Process Injection

T1055

Technique with 12 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific.

More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.

Detection rules85

Rules on DetectionCode tagged with T1055 or one of its sub-techniques.

Sigma41

RuleLevelLog sourceTechnique
CobaltStrike Named Pipecriticalwindows / pipe_createdT1055
CobaltStrike Named Pipe Pattern Regexcriticalwindows / pipe_createdT1055
HackTool - DInjector PowerShell Cradle Executioncriticalwindows / process_creationT1055
Malicious Named Pipe Createdcriticalwindows / pipe_createdT1055
ASLR Disabled Via Sysctl or Direct Syscall - Linuxhighlinux / NULLT1055.009
CobaltStrike Named Pipe Patternshighwindows / pipe_createdT1055
Dllhost.EXE Execution Anomalyhighwindows / process_creationT1055
DotNet CLR DLL Loaded By Scripting Applicationshighwindows / image_loadT1055
Execution Of Non-Existing Filehighwindows / process_creationT1055
HackTool - CACTUSTORCH Remote Thread Creationhighwindows / create_remote_threadT1055.012
HackTool - CoercedPotato Executionhighwindows / process_creationT1055
HackTool - CoercedPotato Named Pipe Creationhighwindows / pipe_createdT1055
HackTool - EfsPotato Named Pipe Creationhighwindows / pipe_createdT1055
HackTool - HollowReaper Executionhighwindows / process_creationT1055.012
HackTool - LittleCorporal Generated Maldoc Injectionhighwindows / process_accessT1055.003

Splunk44

RuleTypeRiskData sourceTechnique
AWS Bedrock Claude excessive use of tokensAnomalyNULLAWS Bedrock ClaudeT1055
AWS Bedrock Claude High Risk Filesystem and Exec Tool InvocationAnomalyNULLAWS Bedrock ClaudeT1055
AWS Bedrock Claude Hostile Prompt SentimentAnomalyNULLAWS Bedrock ClaudeT1055
AWS Bedrock Claude Possible Prompt InjectionHuntingNULLAWS Bedrock ClaudeT1055
AWS Bedrock Claude Sensitive Data in PromptsAnomalyNULLAWS Bedrock ClaudeT1055
AWS Bedrock Claude Unusually Large PromptsAnomalyNULLAWS Bedrock ClaudeT1055
Cisco NVM - Non-Network Binary Making Network ConnectionAnomalyNULLCisco Network Visibility Module Flow DataT1055
Cisco NVM - Suspicious Network Connection From Process With No ArgsAnomalyNULLCisco Network Visibility Module Flow DataT1055
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1055
Cobalt Strike Named PipesTTPNULLSysmon EventID 17, Sysmon EventID 18T1055
Create Remote Thread In Shell ApplicationTTPNULLSysmon EventID 8T1055
DLLHost with no Command Line Arguments with NetworkTTPNULLSysmon EventID 1 AND Sysmon EventID 3T1055
GPUpdate with no Command Line Arguments with NetworkTTPNULLSysmon EventID 1 AND Sysmon EventID 3T1055
Loading Of Dynwrapx ModuleTTPNULLSysmon EventID 7T1055.001
Notepad with no Command Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1055

Sub-techniques12

IDNameExamples
T1055.001Dynamic-link Library Injection67
T1055.002Portable Executable Injection15
T1055.003Thread Execution Hijacking4
T1055.004Asynchronous Procedure Call13
T1055.005Thread Local Storage2
T1055.008Ptrace System Calls1
T1055.009Proc Memory1
T1055.011Extra Window Memory Injection2
T1055.012Process Hollowing43
T1055.013Process Doppelgänging3
T1055.014VDSO Hijacking0
T1055.015ListPlanting1

Groups15

Software65

Show 41 more

Campaigns7

Procedure examples87

Groups15

Used byProcedure example
GroupAPT32

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

GroupAPT37

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

GroupAPT38

APT38 has injected malicious payloads into the `explorer.exe` process.

GroupAPT41

APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.

GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

GroupCobalt Group

Cobalt Group has injected code into trusted processes.

GroupGamaredon Group

Gamaredon Group has injected Remcos into explorer.exe.

View all 15 groups examples

Software65

Used byProcedure example
MalwareABK

ABK has the ability to inject shellcode into svchost.exe.

MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

MalwareANDROMEDA

ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions.

MalwareAttor

Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection.

MalwareAuditCred

AuditCred can inject code from files to other running processes.

MalwareAvenger

Avenger has the ability to inject shellcode into svchost.exe.

MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

MalwareBADHATCH

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

View all 65 software examples

Campaigns7

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2.

Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary.

CampaignArcaneDoor

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

CampaignCutting Edge

During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors.

CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word.

CampaignOperation Wocao

During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original.

CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.