ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1574×

9 examples

TechniqueUsed byProcedure example
T1574
Hijack Execution Flow
MalwareCOATHANGER

COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`.

T1574
Hijack Execution Flow
MalwareRaspberry Robin

Raspberry Robin will drop a copy of itself to a subfolder in %Program Data% or %Program Data%\\Microsoft\\ to attempt privilege elevation and defense evasion if not running in Session 0.

T1574
Hijack Execution Flow
MalwareNightdoor

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

T1574
Hijack Execution Flow
MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

T1574
Hijack Execution Flow
MalwareDarkGate

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script. When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

T1574
Hijack Execution Flow
MalwareSaint Bot

Saint Bot will use the malicious file slideshow.mp4 if present to load the core API provided by ntdll.dll to avoid any hooks placed on calls to the original ntdll.dll file by endpoint detection and response or antimalware software.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1574
Hijack Execution Flow
MalwareDenis

Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe.

T1574
Hijack Execution Flow
MalwareDtrack

One of Dtrack can replace the normal flow of a program execution with malicious code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.