ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1055.012
Process Hollowing
MalwareIcedID

IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing.

T1055.012
Process Hollowing
MalwareISMInjector

ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process.

T1055.012
Process Hollowing
MalwareBBSRAT

BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution.

T1055.012
Process Hollowing
MalwareLumma Stealer

Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload.

T1055.012
Process Hollowing
MalwareClambling

Clambling can execute binaries through process hollowing.

T1055.012
Process Hollowing
MalwareDarkGate

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.

T1055.012
Process Hollowing
MalwareSaint Bot

The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it.

T1055.012
Process Hollowing
MalwareBandook

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1055.012
Process Hollowing
MalwareCaminho

Caminho has launched and hollowed out MSBuild.exe to host malicious code.

T1055.012
Process Hollowing
MalwareBazar

Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing.

T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1055.012
Process Hollowing
MalwareCobalt Strike

Cobalt Strike can use process hollowing for execution.

T1055.012
Process Hollowing
MalwareTRAILBLAZE

TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`.

T1055.012
Process Hollowing
MalwareLokibot

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1055.012
Process Hollowing
MalwareAgent Tesla

Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code.

T1055.012
Process Hollowing
MalwareBADNEWS

BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process.

T1055.012
Process Hollowing
MalwareAstaroth

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1055.012
Process Hollowing
MalwareQakBot

QakBot can use process hollowing to execute its main payload.

T1055.012
Process Hollowing
MalwareDenis

Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext.

T1055.012
Process Hollowing
MalwareDtrack

Dtrack has used process hollowing shellcode to target a predefined list of processes from %SYSTEM32%.

T1055.012
Process Hollowing
MalwareAzorult

Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution.

T1055.012
Process Hollowing
MalwareDuqu

Duqu is capable of loading executable code via process hollowing.

T1055.013
Process Doppelgänging
GroupLeafminer

Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems.

T1055.013
Process Doppelgänging
MalwareSynAck

SynAck abuses NTFS transactions to launch and conceal malicious processes.

T1055.013
Process Doppelgänging
MalwareBazar

Bazar can inject into a target process using process doppelgänging.

T1055.015
ListPlanting
MalwareInvisiMole

InvisiMole has used ListPlanting to inject code into a trusted process.

T1056
Input Capture
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices.

T1056
Input Capture
CampaignLeviathan Australian Intrusions

Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions.

T1056
Input Capture
GroupStorm-1811

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

T1056
Input Capture
GroupAPT39

APT39 has utilized tools to capture mouse movements.

T1056
Input Capture
GroupAPT42

APT42 has used credential harvesting websites.

T1056
Input Capture
MalwareInvisibleFerret

InvisibleFerret has collected mouse and keyboard events using “pyWinhook”.

T1056
Input Capture
MalwareMafalda

Mafalda can conduct mouse event logging.

T1056
Input Capture
MalwareFlawedAmmyy

FlawedAmmyy can collect mouse events.

T1056
Input Capture
MalwareChaes

Chaes has a module to perform any API hooking it desires.

T1056
Input Capture
MalwareKobalos

Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host.

T1056
Input Capture
MalwaremetaMain

metaMain can log mouse events.

T1056
Input Capture
ToolNPPSPY

NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext.

T1056.001
Keylogging
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin.

T1056.001
Keylogging
CampaignCutting Edge

During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials.

T1056.001
Keylogging
CampaignOperation Wocao

During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger.

T1056.001
Keylogging
GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1056.001
Keylogging
GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1056.001
Keylogging
GroupVolt Typhoon

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.

T1056.001
Keylogging
GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

T1056.001
Keylogging
GroupmenuPass

menuPass has used key loggers to steal usernames and passwords.

T1056.001
Keylogging
GroupAPT32

APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes.

T1056.001
Keylogging
GroupSandworm Team

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.