Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1129 Shared Modules |
MalwareBLINDINGCAN | BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine. |
| T1129 Shared Modules |
MalwareBumblebee | Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll. |
| T1129 Shared Modules |
MalwareStuxnet | Stuxnet calls LoadLibrary then executes exports from a DLL. |
| T1129 Shared Modules |
MalwareRotaJakiro | RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`. |
| T1129 Shared Modules |
MalwareVersaMem | VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory. |
| T1129 Shared Modules |
MalwareBOOSTWRITE | BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules. |
| T1129 Shared Modules |
MalwareLightSpy | LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class. |
| T1129 Shared Modules |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using the LoadLibrary API. |
| T1129 Shared Modules |
MalwareDarkWatchman | DarkWatchman can load DLLs. |
| T1129 Shared Modules |
MalwareFoggyWeb | FoggyWeb's loader can call the |
| T1129 Shared Modules |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can load and call DLL functions. |
| T1129 Shared Modules |
MalwareMetamorfo | Metamorfo had used AutoIt to load and execute the DLL payload. |
| T1129 Shared Modules |
MalwarePipeMon | PipeMon has used call to |
| T1129 Shared Modules |
Malwaregh0st RAT | gh0st RAT can load DLLs into memory. |
| T1129 Shared Modules |
MalwareAttor | Attor's dispatcher can execute additional plugins by loading the respective DLLs. |
| T1129 Shared Modules |
MalwareOSX_OCEANLOTUS.D | For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`. |
| T1129 Shared Modules |
MalwareTajMahal | TajMahal has the ability to inject the |
| T1129 Shared Modules |
MalwareEbury | Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`. |
| T1129 Shared Modules |
MalwareKillDisk | KillDisk loads and executes functions from a DLL. |
| T1129 Shared Modules |
MalwareAstaroth | Astaroth uses the LoadLibraryExW() function to load additional modules. |
| T1129 Shared Modules |
MalwareDtrack | Dtrack contains a function that calls |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.