ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1106×

203 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareTrickBot

TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used Nt* API functions to perform Process Injection.

T1106
Native API
MalwareNinja

The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption.

T1106
Native API
MalwarePikabot

Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution.

T1106
Native API
MalwareRCSession

RCSession can use WinSock API for communication including WSASend and WSARecv.

T1106
Native API
MalwareSynAck

SynAck parses the export tables of system DLLs to locate and call various Windows API functions.

T1106
Native API
MalwareBumblebee

Bumblebee can use multiple Native APIs.

T1106
Native API
MalwareAmadey

Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`.

T1106
Native API
MalwareRDFSNIFFER

RDFSNIFFER has used several Win32 API functions to interact with the victim machine.

T1106
Native API
MalwareTorisma

Torisma has used various Windows API calls.

T1106
Native API
MalwareStuxnet

Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels.

T1106
Native API
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect".

T1106
Native API
MalwareAvosLocker

AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`.

T1106
Native API
MalwarePAKLOG

PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions.

T1106
Native API
MalwareSardonic

Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running.

T1106
Native API
MalwareWindTail

WindTail can invoke Apple APIs contentsOfDirectoryAtPath, pathExtension, and (string) compare.

T1106
Native API
MalwareMisdat

Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`.

T1106
Native API
MalwareHAWKBALL

HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity.

T1106
Native API
MalwareHeartCrypt

HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources.

T1106
Native API
MalwareUrsnif

Ursnif has used CreateProcessW to create child processes.

T1106
Native API
MalwareHavoc

Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection.

T1106
Native API
MalwarePrestige

Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection.

T1106
Native API
MalwareBankshot

Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA().

T1106
Native API
MalwareSharpDisco

SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`.

T1106
Native API
MalwarexCaon

xCaon has leveraged native OS function calls to retrieve victim's network adapter's information using GetAdapterInfo() API.

T1106
Native API
MalwarePony

Pony has used several Windows functions for various purposes.

T1106
Native API
MalwareNebulae

Nebulae has the ability to use CreateProcess to execute a process.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1106
Native API
MalwareMedusa Ransomware

Medusa Ransomware has leveraged Windows Native API functions to execute payloads.

T1106
Native API
MalwareRainyDay

The file collection tool used by RainyDay can utilize native API including ReadDirectoryChangeW for folder monitoring.

T1106
Native API
MalwareAppleSeed

AppleSeed has the ability to use multiple dynamically resolved API calls.

T1106
Native API
MalwareNETWIRE

NETWIRE can use Native API including CreateProcess GetProcessById, and WriteProcessMemory.

T1106
Native API
MalwareTinyTurla

TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions.

T1106
Native API
MalwareBOOKWORM

BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareHyperStack

HyperStack can use Windows API's ConnectNamedPipe and WNetAddConnection2 to detect incoming connections and connect to remote shares.

T1106
Native API
MalwareBad Rabbit

Bad Rabbit has used various Windows API calls.

T1106
Native API
MalwareIMAPLoader

IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`.

T1106
Native API
MalwareAria-body

Aria-body has the ability to launch files using ShellExecute.

T1106
Native API
MalwareEmotet

Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares.

T1106
Native API
MalwareDynoWiper

DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion.

T1106
Native API
MalwareBADHATCH

BADHATCH can utilize Native API functions such as, `ToolHelp32` and `Rt1AdjustPrivilege` to enable `SeDebugPrivilege` on a compromised machine.

T1106
Native API
MalwarePUBLOAD

PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareSystemBC

SystemBC has utilized native Windows API functions such as `EnumWindows`and `GetVolumeInformationA` during discovery activities.

T1106
Native API
MalwareWoody RAT

Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection.

T1106
Native API
MalwareMafalda

Mafalda can use a variety of API calls.

T1106
Native API
MalwareCANONSTAGER

CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload.

T1106
Native API
MalwarePolyglotDuke

PolyglotDuke can use LoadLibraryW and CreateProcess to load and execute code.

T1106
Native API
MalwareSombRAT

SombRAT has the ability to respawn itself using ShellExecuteW and CreateProcessW.

T1106
Native API
MalwareODAgent

ODAgent can pass commands using native APIs.

T1106
Native API
MalwareGuLoader

GuLoader can use a number of different APIs for discovery and execution.

T1106
Native API
MalwareWastedLocker

WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.