Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareCardinal RAT | Cardinal RAT injects into a newly spawned process created from a native Windows executable. |
| T1055 Process Injection |
MalwareEgregor | Egregor can inject its payload into iexplore.exe process. |
| T1055 Process Injection |
MalwareANDROMEDA | ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| T1055 Process Injection |
MalwareJPIN | JPIN can inject content into lsass.exe to load a module. |
| T1055 Process Injection |
MalwaremetaMain | metaMain can inject the loader file, Speech02.db, into a process. |
| T1055 Process Injection |
MalwareMis-Type | Mis-Type has been injected directly into a running process, including `explorer.exe`. |
| T1055 Process Injection |
MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055 Process Injection |
MalwareShadowPad | ShadowPad has injected an install module into a newly created process. |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1055 Process Injection |
MalwareDOWNIISSA | DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe. |
| T1055 Process Injection |
MalwareBBK | BBK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareWaterbear | Waterbear can inject decrypted shellcode into the LanmanServer service. |
| T1055 Process Injection |
MalwareLizar | Lizar can migrate the loader into another process. |
| T1055 Process Injection |
MalwareWarzoneRAT | WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation. |
| T1055 Process Injection |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can inject into running processes on a compromised host. |
| T1055 Process Injection |
ToolSliver | Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine. |
| T1055 Process Injection |
ToolSILENTTRINITY | SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process. |
| T1055 Process Injection |
ToolEmpire | Empire contains multiple modules for injecting into processes, such as |
| T1055 Process Injection |
ToolPcShare | The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes. |
| T1055 Process Injection |
ToolPoshC2 | PoshC2 contains multiple modules for injecting into processes, such as |
| T1055 Process Injection |
ToolRemcos | Remcos has a command to hide itself by injecting into another process. |
| T1055 Process Injection |
ToolDonut | Donut includes a subproject |
| T1055 Process Injection |
ToolIronNetInjector | IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process. |
| T1055 Process Injection |
ToolHTRAN | HTRAN can inject into into running processes. |
| T1055.001 Dynamic-link Library Injection |
CampaignC0015 | During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process. |
| T1055.001 Dynamic-link Library Injection |
GroupKimsuky | Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`. |
| T1055.001 Dynamic-link Library Injection |
GroupTropic Trooper | Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupPutter Panda | An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe). |
| T1055.001 Dynamic-link Library Injection |
GroupLeviathan | Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim. |
| T1055.001 Dynamic-link Library Injection |
GroupTurla | Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
| T1055.001 Dynamic-link Library Injection |
GroupTA505 | TA505 has been seen injecting a DLL into winword.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs. |
| T1055.001 Dynamic-link Library Injection |
GroupMalteiro | |
| T1055.001 Dynamic-link Library Injection |
GroupLazarus Group | A Lazarus Group malware sample performs reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
| T1055.001 Dynamic-link Library Injection |
MalwareBumblebee | The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareStuxnet | Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process. |
| T1055.001 Dynamic-link Library Injection |
MalwareGet2 | Get2 has the ability to inject DLLs into processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmissary | Emissary injects its DLL file into a newly spawned Internet Explorer process. |
| T1055.001 Dynamic-link Library Injection |
MalwarePS1 | PS1 can inject its payload DLL Into memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareHavoc | Havoc has DLL spawn and injection modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMatryoshka | Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT. |
| T1055.001 Dynamic-link Library Injection |
MalwareTONESHELL | TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1055.001 Dynamic-link Library Injection |
MalwareAria-body | Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmotet | Emotet has been observed injecting in to Explorer.exe and other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBADHATCH | BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareSombRAT | SombRAT can execute |
| T1055.001 Dynamic-link Library Injection |
MalwareConti | Conti has loaded an encrypted DLL into memory and then executes it. |
| T1055.001 Dynamic-link Library Injection |
MalwareKazuar | If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBlackEnergy | BlackEnergy injects its DLL component into svchost.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.