Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwareDarkTortilla | DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDyre | Dyre injects into other processes to load modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareRemsec | Remsec can perform DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareSykipot | Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareMongall | Mongall can inject a DLL into `rundll32.exe` for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareNetwalker | The Netwalker DLL has been injected reflectively into the memory of a legitimate running process. |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareSaint Bot | Saint Bot has injected its DLL component into `EhStorAurhn.exe`. |
| T1055.001 Dynamic-link Library Injection |
MalwareSagerunex | Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareUroburos | Uroburos can use DLL injection to load embedded files and modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMetamorfo | Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe). |
| T1055.001 Dynamic-link Library Injection |
MalwarePipeMon | PipeMon can inject its modules into various processes using reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwareRARSTONE | After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system. |
| T1055.001 Dynamic-link Library Injection |
MalwareMegaCortex | MegaCortex loads |
| T1055.001 Dynamic-link Library Injection |
MalwareSDBbot | SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process. |
| T1055.001 Dynamic-link Library Injection |
MalwareDerusbi | Derusbi injects itself into the secure shell (SSH) process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRATANKBA | RATANKBA performs a reflective DLL injection using a given pid. |
| T1055.001 Dynamic-link Library Injection |
MalwareFinFisher | FinFisher injects itself into various processes depending on whether it is low integrity or high integrity. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareTaidoor | Taidoor can perform DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwarePoisonIvy | PoisonIvy can inject a malicious DLL into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareTajMahal | TajMahal has the ability to inject DLLs for malicious plugins into running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarbon | Carbon has a command to inject code into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRamsay | Ramsay can use |
| T1055.001 Dynamic-link Library Injection |
MalwareCarberp | Carberp's bootkit can inject a malicious DLL into the address space of running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1055.001 Dynamic-link Library Injection |
MalwareZxShell | ZxShell is injected into a shared SVCHOST process. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1055.001 Dynamic-link Library Injection |
MalwareComRAT | ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process. |
| T1055.001 Dynamic-link Library Injection |
MalwareHeyoka Backdoor | Heyoka Backdoor can inject a DLL into rundll32.exe for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareQilin | Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareSocksbot | Socksbot creates a suspended svchost process and injects its DLL into it. |
| T1055.001 Dynamic-link Library Injection |
MalwareHIDEDRV | HIDEDRV injects a DLL for Downdelph into the explorer.exe process. |
| T1055.001 Dynamic-link Library Injection |
MalwareShadowPad | ShadowPad has injected a DLL into svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareGelsemium | Gelsemium has the ability to inject DLLs into specific processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareLizar | Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
ToolPowerSploit | PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process. |
| T1055.001 Dynamic-link Library Injection |
ToolIronNetInjector | IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe. |
| T1055.001 Dynamic-link Library Injection |
ToolKoadic | Koadic can perform process injection by using a reflective DLL. |
| T1055.001 Dynamic-link Library Injection |
ToolPupy | Pupy can migrate into another process using reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDuqu | Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host). |
| T1055.002 Portable Executable Injection |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus uses the SigFlip tool to inject arbitrary code without affecting or breaking the file's signature. |
| T1055.002 Portable Executable Injection |
GroupGorgon Group | Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process. |
| T1055.002 Portable Executable Injection |
GroupRocke | Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe. |
| T1055.002 Portable Executable Injection |
MalwarePikabot | Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it. |
| T1055.002 Portable Executable Injection |
MalwareZeus Panda | Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process. |
| T1055.002 Portable Executable Injection |
MalwareHavoc | Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1055.002 Portable Executable Injection |
MalwareGreyEnergy | GreyEnergy has a module to inject a PE binary into a remote process. |
| T1055.002 Portable Executable Injection |
MalwareDUSTPAN | DUSTPAN can inject its decrypted payload into another process. |
| T1055.002 Portable Executable Injection |
MalwareGootloader | Gootloader can use its own PE loader to execute payloads in memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.