Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwareDerusbi | Derusbi injects itself into the secure shell (SSH) process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRATANKBA | RATANKBA performs a reflective DLL injection using a given pid. |
| T1055.001 Dynamic-link Library Injection |
MalwareFinFisher | FinFisher injects itself into various processes depending on whether it is low integrity or high integrity. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareTaidoor | Taidoor can perform DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwarePoisonIvy | PoisonIvy can inject a malicious DLL into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareTajMahal | TajMahal has the ability to inject DLLs for malicious plugins into running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarbon | Carbon has a command to inject code into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRamsay | Ramsay can use |
| T1055.001 Dynamic-link Library Injection |
MalwareCarberp | Carberp's bootkit can inject a malicious DLL into the address space of running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1055.001 Dynamic-link Library Injection |
MalwareZxShell | ZxShell is injected into a shared SVCHOST process. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1055.001 Dynamic-link Library Injection |
MalwareComRAT | ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process. |
| T1055.001 Dynamic-link Library Injection |
MalwareHeyoka Backdoor | Heyoka Backdoor can inject a DLL into rundll32.exe for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareQilin | Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareSocksbot | Socksbot creates a suspended svchost process and injects its DLL into it. |
| T1055.001 Dynamic-link Library Injection |
MalwareHIDEDRV | HIDEDRV injects a DLL for Downdelph into the explorer.exe process. |
| T1055.001 Dynamic-link Library Injection |
MalwareShadowPad | ShadowPad has injected a DLL into svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareGelsemium | Gelsemium has the ability to inject DLLs into specific processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareLizar | Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
ToolPowerSploit | PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process. |
| T1055.001 Dynamic-link Library Injection |
ToolIronNetInjector | IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe. |
| T1055.001 Dynamic-link Library Injection |
ToolKoadic | Koadic can perform process injection by using a reflective DLL. |
| T1055.001 Dynamic-link Library Injection |
ToolPupy | Pupy can migrate into another process using reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDuqu | Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host). |
| T1055.002 Portable Executable Injection |
MalwarePikabot | Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it. |
| T1055.002 Portable Executable Injection |
MalwareZeus Panda | Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process. |
| T1055.002 Portable Executable Injection |
MalwareHavoc | Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1055.002 Portable Executable Injection |
MalwareGreyEnergy | GreyEnergy has a module to inject a PE binary into a remote process. |
| T1055.002 Portable Executable Injection |
MalwareDUSTPAN | DUSTPAN can inject its decrypted payload into another process. |
| T1055.002 Portable Executable Injection |
MalwareGootloader | Gootloader can use its own PE loader to execute payloads in memory. |
| T1055.002 Portable Executable Injection |
MalwareInvisiMole | InvisiMole can inject its backdoor as a portable executable into a target process. |
| T1055.002 Portable Executable Injection |
MalwareRustyWater | RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1055.002 Portable Executable Injection |
MalwareCarbanak | Carbanak downloads an executable and injects it directly into a new process. |
| T1055.002 Portable Executable Injection |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1055.002 Portable Executable Injection |
MalwareLizar | Lizar can execute PE files in the address space of the specified process. |
| T1055.002 Portable Executable Injection |
ToolBrute Ratel C4 | Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts. |
| T1055.003 Thread Execution Hijacking |
MalwarePikabot | Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed. |
| T1055.003 Thread Execution Hijacking |
MalwareGazer | Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process. |
| T1055.003 Thread Execution Hijacking |
MalwareTrojan.Karagany | Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the |
| T1055.003 Thread Execution Hijacking |
MalwareWaterbear | Waterbear can use thread injection to inject shellcode into the process of security software. |
| T1055.004 Asynchronous Procedure Call |
MalwareBumblebee | Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2. |
| T1055.004 Asynchronous Procedure Call |
MalwareSardonic | Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine. |
| T1055.004 Asynchronous Procedure Call |
MalwareHeartCrypt | HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection. |
| T1055.004 Asynchronous Procedure Call |
MalwareBADHATCH | BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue. |
| T1055.004 Asynchronous Procedure Call |
MalwareInvisiMole | InvisiMole can inject its code into a trusted process via the APC queue. |
| T1055.004 Asynchronous Procedure Call |
MalwareIcedID | IcedID has used |
| T1055.004 Asynchronous Procedure Call |
MalwareSaint Bot | Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`. |
| T1055.004 Asynchronous Procedure Call |
MalwareAttor | Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.