ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1620×

26 examples

TechniqueUsed byProcedure example
T1620
Reflective Code Loading
MalwarePikabot

Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine.

T1620
Reflective Code Loading
MalwareSardonic

Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions.

T1620
Reflective Code Loading
MalwareEmotet

Emotet has reflectively loaded payloads into memory.

T1620
Reflective Code Loading
MalwareBADHATCH

BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`.

T1620
Reflective Code Loading
MalwareSystemBC

SystemBC has downloaded a text file into memory and set the area of memory via the VirtualProtect call. Then, SystemBC has executed the file via the CreateThread call.

T1620
Reflective Code Loading
MalwareWhisperGate

WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly.

T1620
Reflective Code Loading
MalwareLunarLoader

LunarLoader can use reflective loading to decrypt and run malicious executables in a new thread.

T1620
Reflective Code Loading
MalwarePlugX

PlugX has loaded its payload into memory.

T1620
Reflective Code Loading
MalwareLumma Stealer

Lumma Stealer has used reflective loading techniques to load content into memory during execution.

T1620
Reflective Code Loading
MalwareCuba

Cuba loaded the payload into memory using PowerShell.

T1620
Reflective Code Loading
MalwareThiefQuest

ThiefQuest uses various API functions such as NSCreateObjectFileImageFromMemory to load and link in-memory payloads.

T1620
Reflective Code Loading
MalwareFoggyWeb

FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory.

T1620
Reflective Code Loading
MalwareMuddyViper

MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread.

T1620
Reflective Code Loading
MalwareFooder

Fooder has reflectively loaded a payload into memory.

T1620
Reflective Code Loading
MalwareUroburos

Uroburos has the ability to load new modules directly into memory using its `Load Modules Mem` command.

T1620
Reflective Code Loading
MalwareCobalt Strike

Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process by loading the CLR.

T1620
Reflective Code Loading
MalwareLokibot

Lokibot has reflectively loaded the decoded DLL into memory.

T1620
Reflective Code Loading
MalwareIceApple

IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers.

T1620
Reflective Code Loading
MalwaremetaMain

metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file.

T1620
Reflective Code Loading
MalwareBRUSHFIRE

BRUSHFIRE has executed its commands within memory and is not saved on disk.

T1620
Reflective Code Loading
MalwareGelsemium

Gelsemium can use custom shellcode to map embedded DLLs into memory.

T1620
Reflective Code Loading
MalwareLizar

Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory.

T1620
Reflective Code Loading
ToolSILENTTRINITY

SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR.

T1620
Reflective Code Loading
ToolPowerSploit

PowerSploit reflectively loads a Windows PE file into a process.

T1620
Reflective Code Loading
ToolBrute Ratel C4

Brute Ratel C4 has used reflective loading to execute malicious DLLs.

T1620
Reflective Code Loading
ToolDonut

Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.