Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.004 Asynchronous Procedure Call |
MalwareXLoader | XLoader injects code into the APC queue using `NtQueueApcThread` API. |
| T1055.004 Asynchronous Procedure Call |
MalwareCarberp | Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread. |
| T1055.004 Asynchronous Procedure Call |
MalwarePillowmint | Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe. |
| T1055.004 Asynchronous Procedure Call |
MalwareTURNEDUP | TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection." |
| T1055.005 Thread Local Storage |
MalwareUrsnif | Ursnif has injected code into target processes via thread local storage callbacks. |
| T1055.005 Thread Local Storage |
MalwareCANONSTAGER | CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array. |
| T1055.008 Ptrace System Calls |
MalwarePACEMAKER | PACEMAKER can use PTRACE to attach to a targeted process to read process memory. |
| T1055.011 Extra Window Memory Injection |
MalwarePower Loader | Power Loader overwrites Explorer’s Shell_TrayWnd extra window memory to redirect execution to a NTDLL function that is abused to assemble and execute a return-oriented programming (ROP) chain and create a malicious thread within Explorer.exe. |
| T1055.011 Extra Window Memory Injection |
MalwareEpic | Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process. |
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload. |
| T1055.012 Process Hollowing |
MalwareSmoke Loader | Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware. |
| T1055.012 Process Hollowing |
MalwareHeartCrypt | For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe. |
| T1055.012 Process Hollowing |
MalwareUrsnif | Ursnif has used process hollowing to inject into child processes. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1055.012 Process Hollowing |
MalwareEmotet | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code. |
| T1055.012 Process Hollowing |
MalwareGootloader | Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique. |
| T1055.012 Process Hollowing |
MalwareWoody RAT | Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1055.012 Process Hollowing |
MalwareSnip3 | Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1055.012 Process Hollowing |
MalwareWhisperGate | WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1055.012 Process Hollowing |
MalwareRaspberry Robin | Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution. |
| T1055.012 Process Hollowing |
MalwareIcedID | IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1055.012 Process Hollowing |
MalwareISMInjector | ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process. |
| T1055.012 Process Hollowing |
MalwareBBSRAT | BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution. |
| T1055.012 Process Hollowing |
MalwareLumma Stealer | Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1055.012 Process Hollowing |
MalwareClambling | Clambling can execute binaries through process hollowing. |
| T1055.012 Process Hollowing |
MalwareDarkGate | DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1055.012 Process Hollowing |
MalwareSaint Bot | The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1055.012 Process Hollowing |
MalwareBandook | Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1055.012 Process Hollowing |
MalwareCaminho | Caminho has launched and hollowed out MSBuild.exe to host malicious code. |
| T1055.012 Process Hollowing |
MalwareBazar | Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing. |
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1055.012 Process Hollowing |
MalwareTRAILBLAZE | TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1055.012 Process Hollowing |
MalwareLokibot | Lokibot has used process hollowing to inject itself into legitimate Windows process. |
| T1055.012 Process Hollowing |
MalwareAgent Tesla | Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1055.012 Process Hollowing |
MalwareBADNEWS | BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1055.012 Process Hollowing |
MalwareAstaroth | Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code. |
| T1055.012 Process Hollowing |
MalwareQakBot | QakBot can use process hollowing to execute its main payload. |
| T1055.012 Process Hollowing |
MalwareDenis | Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1055.012 Process Hollowing |
MalwareDtrack | Dtrack has used process hollowing shellcode to target a predefined list of processes from |
| T1055.012 Process Hollowing |
MalwareAzorult | Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution. |
| T1055.012 Process Hollowing |
MalwareDuqu | Duqu is capable of loading executable code via process hollowing. |
| T1055.013 Process Doppelgänging |
MalwareSynAck | SynAck abuses NTFS transactions to launch and conceal malicious processes. |
| T1055.013 Process Doppelgänging |
MalwareBazar | Bazar can inject into a target process using process doppelgänging. |
| T1055.015 ListPlanting |
MalwareInvisiMole | InvisiMole has used ListPlanting to inject code into a trusted process. |
| T1056 Input Capture |
MalwareInvisibleFerret | InvisibleFerret has collected mouse and keyboard events using “pyWinhook”. |
| T1056 Input Capture |
MalwareMafalda | Mafalda can conduct mouse event logging. |
| T1056 Input Capture |
MalwareFlawedAmmyy | FlawedAmmyy can collect mouse events. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.