Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.007 Msiexec |
MalwareRCSession | RCSession has the ability to execute inside the msiexec.exe process. |
| T1218.007 Msiexec |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via an MSI installer. |
| T1218.007 Msiexec |
MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| T1218.007 Msiexec |
MalwareRaspberry Robin | Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution. |
| T1218.007 Msiexec |
MalwareMispadu | Mispadu has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1218.007 Msiexec |
MalwareRagnar Locker | Ragnar Locker has been delivered as an unsigned MSI package that was executed with |
| T1218.007 Msiexec |
MalwareJavali | Javali has used the MSI installer to download and execute malicious payloads. |
| T1218.007 Msiexec |
MalwareLatrodectus | Latrodectus has called `msiexec` to install remotely-hosted MSI files. |
| T1218.007 Msiexec |
MalwareChaes | Chaes has used .MSI files as an initial way to start the infection chain. |
| T1218.007 Msiexec |
MalwareMetamorfo | Metamorfo has used MsiExec.exe to automatically execute files. |
| T1218.007 Msiexec |
MalwareRedLine Stealer | RedLine Stealer has been installed via MSI Installer. |
| T1218.007 Msiexec |
MalwareGrandoreiro | Grandoreiro can use MSI files to execute DLLs. |
| T1218.007 Msiexec |
MalwareDEADEYE | DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| T1218.007 Msiexec |
MalwareClop | Clop can use msiexec.exe to disable security tools on the system. |
| T1218.007 Msiexec |
MalwareMelcoz | Melcoz can use MSI files with embedded VBScript for execution. |
| T1218.007 Msiexec |
MalwareMaze | Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1218.007 Msiexec |
MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareQakBot | QakBot can use MSIExec to spawn multiple cmd.exe processes. |
| T1218.007 Msiexec |
MalwareDOWNIISSA | DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process. |
| T1218.007 Msiexec |
MalwareLoudMiner | LoudMiner used an MSI installer to install the virtualization software. |
| T1218.007 Msiexec |
ToolRemoteUtilities | RemoteUtilities can use Msiexec to install a service. |
| T1218.007 Msiexec |
MalwareDuqu | Duqu has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.