Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1620 Reflective Code Loading |
MalwarePikabot | Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine. |
| T1620 Reflective Code Loading |
MalwareSardonic | Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions. |
| T1620 Reflective Code Loading |
MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
| T1620 Reflective Code Loading |
MalwareBADHATCH | BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`. |
| T1620 Reflective Code Loading |
MalwareSystemBC | SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call. |
| T1620 Reflective Code Loading |
MalwareWhisperGate | WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly. |
| T1620 Reflective Code Loading |
MalwareLunarLoader | LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
| T1620 Reflective Code Loading |
MalwareLumma Stealer | Lumma Stealer has used reflective loading techniques to load content into memory during execution. |
| T1620 Reflective Code Loading |
MalwareCuba | Cuba loaded the payload into memory using PowerShell. |
| T1620 Reflective Code Loading |
MalwareThiefQuest | ThiefQuest uses various API functions such as |
| T1620 Reflective Code Loading |
MalwareFoggyWeb | FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory. |
| T1620 Reflective Code Loading |
MalwareMuddyViper | MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread. |
| T1620 Reflective Code Loading |
MalwareFooder | Fooder has reflectively loaded a payload into memory. |
| T1620 Reflective Code Loading |
MalwareUroburos | Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command. |
| T1620 Reflective Code Loading |
MalwareCobalt Strike | Cobalt Strike's |
| T1620 Reflective Code Loading |
MalwareLokibot | Lokibot has reflectively loaded the decoded DLL into memory. |
| T1620 Reflective Code Loading |
MalwareIceApple | IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers. |
| T1620 Reflective Code Loading |
MalwaremetaMain | metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file. |
| T1620 Reflective Code Loading |
MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| T1620 Reflective Code Loading |
MalwareGelsemium | Gelsemium can use custom shellcode to map embedded DLLs into memory. |
| T1620 Reflective Code Loading |
MalwareLizar | Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory. |
| T1620 Reflective Code Loading |
ToolSILENTTRINITY | SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR. |
| T1620 Reflective Code Loading |
ToolPowerSploit | PowerSploit reflectively loads a Windows PE file into a process. |
| T1620 Reflective Code Loading |
ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| T1620 Reflective Code Loading |
ToolDonut | Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.