Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwaremetaMain | metaMain can inject the loader file, Speech02.db, into a process. |
| T1055 Process Injection |
MalwareMis-Type | Mis-Type has been injected directly into a running process, including `explorer.exe`. |
| T1055 Process Injection |
MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055 Process Injection |
MalwareShadowPad | ShadowPad has injected an install module into a newly created process. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1055 Process Injection |
MalwareDOWNIISSA | DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe. |
| T1055 Process Injection |
MalwareBBK | BBK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareWaterbear | Waterbear can inject decrypted shellcode into the LanmanServer service. |
| T1055 Process Injection |
MalwareLizar | Lizar can migrate the loader into another process. |
| T1055 Process Injection |
MalwareWarzoneRAT | WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation. |
| T1055 Process Injection |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can inject into running processes on a compromised host. |
| T1055 Process Injection |
ToolSliver | Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine. |
| T1055 Process Injection |
ToolSILENTTRINITY | SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process. |
| T1055 Process Injection |
ToolEmpire | Empire contains multiple modules for injecting into processes, such as |
| T1055 Process Injection |
ToolPcShare | The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes. |
| T1055 Process Injection |
ToolPoshC2 | PoshC2 contains multiple modules for injecting into processes, such as |
| T1055 Process Injection |
ToolRemcos | Remcos has a command to hide itself by injecting into another process. |
| T1055 Process Injection |
ToolDonut | Donut includes a subproject |
| T1055 Process Injection |
ToolIronNetInjector | IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process. |
| T1055 Process Injection |
ToolHTRAN | HTRAN can inject into into running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBumblebee | The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareStuxnet | Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process. |
| T1055.001 Dynamic-link Library Injection |
MalwareGet2 | Get2 has the ability to inject DLLs into processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmissary | Emissary injects its DLL file into a newly spawned Internet Explorer process. |
| T1055.001 Dynamic-link Library Injection |
MalwarePS1 | PS1 can inject its payload DLL Into memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareHavoc | Havoc has DLL spawn and injection modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMatryoshka | Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT. |
| T1055.001 Dynamic-link Library Injection |
MalwareTONESHELL | TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1055.001 Dynamic-link Library Injection |
MalwareAria-body | Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmotet | Emotet has been observed injecting in to Explorer.exe and other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBADHATCH | BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareSombRAT | SombRAT can execute |
| T1055.001 Dynamic-link Library Injection |
MalwareConti | Conti has loaded an encrypted DLL into memory and then executes it. |
| T1055.001 Dynamic-link Library Injection |
MalwareKazuar | If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBlackEnergy | BlackEnergy injects its DLL component into svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareDarkTortilla | DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDyre | Dyre injects into other processes to load modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareRemsec | Remsec can perform DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareSykipot | Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareMongall | Mongall can inject a DLL into `rundll32.exe` for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareNetwalker | The Netwalker DLL has been injected reflectively into the memory of a legitimate running process. |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareSaint Bot | Saint Bot has injected its DLL component into `EhStorAurhn.exe`. |
| T1055.001 Dynamic-link Library Injection |
MalwareSagerunex | Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareUroburos | Uroburos can use DLL injection to load embedded files and modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMetamorfo | Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe). |
| T1055.001 Dynamic-link Library Injection |
MalwarePipeMon | PipeMon can inject its modules into various processes using reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwareRARSTONE | After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system. |
| T1055.001 Dynamic-link Library Injection |
MalwareMegaCortex | MegaCortex loads |
| T1055.001 Dynamic-link Library Injection |
MalwareSDBbot | SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.