Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.002 Portable Executable Injection |
MalwarePikabot | Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it. |
| T1055.002 Portable Executable Injection |
MalwareZeus Panda | Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process. |
| T1055.002 Portable Executable Injection |
MalwareHavoc | Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1055.002 Portable Executable Injection |
MalwareGreyEnergy | GreyEnergy has a module to inject a PE binary into a remote process. |
| T1055.002 Portable Executable Injection |
MalwareDUSTPAN | DUSTPAN can inject its decrypted payload into another process. |
| T1055.002 Portable Executable Injection |
MalwareGootloader | Gootloader can use its own PE loader to execute payloads in memory. |
| T1055.002 Portable Executable Injection |
MalwareInvisiMole | InvisiMole can inject its backdoor as a portable executable into a target process. |
| T1055.002 Portable Executable Injection |
MalwareRustyWater | RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1055.002 Portable Executable Injection |
MalwareCarbanak | Carbanak downloads an executable and injects it directly into a new process. |
| T1055.002 Portable Executable Injection |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1055.002 Portable Executable Injection |
MalwareLizar | Lizar can execute PE files in the address space of the specified process. |
| T1055.002 Portable Executable Injection |
ToolBrute Ratel C4 | Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.