ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
Toolschtasks

schtasks is used to schedule tasks on a Windows system to run at a specific date and time.

T1053.005
Scheduled Task
ToolQuasarRAT

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1053.005
Scheduled Task
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1053.006
Systemd Timers
MalwareMini Shai-Hulud

Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts.

T1053.006
Systemd Timers
MalwareCanisterWorm

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

T1055
Process Injection
MalwareTrickBot

TrickBot has used Nt* Native API functions to inject code into legitimate processes such as wermgr.exe.

T1055
Process Injection
MalwareNinja

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1055
Process Injection
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can inject files into running processes.

T1055
Process Injection
MalwareBumblebee

Bumblebee can inject code into multiple processes on infected endpoints.

T1055
Process Injection
MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

T1055
Process Injection
MalwareCOATHANGER

COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library.

T1055
Process Injection
MalwareSmoke Loader

Smoke Loader injects into the Internet Explorer process.

T1055
Process Injection
MalwareAuditCred

AuditCred can inject code from files to other running processes.

T1055
Process Injection
MalwareNETWIRE

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.

T1055
Process Injection
MalwareDUSTTRAP

DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins.

T1055
Process Injection
MalwareBADHATCH

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

T1055
Process Injection
MalwareAvenger

Avenger has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareWoody RAT

Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread.

T1055
Process Injection
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption.

T1055
Process Injection
MalwareHOPLIGHT

HOPLIGHT has injected into running processes.

T1055
Process Injection
MalwareGuLoader

GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process.

T1055
Process Injection
MalwareInvisiMole

InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure.

T1055
Process Injection
MalwareMispadu

Mispadu's binary is injected into memory via `WriteProcessMemory`.

T1055
Process Injection
MalwareNavRAT

NavRAT copies itself into a running Internet Explorer process to evade detection.

T1055
Process Injection
MalwareCostaBricks

CostaBricks can inject a payload into the memory of a compromised host.

T1055
Process Injection
MalwareHyperBro

HyperBro can run shellcode it injects into a newly created process.

T1055
Process Injection
MalwareROKRAT

ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`.

T1055
Process Injection
MalwareDyre

Dyre has the ability to directly inject its code into the web browser process.

T1055
Process Injection
MalwareNOOPLDR

NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe.

T1055
Process Injection
MalwareClambling

Clambling can inject into the `svchost.exe` process for execution.

T1055
Process Injection
MalwarePureCrypter

PureCrypter can inject its final stage into another process on the targeted system.

T1055
Process Injection
MalwareGazer

Gazer injects its communication module into an Internet accessible process through which it performs C2.

T1055
Process Injection
MalwareTSCookie

TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1055
Process Injection
Malwaregh0st RAT

gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function.

T1055
Process Injection
MalwareJHUHUGIT

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1055
Process Injection
MalwareStoneDrill

StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser.

T1055
Process Injection
MalwareAttor

Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection.

T1055
Process Injection
MalwareBazar

Bazar can inject code through calling VirtualAllocExNuma.

T1055
Process Injection
MalwareHiddenFace

HiddenFace can inject code directly into legitimate applications.

T1055
Process Injection
MalwareRyuk

Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.

T1055
Process Injection
MalwareABK

ABK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwarePandora

Pandora can start and inject code into a new `svchost` process.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1055
Process Injection
MalwareWingbird

Wingbird performs multiple process injections to hijack system processes and execute malicious code.

T1055
Process Injection
MalwareREvil

REvil can inject itself into running processes on a compromised host.

T1055
Process Injection
MalwareCardinal RAT

Cardinal RAT injects into a newly spawned process created from a native Windows executable.

T1055
Process Injection
MalwareEgregor

Egregor can inject its payload into iexplore.exe process.

T1055
Process Injection
MalwareANDROMEDA

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

T1055
Process Injection
MalwareJPIN

JPIN can inject content into lsass.exe to load a module.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.