ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055.012×

35 examples

TechniqueUsed byProcedure example
T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1055.012
Process Hollowing
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload.

T1055.012
Process Hollowing
MalwareSmoke Loader

Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware.

T1055.012
Process Hollowing
MalwareHeartCrypt

For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe.

T1055.012
Process Hollowing
MalwareUrsnif

Ursnif has used process hollowing to inject into child processes.

T1055.012
Process Hollowing
MalwareNETWIRE

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1055.012
Process Hollowing
MalwareEmotet

Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code.

T1055.012
Process Hollowing
MalwareGootloader

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.

T1055.012
Process Hollowing
MalwareWoody RAT

Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1055.012
Process Hollowing
MalwareSnip3

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1055.012
Process Hollowing
MalwareWhisperGate

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.

T1055.012
Process Hollowing
MalwareRaspberry Robin

Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution.

T1055.012
Process Hollowing
MalwareIcedID

IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing.

T1055.012
Process Hollowing
MalwareISMInjector

ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process.

T1055.012
Process Hollowing
MalwareBBSRAT

BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution.

T1055.012
Process Hollowing
MalwareLumma Stealer

Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload.

T1055.012
Process Hollowing
MalwareClambling

Clambling can execute binaries through process hollowing.

T1055.012
Process Hollowing
MalwareDarkGate

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.

T1055.012
Process Hollowing
MalwareSaint Bot

The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it.

T1055.012
Process Hollowing
MalwareBandook

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1055.012
Process Hollowing
MalwareCaminho

Caminho has launched and hollowed out MSBuild.exe to host malicious code.

T1055.012
Process Hollowing
MalwareBazar

Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing.

T1055.012
Process Hollowing
MalwareXLoader

XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory.

T1055.012
Process Hollowing
MalwareCobalt Strike

Cobalt Strike can use process hollowing for execution.

T1055.012
Process Hollowing
MalwareTRAILBLAZE

TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`.

T1055.012
Process Hollowing
MalwareLokibot

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1055.012
Process Hollowing
MalwareAgent Tesla

Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code.

T1055.012
Process Hollowing
MalwareBADNEWS

BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process.

T1055.012
Process Hollowing
MalwareAstaroth

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1055.012
Process Hollowing
MalwareQakBot

QakBot can use process hollowing to execute its main payload.

T1055.012
Process Hollowing
MalwareDenis

Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext.

T1055.012
Process Hollowing
MalwareDtrack

Dtrack has used process hollowing shellcode to target a predefined list of processes from %SYSTEM32%.

T1055.012
Process Hollowing
MalwareAzorult

Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution.

T1055.012
Process Hollowing
MalwareDuqu

Duqu is capable of loading executable code via process hollowing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.