Portable Executable Injection

T1055.002

Sub-technique of T1055 Process Injection.View on attack.mitre.org

About this technique

Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.

PE injection is commonly performed by copying code (perhaps without a file on disk) into the virtual address space of the target process before invoking it via a new thread. The write can be performed with native Windows API calls such as VirtualAllocEx and WriteProcessMemory, then invoked with CreateRemoteThread or additional code (ex: shellcode). The displacement of the injected code does introduce the additional requirement for functionality to remap memory references.

Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via PE injection may also evade detection from security products since the execution is masked under a legitimate process.

Detection rules4

Rules on DetectionCode tagged with T1055.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk4

RuleTypeRiskData source
Windows Process Injection into Commonly Abused ProcessesAnomalyNULLSysmon EventID 10
Windows Process Injection into NotepadAnomalyNULLSysmon EventID 10
Windows Process Injection Remote ThreadTTPNULLSysmon EventID 8
Windows Process Injection With Public Source PathHuntingNULLSysmon EventID 8

Groups2

Software12

Campaigns1

Procedure examples15

Groups2

Used byProcedure example
GroupGorgon Group

Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.

GroupRocke

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

Software12

Used byProcedure example
ToolBrute Ratel C4

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.

MalwareCarbanak

Carbanak downloads an executable and injects it directly into a new process.

MalwareDUSTPAN

DUSTPAN can inject its decrypted payload into another process.

MalwareGootloader

Gootloader can use its own PE loader to execute payloads in memory.

MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

MalwareLizar

Lizar can execute PE files in the address space of the specified process.

View all 12 software examples

Campaigns1

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus uses the SigFlip tool to inject arbitrary code without affecting or breaking the file's signature.

References1

  1. Elastic Process Injection July 2017 Open source
    Hosseini, A. (2017, July 18). Ten Process Injection Techniques: A Technical Survey Of Common And Trending Process Injection Techniques. Retrieved December 7, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.