Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.012 Process Hollowing |
MalwareIcedID | IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1055.012 Process Hollowing |
MalwareISMInjector | ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process. |
| T1055.012 Process Hollowing |
MalwareBBSRAT | BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution. |
| T1055.012 Process Hollowing |
MalwareLumma Stealer | Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1055.012 Process Hollowing |
MalwareClambling | Clambling can execute binaries through process hollowing. |
| T1055.012 Process Hollowing |
MalwareDarkGate | DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1055.012 Process Hollowing |
MalwareSaint Bot | The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1055.012 Process Hollowing |
MalwareBandook | Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1055.012 Process Hollowing |
MalwareCaminho | Caminho has launched and hollowed out MSBuild.exe to host malicious code. |
| T1055.012 Process Hollowing |
MalwareBazar | Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing. |
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1055.012 Process Hollowing |
MalwareTRAILBLAZE | TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1055.012 Process Hollowing |
MalwareLokibot | Lokibot has used process hollowing to inject itself into legitimate Windows process. |
| T1055.012 Process Hollowing |
MalwareAgent Tesla | Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1055.012 Process Hollowing |
MalwareBADNEWS | BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1055.012 Process Hollowing |
MalwareAstaroth | Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code. |
| T1055.012 Process Hollowing |
MalwareQakBot | QakBot can use process hollowing to execute its main payload. |
| T1055.012 Process Hollowing |
MalwareDenis | Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1055.012 Process Hollowing |
MalwareDtrack | Dtrack has used process hollowing shellcode to target a predefined list of processes from |
| T1055.012 Process Hollowing |
MalwareAzorult | Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution. |
| T1055.012 Process Hollowing |
MalwareDuqu | Duqu is capable of loading executable code via process hollowing. |
| T1055.013 Process Doppelgänging |
GroupLeafminer | Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems. |
| T1055.013 Process Doppelgänging |
MalwareSynAck | SynAck abuses NTFS transactions to launch and conceal malicious processes. |
| T1055.013 Process Doppelgänging |
MalwareBazar | Bazar can inject into a target process using process doppelgänging. |
| T1055.015 ListPlanting |
MalwareInvisiMole | InvisiMole has used ListPlanting to inject code into a trusted process. |
| T1056 Input Capture |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices. |
| T1056 Input Capture |
CampaignLeviathan Australian Intrusions | Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions. |
| T1056 Input Capture |
GroupStorm-1811 | Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item. |
| T1056 Input Capture |
GroupAPT39 | APT39 has utilized tools to capture mouse movements. |
| T1056 Input Capture |
GroupAPT42 | APT42 has used credential harvesting websites. |
| T1056 Input Capture |
MalwareInvisibleFerret | InvisibleFerret has collected mouse and keyboard events using “pyWinhook”. |
| T1056 Input Capture |
MalwareMafalda | Mafalda can conduct mouse event logging. |
| T1056 Input Capture |
MalwareFlawedAmmyy | FlawedAmmyy can collect mouse events. |
| T1056 Input Capture |
MalwareChaes | Chaes has a module to perform any API hooking it desires. |
| T1056 Input Capture |
MalwareKobalos | Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host. |
| T1056 Input Capture |
MalwaremetaMain | metaMain can log mouse events. |
| T1056 Input Capture |
ToolNPPSPY | NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext. |
| T1056.001 Keylogging |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin. |
| T1056.001 Keylogging |
CampaignCutting Edge | During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials. |
| T1056.001 Keylogging |
CampaignOperation Wocao | During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger. |
| T1056.001 Keylogging |
GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1056.001 Keylogging |
GroupVolt Typhoon | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution. |
| T1056.001 Keylogging |
GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| T1056.001 Keylogging |
GroupmenuPass | menuPass has used key loggers to steal usernames and passwords. |
| T1056.001 Keylogging |
GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| T1056.001 Keylogging |
GroupSandworm Team | Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.