Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
GroupKimsuky | Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`. |
| T1055.001 Dynamic-link Library Injection |
GroupTropic Trooper | Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupPutter Panda | An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe). |
| T1055.001 Dynamic-link Library Injection |
GroupLeviathan | Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim. |
| T1055.001 Dynamic-link Library Injection |
GroupTurla | Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
| T1055.001 Dynamic-link Library Injection |
GroupTA505 | TA505 has been seen injecting a DLL into winword.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs. |
| T1055.001 Dynamic-link Library Injection |
GroupMalteiro | |
| T1055.001 Dynamic-link Library Injection |
GroupLazarus Group | A Lazarus Group malware sample performs reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.