Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574 Hijack Execution Flow |
MalwareCOATHANGER | COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`. |
| T1574 Hijack Execution Flow |
MalwareRaspberry Robin | Raspberry Robin will drop a copy of itself to a subfolder in |
| T1574 Hijack Execution Flow |
MalwareNightdoor | Nightdoor uses a legitimate executable to load a malicious DLL file for installation. |
| T1574 Hijack Execution Flow |
MalwareShimRat | ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls. |
| T1574 Hijack Execution Flow |
MalwareDarkGate | DarkGate edits the Registry key |
| T1574 Hijack Execution Flow |
MalwareSaint Bot | Saint Bot will use the malicious file |
| T1574 Hijack Execution Flow |
MalwareSPAWNCHIMERA | SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process. |
| T1574 Hijack Execution Flow |
MalwareDenis | Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe. |
| T1574 Hijack Execution Flow |
MalwareDtrack | One of Dtrack can replace the normal flow of a program execution with malicious code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.