ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1573.002
Asymmetric Cryptography
GroupShinyHunters

ShinyHunters has established a connection between the staging host and the C2 using SSH.

T1574.001
DLL
GroupSideCopy

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1574.001
DLL
GroupGALLIUM

GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.

T1574.001
DLL
GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

T1574.001
DLL
GroupPatchwork

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1574.001
DLL
GroupEvilnum

Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

T1574.001
DLL
GroupMuddyWater

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.

T1574.001
DLL
GroupNaikon

Naikon has used DLL side-loading to load malicious DLL's into legitimate executables.

T1574.001
DLL
GroupStorm-1811

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.

T1574.001
DLL
GroupSidewinder

Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
GroupHigaisa

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.

T1574.001
DLL
GroupTropic Trooper

Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1574.001
DLL
GroupBlackTech

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

T1574.001
DLL
GroupCinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.

T1574.001
DLL
GroupChimera

Chimera has used side loading to place malicious DLLs in memory.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1574.001
DLL
GroupBRONZE BUTLER

BRONZE BUTLER has used legitimate applications to side-load malicious DLLs.

T1574.001
DLL
GroupBackdoorDiplomacy

BackdoorDiplomacy has executed DLL search order hijacking.

T1574.001
DLL
GroupWhitefly

Whitefly has used search order hijacking to run the loader Vcrodat.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1574.001
DLL
GroupRTM

RTM has used search order hijacking to force TeamViewer to load a malicious DLL.

T1574.001
DLL
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

T1574.001
DLL
GroupTonto Team

Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL.

T1574.001
DLL
GroupLazarus Group

Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`.

T1574.001
DLL
GroupEarth Lusca

Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service.

T1574.001
DLL
GroupVelvet Ant

Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

T1574.001
DLL
GroupWIRTE

WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1574.001
DLL
GroupFIN13

FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).

T1574.001
DLL
GroupAPT19

APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL.

T1574.005
Executable Installer File Permissions Weakness
GroupMustang Panda

Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload.

T1574.006
Dynamic Linker Hijacking
GroupAPT41

APT41 has configured payloads to load via LD_PRELOAD.

T1574.006
Dynamic Linker Hijacking
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1574.006
Dynamic Linker Hijacking
GroupAquatic Panda

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.

T1574.012
COR_PROFILER
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR.

T1574.013
KernelCallbackTable
GroupLazarus Group

Lazarus Group has abused the KernelCallbackTable to hijack process control flow and execute shellcode.

T1578.002
Create Cloud Instance
GroupScattered Spider

Scattered Spider has created Amazon EC2 instances within the victim's environment.

T1578.002
Create Cloud Instance
GroupLAPSUS$

LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.

T1578.003
Delete Cloud Instance
GroupStorm-0501

Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions.

T1578.003
Delete Cloud Instance
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1580
Cloud Infrastructure Discovery
GroupStorm-0501

Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources.

T1580
Cloud Infrastructure Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.

T1583
Acquire Infrastructure
GroupIndrik Spider

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.