Native API

T1106

Technique.View on attack.mitre.org

About this technique

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.

Adversaries may abuse these OS API functions as a means of executing behaviors. Similar to Command and Scripting Interpreter, the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system.

Native API functions (such as NtCreateProcess) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries. For example, functions such as the Windows API CreateProcess() or GNU fork() will allow programs and scripts to start other processes. This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.

Higher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.

Adversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks. Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via Disable or Modify Tools.

Detection rules11

Rules on DetectionCode tagged with T1106.

Sigma11

RuleLevelLog source
BPFDoor Abnormal Process ID or Lock File Accessedhighlinux / NULL
HackTool - CobaltStrike BOF Injection Patternhighwindows / process_access
HackTool - HandleKatz Duplicating LSASS Handlehighwindows / process_access
HackTool - RedMimicry Winnti Playbook Executionhighwindows / process_creation
HackTool - WinPwn Executionhighwindows / process_creation
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_script
Potential WinAPI Calls Via CommandLinehighwindows / process_creation
Potential WinAPI Calls Via PowerShell Scriptshighwindows / ps_script
Suspicious Mshta.EXE Execution Patternshighwindows / process_creation
Potential Binary Proxy Execution Via Cdb.EXEmediumwindows / process_creation
Potential Direct Syscall of NtOpenProcessmediumwindows / process_access

Splunk0

No Splunk rules are mapped to this technique yet.

Groups20

Software203

Show 179 more

Campaigns5

Procedure examples228

Groups20

Used byProcedure example
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

GroupAPT38

APT38 has used the Windows API to execute code within a victim's system.

GroupBlackTech

BlackTech has used built-in API functions.

GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

GroupGamaredon Group

Gamaredon Group malware has used CreateProcess to launch additional malicious components.

GroupGorgon Group

Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution.

GroupHigaisa

Higaisa has called various native OS APIs.

GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

View all 20 groups examples

Software203

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL is capable of starting a process using CreateProcess.

MalwareAkira

Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.

MalwareAmadey

Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`.

MalwareANELLDR

ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion.

MalwareAppleSeed

AppleSeed has the ability to use multiple dynamically resolved API calls.

MalwareAria-body

Aria-body has the ability to launch files using ShellExecute.

ToolAsyncRAT

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

MalwareAttor

Attor's dispatcher has used CreateProcessW API for execution.

View all 203 software examples

Campaigns5

Used byProcedure example
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`.

CampaignOperation Sharpshooter

During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`.

CampaignOperation Wocao

During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process.

References15

  1. Apple Core Services Open source
    Apple. (n.d.). Core Services. Retrieved June 25, 2020.
  2. CyberBit System Calls Open source
    Gavriel, H. (2018, November 27). Malware Mitigation when Direct System Calls are Used. Retrieved September 29, 2021.
  3. GLIBC Open source
    glibc developer community. (2020, February 1). The GNU C Library (glibc). Retrieved June 25, 2020.
  4. GNU Fork Open source
    Free Software Foundation, Inc.. (2020, June 18). Creating a Process. Retrieved June 25, 2020.
  5. LIBC Open source
    Kerrisk, M. (2016, December 12). libc(7) — Linux manual page. Retrieved June 25, 2020.
  6. Linux Kernel API Open source
    Linux Kernel Organization, Inc. (n.d.). The Linux Kernel API. Retrieved June 25, 2020.
  7. MACOS Cocoa Open source
    Apple. (2015, September 16). Cocoa Application Layer. Retrieved June 25, 2020.
  8. MDSec System Calls Open source
    MDSec Research. (2020, December). Bypassing User-Mode Hooks and Direct Invocation of System Calls for Red Teams. Retrieved September 29, 2021.
  9. Microsoft CreateProcess Open source
    Microsoft. (n.d.). CreateProcess function. Retrieved September 12, 2024.
  10. Microsoft NET Open source
    Microsoft. (n.d.). What is .NET Framework?. Retrieved March 15, 2020.
  11. Microsoft Win32 Open source
    Microsoft. (n.d.). Programming reference for the Win32 API. Retrieved March 15, 2020.
  12. NT API Windows Open source
    The NTinterlnals.net team. (n.d.). Nowak, T. Retrieved June 25, 2020.
  13. OutFlank System Calls Open source
    de Plaa, C. (2019, June 19). Red Team Tactics: Combining Direct System Calls and sRDI to bypass AV/EDR. Retrieved September 29, 2021.
  14. Redops Syscalls Open source
    Feichter, D. (2023, June 30). Direct Syscalls vs Indirect Syscalls. Retrieved September 27, 2023.
  15. macOS Foundation Open source
    Apple. (n.d.). Foundation. Retrieved July 1, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.