Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1559 Inter-Process Communication |
MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| T1559 Inter-Process Communication |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID. |
| T1559 Inter-Process Communication |
MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| T1559 Inter-Process Communication |
MalwareTONESHELL | TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr. |
| T1559 Inter-Process Communication |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
| T1559 Inter-Process Communication |
MalwareHyperStack | HyperStack can connect to the IPC$ share on remote machines. |
| T1559 Inter-Process Communication |
MalwareRaspberry Robin | Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory. |
| T1559 Inter-Process Communication |
MalwareUroburos | Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes. |
| T1559 Inter-Process Communication |
MalwareOilBooster | OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| T1559 Inter-Process Communication |
MalwareCyclops Blink | Cyclops Blink has the ability to create a pipe to enable inter-process communication. |
| T1559 Inter-Process Communication |
MalwareROADSWEEP | ROADSWEEP can pipe command output to a targeted process. |
| T1559 Inter-Process Communication |
MalwareStealBit | StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner. |
| T1559 Inter-Process Communication |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process. |
| T1559 Inter-Process Communication |
MalwarePITSTOP | PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`. |
| T1559 Inter-Process Communication |
MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| T1559 Inter-Process Communication |
MalwareMini Shai-Hulud | Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.