Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwareBumblebee | The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareStuxnet | Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process. |
| T1055.001 Dynamic-link Library Injection |
MalwareGet2 | Get2 has the ability to inject DLLs into processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmissary | Emissary injects its DLL file into a newly spawned Internet Explorer process. |
| T1055.001 Dynamic-link Library Injection |
MalwarePS1 | PS1 can inject its payload DLL Into memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareHavoc | Havoc has DLL spawn and injection modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMatryoshka | Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT. |
| T1055.001 Dynamic-link Library Injection |
MalwareTONESHELL | TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1055.001 Dynamic-link Library Injection |
MalwareAria-body | Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmotet | Emotet has been observed injecting in to Explorer.exe and other processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBADHATCH | BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareSombRAT | SombRAT can execute |
| T1055.001 Dynamic-link Library Injection |
MalwareConti | Conti has loaded an encrypted DLL into memory and then executes it. |
| T1055.001 Dynamic-link Library Injection |
MalwareKazuar | If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareBlackEnergy | BlackEnergy injects its DLL component into svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareDarkTortilla | DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDyre | Dyre injects into other processes to load modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareRemsec | Remsec can perform DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareSykipot | Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareMongall | Mongall can inject a DLL into `rundll32.exe` for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareNetwalker | The Netwalker DLL has been injected reflectively into the memory of a legitimate running process. |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareSaint Bot | Saint Bot has injected its DLL component into `EhStorAurhn.exe`. |
| T1055.001 Dynamic-link Library Injection |
MalwareSagerunex | Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareUroburos | Uroburos can use DLL injection to load embedded files and modules. |
| T1055.001 Dynamic-link Library Injection |
MalwareMetamorfo | Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe). |
| T1055.001 Dynamic-link Library Injection |
MalwarePipeMon | PipeMon can inject its modules into various processes using reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwareRARSTONE | After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system. |
| T1055.001 Dynamic-link Library Injection |
MalwareMegaCortex | MegaCortex loads |
| T1055.001 Dynamic-link Library Injection |
MalwareSDBbot | SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process. |
| T1055.001 Dynamic-link Library Injection |
MalwareDerusbi | Derusbi injects itself into the secure shell (SSH) process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRATANKBA | RATANKBA performs a reflective DLL injection using a given pid. |
| T1055.001 Dynamic-link Library Injection |
MalwareFinFisher | FinFisher injects itself into various processes depending on whether it is low integrity or high integrity. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareTaidoor | Taidoor can perform DLL loading. |
| T1055.001 Dynamic-link Library Injection |
MalwarePoisonIvy | PoisonIvy can inject a malicious DLL into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareTajMahal | TajMahal has the ability to inject DLLs for malicious plugins into running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareCarbon | Carbon has a command to inject code into a process. |
| T1055.001 Dynamic-link Library Injection |
MalwareRamsay | Ramsay can use |
| T1055.001 Dynamic-link Library Injection |
MalwareCarberp | Carberp's bootkit can inject a malicious DLL into the address space of running processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1055.001 Dynamic-link Library Injection |
MalwareZxShell | ZxShell is injected into a shared SVCHOST process. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1055.001 Dynamic-link Library Injection |
MalwareComRAT | ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process. |
| T1055.001 Dynamic-link Library Injection |
MalwareHeyoka Backdoor | Heyoka Backdoor can inject a DLL into rundll32.exe for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareQilin | Qilin can inject pwndll.dll, a patched DLL from the legitimate DLL WICloader.dll, into svchost.exe for continuous execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareSocksbot | Socksbot creates a suspended svchost process and injects its DLL into it. |
| T1055.001 Dynamic-link Library Injection |
MalwareHIDEDRV | HIDEDRV injects a DLL for Downdelph into the explorer.exe process. |
| T1055.001 Dynamic-link Library Injection |
MalwareShadowPad | ShadowPad has injected a DLL into svchost.exe. |
| T1055.001 Dynamic-link Library Injection |
MalwareGelsemium | Gelsemium has the ability to inject DLLs into specific processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.