ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055×

65 examples

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareTrickBot

TrickBot has used Nt* Native API functions to inject code into legitimate processes such as wermgr.exe.

T1055
Process Injection
MalwareNinja

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1055
Process Injection
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can inject files into running processes.

T1055
Process Injection
MalwareBumblebee

Bumblebee can inject code into multiple processes on infected endpoints.

T1055
Process Injection
MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

T1055
Process Injection
MalwareCOATHANGER

COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library.

T1055
Process Injection
MalwareSmoke Loader

Smoke Loader injects into the Internet Explorer process.

T1055
Process Injection
MalwareAuditCred

AuditCred can inject code from files to other running processes.

T1055
Process Injection
MalwareNETWIRE

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.

T1055
Process Injection
MalwareDUSTTRAP

DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins.

T1055
Process Injection
MalwareBADHATCH

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

T1055
Process Injection
MalwareAvenger

Avenger has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareWoody RAT

Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread.

T1055
Process Injection
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption.

T1055
Process Injection
MalwareHOPLIGHT

HOPLIGHT has injected into running processes.

T1055
Process Injection
MalwareGuLoader

GuLoader has the ability to inject shellcode into a donor processes that is started in a suspended state. GuLoader has previously used RegAsm as a donor process.

T1055
Process Injection
MalwareInvisiMole

InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure.

T1055
Process Injection
MalwareMispadu

Mispadu's binary is injected into memory via `WriteProcessMemory`.

T1055
Process Injection
MalwareNavRAT

NavRAT copies itself into a running Internet Explorer process to evade detection.

T1055
Process Injection
MalwareCostaBricks

CostaBricks can inject a payload into the memory of a compromised host.

T1055
Process Injection
MalwareHyperBro

HyperBro can run shellcode it injects into a newly created process.

T1055
Process Injection
MalwareROKRAT

ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`.

T1055
Process Injection
MalwareDyre

Dyre has the ability to directly inject its code into the web browser process.

T1055
Process Injection
MalwareNOOPLDR

NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe.

T1055
Process Injection
MalwareClambling

Clambling can inject into the `svchost.exe` process for execution.

T1055
Process Injection
MalwarePureCrypter

PureCrypter can inject its final stage into another process on the targeted system.

T1055
Process Injection
MalwareGazer

Gazer injects its communication module into an Internet accessible process through which it performs C2.

T1055
Process Injection
MalwareTSCookie

TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1055
Process Injection
Malwaregh0st RAT

gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function.

T1055
Process Injection
MalwareJHUHUGIT

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1055
Process Injection
MalwareStoneDrill

StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser.

T1055
Process Injection
MalwareAttor

Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection.

T1055
Process Injection
MalwareBazar

Bazar can inject code through calling VirtualAllocExNuma.

T1055
Process Injection
MalwareHiddenFace

HiddenFace can inject code directly into legitimate applications.

T1055
Process Injection
MalwareRyuk

Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.

T1055
Process Injection
MalwareABK

ABK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwarePandora

Pandora can start and inject code into a new `svchost` process.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1055
Process Injection
MalwareWingbird

Wingbird performs multiple process injections to hijack system processes and execute malicious code.

T1055
Process Injection
MalwareREvil

REvil can inject itself into running processes on a compromised host.

T1055
Process Injection
MalwareCardinal RAT

Cardinal RAT injects into a newly spawned process created from a native Windows executable.

T1055
Process Injection
MalwareEgregor

Egregor can inject its payload into iexplore.exe process.

T1055
Process Injection
MalwareANDROMEDA

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

T1055
Process Injection
MalwareJPIN

JPIN can inject content into lsass.exe to load a module.

T1055
Process Injection
MalwaremetaMain

metaMain can inject the loader file, Speech02.db, into a process.

T1055
Process Injection
MalwareMis-Type

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1055
Process Injection
MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055
Process Injection
MalwareShadowPad

ShadowPad has injected an install module into a newly created process.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.