ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055.002×

12 examples

TechniqueUsed byProcedure example
T1055.002
Portable Executable Injection
MalwarePikabot

Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it.

T1055.002
Portable Executable Injection
MalwareZeus Panda

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.

T1055.002
Portable Executable Injection
MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1055.002
Portable Executable Injection
MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

T1055.002
Portable Executable Injection
MalwareDUSTPAN

DUSTPAN can inject its decrypted payload into another process.

T1055.002
Portable Executable Injection
MalwareGootloader

Gootloader can use its own PE loader to execute payloads in memory.

T1055.002
Portable Executable Injection
MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

T1055.002
Portable Executable Injection
MalwareRustyWater

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1055.002
Portable Executable Injection
MalwareCarbanak

Carbanak downloads an executable and injects it directly into a new process.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1055.002
Portable Executable Injection
MalwareLizar

Lizar can execute PE files in the address space of the specified process.

T1055.002
Portable Executable Injection
ToolBrute Ratel C4

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.