Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.012 Process Hollowing |
MalwareTrickBot | TrickBot injects into the svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload. |
| T1055.012 Process Hollowing |
MalwareSmoke Loader | Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware. |
| T1055.012 Process Hollowing |
MalwareHeartCrypt | For .NET payloads, HeartCrypt can use process hollowing to inject into processes spawned by csc.exe or AppLaunch.exe. |
| T1055.012 Process Hollowing |
MalwareUrsnif | Ursnif has used process hollowing to inject into child processes. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1055.012 Process Hollowing |
MalwareEmotet | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code. |
| T1055.012 Process Hollowing |
MalwareGootloader | Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique. |
| T1055.012 Process Hollowing |
MalwareWoody RAT | Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`. |
| T1055.012 Process Hollowing |
MalwareSnip3 | Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1055.012 Process Hollowing |
MalwareWhisperGate | WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1055.012 Process Hollowing |
MalwareRaspberry Robin | Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution. |
| T1055.012 Process Hollowing |
MalwareIcedID | IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing. |
| T1055.012 Process Hollowing |
MalwareISMInjector | ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process. |
| T1055.012 Process Hollowing |
MalwareBBSRAT | BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution. |
| T1055.012 Process Hollowing |
MalwareLumma Stealer | Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1055.012 Process Hollowing |
MalwareClambling | Clambling can execute binaries through process hollowing. |
| T1055.012 Process Hollowing |
MalwareDarkGate | DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe. |
| T1055.012 Process Hollowing |
MalwareSaint Bot | The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1055.012 Process Hollowing |
MalwareBandook | Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1055.012 Process Hollowing |
MalwareCaminho | Caminho has launched and hollowed out MSBuild.exe to host malicious code. |
| T1055.012 Process Hollowing |
MalwareBazar | Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing. |
| T1055.012 Process Hollowing |
MalwareXLoader | XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1055.012 Process Hollowing |
MalwareTRAILBLAZE | TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1055.012 Process Hollowing |
MalwareLokibot | Lokibot has used process hollowing to inject itself into legitimate Windows process. |
| T1055.012 Process Hollowing |
MalwareAgent Tesla | Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1055.012 Process Hollowing |
MalwareBADNEWS | BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1055.012 Process Hollowing |
MalwareAstaroth | Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code. |
| T1055.012 Process Hollowing |
MalwareQakBot | QakBot can use process hollowing to execute its main payload. |
| T1055.012 Process Hollowing |
MalwareDenis | Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1055.012 Process Hollowing |
MalwareDtrack | Dtrack has used process hollowing shellcode to target a predefined list of processes from |
| T1055.012 Process Hollowing |
MalwareAzorult | Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution. |
| T1055.012 Process Hollowing |
MalwareDuqu | Duqu is capable of loading executable code via process hollowing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.