ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareDarkTortilla

DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection.

T1055.001
Dynamic-link Library Injection
MalwareDyre

Dyre injects into other processes to load modules.

T1055.001
Dynamic-link Library Injection
MalwareRemsec

Remsec can perform DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareSykipot

Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe.

T1055.001
Dynamic-link Library Injection
MalwareMongall

Mongall can inject a DLL into `rundll32.exe` for execution.

T1055.001
Dynamic-link Library Injection
MalwareNetwalker

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1055.001
Dynamic-link Library Injection
MalwareSaint Bot

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.001
Dynamic-link Library Injection
MalwareSagerunex

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1055.001
Dynamic-link Library Injection
MalwareUroburos

Uroburos can use DLL injection to load embedded files and modules.

T1055.001
Dynamic-link Library Injection
MalwareMetamorfo

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1055.001
Dynamic-link Library Injection
MalwarePipeMon

PipeMon can inject its modules into various processes using reflective DLL loading.

T1055.001
Dynamic-link Library Injection
MalwareRARSTONE

After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system.

T1055.001
Dynamic-link Library Injection
MalwareMegaCortex

MegaCortex loads injecthelper.dll into a newly created rundll32.exe process.

T1055.001
Dynamic-link Library Injection
MalwareSDBbot

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

T1055.001
Dynamic-link Library Injection
MalwareDerusbi

Derusbi injects itself into the secure shell (SSH) process.

T1055.001
Dynamic-link Library Injection
MalwareRATANKBA

RATANKBA performs a reflective DLL injection using a given pid.

T1055.001
Dynamic-link Library Injection
MalwareFinFisher

FinFisher injects itself into various processes depending on whether it is low integrity or high integrity.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1055.001
Dynamic-link Library Injection
MalwareTaidoor

Taidoor can perform DLL loading.

T1055.001
Dynamic-link Library Injection
MalwarePoisonIvy

PoisonIvy can inject a malicious DLL into a process.

T1055.001
Dynamic-link Library Injection
MalwareTajMahal

TajMahal has the ability to inject DLLs for malicious plugins into running processes.

T1055.001
Dynamic-link Library Injection
MalwareCarbon

Carbon has a command to inject code into a process.

T1055.001
Dynamic-link Library Injection
MalwareRamsay

Ramsay can use ImprovedReflectiveDLLInjection to deploy components.

T1055.001
Dynamic-link Library Injection
MalwareCarberp

Carberp's bootkit can inject a malicious DLL into the address space of running processes.

T1055.001
Dynamic-link Library Injection
MalwareFunnyDream

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1055.001
Dynamic-link Library Injection
MalwareZxShell

ZxShell is injected into a shared SVCHOST process.

T1055.001
Dynamic-link Library Injection
MalwareMaze

Maze has injected the malware DLL into a target process.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1055.001
Dynamic-link Library Injection
MalwareHeyoka Backdoor

Heyoka Backdoor can inject a DLL into rundll32.exe for execution.

T1055.001
Dynamic-link Library Injection
MalwareQilin

Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution.

T1055.001
Dynamic-link Library Injection
MalwareSocksbot

Socksbot creates a suspended svchost process and injects its DLL into it.

T1055.001
Dynamic-link Library Injection
MalwareHIDEDRV

HIDEDRV injects a DLL for Downdelph into the explorer.exe process.

T1055.001
Dynamic-link Library Injection
MalwareShadowPad

ShadowPad has injected a DLL into svchost.exe.

T1055.001
Dynamic-link Library Injection
MalwareGelsemium

Gelsemium has the ability to inject DLLs into specific processes.

T1055.001
Dynamic-link Library Injection
MalwareLizar

Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading.

T1055.001
Dynamic-link Library Injection
ToolPowerSploit

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1055.001
Dynamic-link Library Injection
ToolIronNetInjector

IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe.

T1055.001
Dynamic-link Library Injection
ToolKoadic

Koadic can perform process injection by using a reflective DLL.

T1055.001
Dynamic-link Library Injection
ToolPupy

Pupy can migrate into another process using reflective DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareDuqu

Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host).

T1055.002
Portable Executable Injection
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus uses the SigFlip tool to inject arbitrary code without affecting or breaking the file's signature.

T1055.002
Portable Executable Injection
GroupGorgon Group

Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.

T1055.002
Portable Executable Injection
GroupRocke

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

T1055.002
Portable Executable Injection
MalwarePikabot

Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it.

T1055.002
Portable Executable Injection
MalwareZeus Panda

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.

T1055.002
Portable Executable Injection
MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1055.002
Portable Executable Injection
MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

T1055.002
Portable Executable Injection
MalwareDUSTPAN

DUSTPAN can inject its decrypted payload into another process.

T1055.002
Portable Executable Injection
MalwareGootloader

Gootloader can use its own PE loader to execute payloads in memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.