Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.002 Portable Executable Injection |
MalwareInvisiMole | InvisiMole can inject its backdoor as a portable executable into a target process. |
| T1055.002 Portable Executable Injection |
MalwareRustyWater | RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1055.002 Portable Executable Injection |
MalwareCarbanak | Carbanak downloads an executable and injects it directly into a new process. |
| T1055.002 Portable Executable Injection |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1055.002 Portable Executable Injection |
MalwareLizar | Lizar can execute PE files in the address space of the specified process. |
| T1055.002 Portable Executable Injection |
ToolBrute Ratel C4 | Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts. |
| T1055.003 Thread Execution Hijacking |
MalwarePikabot | Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed. |
| T1055.003 Thread Execution Hijacking |
MalwareGazer | Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process. |
| T1055.003 Thread Execution Hijacking |
MalwareTrojan.Karagany | Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the |
| T1055.003 Thread Execution Hijacking |
MalwareWaterbear | Waterbear can use thread injection to inject shellcode into the process of security software. |
| T1055.004 Asynchronous Procedure Call |
GroupFIN8 | FIN8 has injected malicious code into a new svchost.exe process. |
| T1055.004 Asynchronous Procedure Call |
MalwareBumblebee | Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2. |
| T1055.004 Asynchronous Procedure Call |
MalwareSardonic | Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine. |
| T1055.004 Asynchronous Procedure Call |
MalwareHeartCrypt | HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection. |
| T1055.004 Asynchronous Procedure Call |
MalwareBADHATCH | BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue. |
| T1055.004 Asynchronous Procedure Call |
MalwareInvisiMole | InvisiMole can inject its code into a trusted process via the APC queue. |
| T1055.004 Asynchronous Procedure Call |
MalwareIcedID | IcedID has used |
| T1055.004 Asynchronous Procedure Call |
MalwareSaint Bot | Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`. |
| T1055.004 Asynchronous Procedure Call |
MalwareAttor | Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API. |
| T1055.004 Asynchronous Procedure Call |
MalwareXLoader | XLoader injects code into the APC queue using `NtQueueApcThread` API. |
| T1055.004 Asynchronous Procedure Call |
MalwareCarberp | Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread. |
| T1055.004 Asynchronous Procedure Call |
MalwarePillowmint | Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe. |
| T1055.004 Asynchronous Procedure Call |
MalwareTURNEDUP | TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection." |
| T1055.005 Thread Local Storage |
MalwareUrsnif | Ursnif has injected code into target processes via thread local storage callbacks. |
| T1055.005 Thread Local Storage |
MalwareCANONSTAGER | CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array. |
| T1055.008 Ptrace System Calls |
MalwarePACEMAKER | PACEMAKER can use PTRACE to attach to a targeted process to read process memory. |
| T1055.009 Proc Memory |
CampaignKV Botnet Activity | KV Botnet Activity final payload installation includes mounting and binding to the |
| T1055.011 Extra Window Memory Injection |
MalwarePower Loader | Power Loader overwrites Explorer’s Shell_TrayWnd extra window memory to redirect execution to a NTDLL function that is abused to assemble and execute a return-oriented programming (ROP) chain and create a malicious thread within Explorer.exe. |
| T1055.011 Extra Window Memory Injection |
MalwareEpic | Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process. |
| T1055.012 Process Hollowing |
GroupBlackByte | BlackByte used process hollowing for defense evasion purposes. |
| T1055.012 Process Hollowing |
GroupKimsuky | Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing. |
| T1055.012 Process Hollowing |
GroupPatchwork | A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe. |
| T1055.012 Process Hollowing |
GroupGorgon Group | Gorgon Group malware can use process hollowing to inject one of its trojans into another process. |
| T1055.012 Process Hollowing |
GroupmenuPass | menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant. |
| T1055.012 Process Hollowing |
GroupTA2541 | TA2541 has used process hollowing to execute CyberGate malware. |
| T1055.012 Process Hollowing |
GroupAPT-C-36 | APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. |
| T1055.012 Process Hollowing |
GroupThreat Group-3390 | A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process. |
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload. |
| T1055.012 Process Hollowing |
MalwareSmoke Loader | Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware. |
| T1055.012 Process Hollowing |
MalwareHeartCrypt | For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe. |
| T1055.012 Process Hollowing |
MalwareUrsnif | Ursnif has used process hollowing to inject into child processes. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1055.012 Process Hollowing |
MalwareEmotet | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code. |
| T1055.012 Process Hollowing |
MalwareGootloader | Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique. |
| T1055.012 Process Hollowing |
MalwareWoody RAT | Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1055.012 Process Hollowing |
MalwareSnip3 | Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1055.012 Process Hollowing |
MalwareWhisperGate | WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1055.012 Process Hollowing |
MalwareRaspberry Robin | Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.