ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1055.002
Portable Executable Injection
MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

T1055.002
Portable Executable Injection
MalwareRustyWater

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1055.002
Portable Executable Injection
MalwareCarbanak

Carbanak downloads an executable and injects it directly into a new process.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1055.002
Portable Executable Injection
MalwareLizar

Lizar can execute PE files in the address space of the specified process.

T1055.002
Portable Executable Injection
ToolBrute Ratel C4

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.

T1055.003
Thread Execution Hijacking
MalwarePikabot

Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed.

T1055.003
Thread Execution Hijacking
MalwareGazer

Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.

T1055.003
Thread Execution Hijacking
MalwareTrojan.Karagany

Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the ResumeThread API.

T1055.003
Thread Execution Hijacking
MalwareWaterbear

Waterbear can use thread injection to inject shellcode into the process of security software.

T1055.004
Asynchronous Procedure Call
GroupFIN8

FIN8 has injected malicious code into a new svchost.exe process.

T1055.004
Asynchronous Procedure Call
MalwareBumblebee

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

T1055.004
Asynchronous Procedure Call
MalwareSardonic

Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine.

T1055.004
Asynchronous Procedure Call
MalwareHeartCrypt

HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection.

T1055.004
Asynchronous Procedure Call
MalwareBADHATCH

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

T1055.004
Asynchronous Procedure Call
MalwareInvisiMole

InvisiMole can inject its code into a trusted process via the APC queue.

T1055.004
Asynchronous Procedure Call
MalwareIcedID

IcedID has used ZwQueueApcThread to inject itself into remote processes.

T1055.004
Asynchronous Procedure Call
MalwareSaint Bot

Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`.

T1055.004
Asynchronous Procedure Call
MalwareAttor

Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API.

T1055.004
Asynchronous Procedure Call
MalwareXLoader

XLoader injects code into the APC queue using `NtQueueApcThread` API.

T1055.004
Asynchronous Procedure Call
MalwareCarberp

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.

T1055.004
Asynchronous Procedure Call
MalwarePillowmint

Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe.

T1055.004
Asynchronous Procedure Call
MalwareTURNEDUP

TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection."

T1055.005
Thread Local Storage
MalwareUrsnif

Ursnif has injected code into target processes via thread local storage callbacks.

T1055.005
Thread Local Storage
MalwareCANONSTAGER

CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array.

T1055.008
Ptrace System Calls
MalwarePACEMAKER

PACEMAKER can use PTRACE to attach to a targeted process to read process memory.

T1055.009
Proc Memory
CampaignKV Botnet Activity

KV Botnet Activity final payload installation includes mounting and binding to the \/proc\/ filepath on the victim system to enable subsequent operation in memory while also removing on-disk artifacts.

T1055.011
Extra Window Memory Injection
MalwarePower Loader

Power Loader overwrites Explorer’s Shell_TrayWnd extra window memory to redirect execution to a NTDLL function that is abused to assemble and execute a return-oriented programming (ROP) chain and create a malicious thread within Explorer.exe.

T1055.011
Extra Window Memory Injection
MalwareEpic

Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process.

T1055.012
Process Hollowing
GroupBlackByte

BlackByte used process hollowing for defense evasion purposes.

T1055.012
Process Hollowing
GroupKimsuky

Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing.

T1055.012
Process Hollowing
GroupPatchwork

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.

T1055.012
Process Hollowing
GroupGorgon Group

Gorgon Group malware can use process hollowing to inject one of its trojans into another process.

T1055.012
Process Hollowing
GroupmenuPass

menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant.

T1055.012
Process Hollowing
GroupTA2541

TA2541 has used process hollowing to execute CyberGate malware.

T1055.012
Process Hollowing
GroupAPT-C-36

APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes.

T1055.012
Process Hollowing
GroupThreat Group-3390

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.

T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1055.012
Process Hollowing
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload.

T1055.012
Process Hollowing
MalwareSmoke Loader

Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware.

T1055.012
Process Hollowing
MalwareHeartCrypt

For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe.

T1055.012
Process Hollowing
MalwareUrsnif

Ursnif has used process hollowing to inject into child processes.

T1055.012
Process Hollowing
MalwareNETWIRE

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1055.012
Process Hollowing
MalwareEmotet

Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code.

T1055.012
Process Hollowing
MalwareGootloader

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.

T1055.012
Process Hollowing
MalwareWoody RAT

Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1055.012
Process Hollowing
MalwareSnip3

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1055.012
Process Hollowing
MalwareWhisperGate

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.

T1055.012
Process Hollowing
MalwareRaspberry Robin

Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.