ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareCardinal RAT

Cardinal RAT injects into a newly spawned process created from a native Windows executable.

T1055
Process Injection
MalwareEgregor

Egregor can inject its payload into iexplore.exe process.

T1055
Process Injection
MalwareANDROMEDA

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

T1055
Process Injection
MalwareJPIN

JPIN can inject content into lsass.exe to load a module.

T1055
Process Injection
MalwaremetaMain

metaMain can inject the loader file, Speech02.db, into a process.

T1055
Process Injection
MalwareMis-Type

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1055
Process Injection
MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055
Process Injection
MalwareShadowPad

ShadowPad has injected an install module into a newly created process.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1055
Process Injection
MalwareDOWNIISSA

DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe.

T1055
Process Injection
MalwareBBK

BBK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareWaterbear

Waterbear can inject decrypted shellcode into the LanmanServer service.

T1055
Process Injection
MalwareLizar

Lizar can migrate the loader into another process.

T1055
Process Injection
MalwareWarzoneRAT

WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation.

T1055
Process Injection
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can inject into running processes on a compromised host.

T1055
Process Injection
ToolSliver

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1055
Process Injection
ToolSILENTTRINITY

SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process.

T1055
Process Injection
ToolEmpire

Empire contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolPcShare

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1055
Process Injection
ToolPoshC2

PoshC2 contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolRemcos

Remcos has a command to hide itself by injecting into another process.

T1055
Process Injection
ToolDonut

Donut includes a subproject DonutTest to inject shellcode into a target process.

T1055
Process Injection
ToolIronNetInjector

IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process.

T1055
Process Injection
ToolHTRAN

HTRAN can inject into into running processes.

T1055.001
Dynamic-link Library Injection
CampaignC0015

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.

T1055.001
Dynamic-link Library Injection
GroupKimsuky

Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1055.001
Dynamic-link Library Injection
GroupPutter Panda

An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe).

T1055.001
Dynamic-link Library Injection
GroupLeviathan

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1055.001
Dynamic-link Library Injection
GroupTurla

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

T1055.001
Dynamic-link Library Injection
GroupTA505

TA505 has been seen injecting a DLL into winword.exe.

T1055.001
Dynamic-link Library Injection
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs.

T1055.001
Dynamic-link Library Injection
GroupMalteiro

Malteiro has injected Mispadu’s DLL into a process.

T1055.001
Dynamic-link Library Injection
GroupLazarus Group

A Lazarus Group malware sample performs reflective DLL injection.

T1055.001
Dynamic-link Library Injection
GroupWizard Spider

Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions.

T1055.001
Dynamic-link Library Injection
MalwareBumblebee

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.001
Dynamic-link Library Injection
MalwareStuxnet

Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.

T1055.001
Dynamic-link Library Injection
MalwareGet2

Get2 has the ability to inject DLLs into processes.

T1055.001
Dynamic-link Library Injection
MalwareEmissary

Emissary injects its DLL file into a newly spawned Internet Explorer process.

T1055.001
Dynamic-link Library Injection
MalwarePS1

PS1 can inject its payload DLL Into memory.

T1055.001
Dynamic-link Library Injection
MalwareHavoc

Havoc has DLL spawn and injection modules.

T1055.001
Dynamic-link Library Injection
MalwareMatryoshka

Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT.

T1055.001
Dynamic-link Library Injection
MalwareTONESHELL

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1055.001
Dynamic-link Library Injection
MalwareAria-body

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1055.001
Dynamic-link Library Injection
MalwareEmotet

Emotet has been observed injecting in to Explorer.exe and other processes.

T1055.001
Dynamic-link Library Injection
MalwareBADHATCH

BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine.

T1055.001
Dynamic-link Library Injection
MalwareSombRAT

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1055.001
Dynamic-link Library Injection
MalwareConti

Conti has loaded an encrypted DLL into memory and then executes it.

T1055.001
Dynamic-link Library Injection
MalwareKazuar

If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes.

T1055.001
Dynamic-link Library Injection
MalwareBlackEnergy

BlackEnergy injects its DLL component into svchost.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.