Process Injection |
MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| T1055 Process Injection |
MalwareCOATHANGER | COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library. |
| T1055 Process Injection |
MalwareSmoke Loader | Smoke Loader injects into the Internet Explorer process. |
| T1055 Process Injection |
MalwareAuditCred | AuditCred can inject code from files to other running processes. |
| T1055 Process Injection |
MalwareNETWIRE | NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe. |
| T1055 Process Injection |
MalwareDUSTTRAP | DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins. |
| T1055 Process Injection |
MalwareBADHATCH | BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| T1055 Process Injection |
MalwareAvenger | Avenger has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareWoody RAT | Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread. |
| T1055 Process Injection |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption. |
| T1055 Process Injection |
MalwareHOPLIGHT | HOPLIGHT has injected into running processes. |
| T1055 Process Injection |
MalwareGuLoader | GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process. |
| T1055 Process Injection |
MalwareInvisiMole | InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure. |
| T1055 Process Injection |
MalwareMispadu | Mispadu's binary is injected into memory via `WriteProcessMemory`. |
| T1055 Process Injection |
MalwareNavRAT | NavRAT copies itself into a running Internet Explorer process to evade detection. |
| T1055 Process Injection |
MalwareCostaBricks | CostaBricks can inject a payload into the memory of a compromised host. |
| T1055 Process Injection |
MalwareHyperBro | HyperBro can run shellcode it injects into a newly created process. |
| T1055 Process Injection |
MalwareROKRAT | ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`. |
| T1055 Process Injection |
MalwareDyre | Dyre has the ability to directly inject its code into the web browser process. |
| T1055 Process Injection |
MalwareNOOPLDR | NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe. |
| T1055 Process Injection |
MalwareClambling | Clambling can inject into the `svchost.exe` process for execution. |
| T1055 Process Injection |
MalwarePureCrypter | PureCrypter can inject its final stage into another process on the targeted system. |
| T1055 Process Injection |
MalwareGazer | Gazer injects its communication module into an Internet accessible process through which it performs C2. |
| T1055 Process Injection |
MalwareTSCookie | TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes. |
| T1055 Process Injection |
MalwareLODEINFO | LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1055 Process Injection |
Malwaregh0st RAT | gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function. |
| T1055 Process Injection |
MalwareJHUHUGIT | JHUHUGIT performs code injection injecting its own functions to browser processes. |
| T1055 Process Injection |
MalwareStoneDrill | StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser. |
| T1055 Process Injection |
MalwareAttor | Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection. |
| T1055 Process Injection |
MalwareBazar | Bazar can inject code through calling |
| T1055 Process Injection |
MalwareHiddenFace | HiddenFace can inject code directly into legitimate applications. |
| T1055 Process Injection |
MalwareRyuk | Ryuk has injected itself into remote processes to encrypt files using a combination of |
| T1055 Process Injection |
MalwareABK | ABK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwarePandora | Pandora can start and inject code into a new `svchost` process. |
| T1055 Process Injection |
MalwareCobalt Strike | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary. |
| T1055 Process Injection |
MalwareWingbird | Wingbird performs multiple process injections to hijack system processes and execute malicious code. |
| T1055 Process Injection |
MalwareREvil | REvil can inject itself into running processes on a compromised host. |
| T1055 Process Injection |
MalwareCardinal RAT | Cardinal RAT injects into a newly spawned process created from a native Windows executable. |
| T1055 Process Injection |
MalwareEgregor | Egregor can inject its payload into iexplore.exe process. |
| T1055 Process Injection |
MalwareANDROMEDA | ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| T1055 Process Injection |
MalwareJPIN | JPIN can inject content into lsass.exe to load a module. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.