ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareDerusbi

Derusbi injects itself into the secure shell (SSH) process.

T1055.001
Dynamic-link Library Injection
MalwareRATANKBA

RATANKBA performs a reflective DLL injection using a given pid.

T1055.001
Dynamic-link Library Injection
MalwareFinFisher

FinFisher injects itself into various processes depending on whether it is low integrity or high integrity.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1055.001
Dynamic-link Library Injection
MalwareTaidoor

Taidoor can perform DLL loading.

T1055.001
Dynamic-link Library Injection
MalwarePoisonIvy

PoisonIvy can inject a malicious DLL into a process.

T1055.001
Dynamic-link Library Injection
MalwareTajMahal

TajMahal has the ability to inject DLLs for malicious plugins into running processes.

T1055.001
Dynamic-link Library Injection
MalwareCarbon

Carbon has a command to inject code into a process.

T1055.001
Dynamic-link Library Injection
MalwareRamsay

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.

T1055.001
Dynamic-link Library Injection
MalwareCarberp

Carberp's bootkit can inject a malicious DLL into the address space of running processes.

T1055.001
Dynamic-link Library Injection
MalwareFunnyDream

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1055.001
Dynamic-link Library Injection
MalwareZxShell

ZxShell is injected into a shared SVCHOST process.

T1055.001
Dynamic-link Library Injection
MalwareMaze

Maze has injected the malware DLL into a target process.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1055.001
Dynamic-link Library Injection
MalwareHeyoka Backdoor

Heyoka Backdoor can inject a DLL into rundll32.exe for execution.

T1055.001
Dynamic-link Library Injection
MalwareQilin

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1055.001
Dynamic-link Library Injection
MalwareSocksbot

Socksbot creates a suspended svchost process and injects its DLL into it.

T1055.001
Dynamic-link Library Injection
MalwareHIDEDRV

HIDEDRV injects a DLL for Downdelph into the explorer.exe process.

T1055.001
Dynamic-link Library Injection
MalwareShadowPad

ShadowPad has injected a DLL into svchost.exe.

T1055.001
Dynamic-link Library Injection
MalwareGelsemium

Gelsemium has the ability to inject DLLs into specific processes.

T1055.001
Dynamic-link Library Injection
MalwareLizar

Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading.

T1055.001
Dynamic-link Library Injection
ToolPowerSploit

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1055.001
Dynamic-link Library Injection
ToolIronNetInjector

IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe.

T1055.001
Dynamic-link Library Injection
ToolKoadic

Koadic can perform process injection by using a reflective DLL.

T1055.001
Dynamic-link Library Injection
ToolPupy

Pupy can migrate into another process using reflective DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareDuqu

Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host).

T1055.002
Portable Executable Injection
MalwarePikabot

Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it.

T1055.002
Portable Executable Injection
MalwareZeus Panda

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.

T1055.002
Portable Executable Injection
MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1055.002
Portable Executable Injection
MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

T1055.002
Portable Executable Injection
MalwareDUSTPAN

DUSTPAN can inject its decrypted payload into another process.

T1055.002
Portable Executable Injection
MalwareGootloader

Gootloader can use its own PE loader to execute payloads in memory.

T1055.002
Portable Executable Injection
MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

T1055.002
Portable Executable Injection
MalwareRustyWater

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1055.002
Portable Executable Injection
MalwareCarbanak

Carbanak downloads an executable and injects it directly into a new process.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1055.002
Portable Executable Injection
MalwareLizar

Lizar can execute PE files in the address space of the specified process.

T1055.002
Portable Executable Injection
ToolBrute Ratel C4

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.

T1055.003
Thread Execution Hijacking
MalwarePikabot

Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed.

T1055.003
Thread Execution Hijacking
MalwareGazer

Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.

T1055.003
Thread Execution Hijacking
MalwareTrojan.Karagany

Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the ResumeThread API.

T1055.003
Thread Execution Hijacking
MalwareWaterbear

Waterbear can use thread injection to inject shellcode into the process of security software.

T1055.004
Asynchronous Procedure Call
MalwareBumblebee

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

T1055.004
Asynchronous Procedure Call
MalwareSardonic

Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine.

T1055.004
Asynchronous Procedure Call
MalwareHeartCrypt

HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection.

T1055.004
Asynchronous Procedure Call
MalwareBADHATCH

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

T1055.004
Asynchronous Procedure Call
MalwareInvisiMole

InvisiMole can inject its code into a trusted process via the APC queue.

T1055.004
Asynchronous Procedure Call
MalwareIcedID

IcedID has used ZwQueueApcThread to inject itself into remote processes.

T1055.004
Asynchronous Procedure Call
MalwareSaint Bot

Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`.

T1055.004
Asynchronous Procedure Call
MalwareAttor

Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.