ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055.001×

10 examples

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
GroupKimsuky

Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1055.001
Dynamic-link Library Injection
GroupPutter Panda

An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe).

T1055.001
Dynamic-link Library Injection
GroupLeviathan

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1055.001
Dynamic-link Library Injection
GroupTurla

Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges.

T1055.001
Dynamic-link Library Injection
GroupTA505

TA505 has been seen injecting a DLL into winword.exe.

T1055.001
Dynamic-link Library Injection
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs.

T1055.001
Dynamic-link Library Injection
GroupMalteiro

Malteiro has injected Mispadu’s DLL into a process.

T1055.001
Dynamic-link Library Injection
GroupLazarus Group

A Lazarus Group malware sample performs reflective DLL injection.

T1055.001
Dynamic-link Library Injection
GroupWizard Spider

Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.