Technique.View on attack.mitre.org
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.
Adversaries may abuse these OS API functions as a means of executing behaviors. Similar to Command and Scripting Interpreter, the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system.
Native API functions (such as NtCreateProcess) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries. For example, functions such as the Windows API CreateProcess() or GNU fork() will allow programs and scripts to start other processes. This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.
Higher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.
Adversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks. Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via Disable or Modify Tools.
Rules on DetectionCode tagged with T1106.
| Rule | Level | Log source |
|---|---|---|
| BPFDoor Abnormal Process ID or Lock File Accessed | high | linux / NULL |
| HackTool - CobaltStrike BOF Injection Pattern | high | windows / process_access |
| HackTool - HandleKatz Duplicating LSASS Handle | high | windows / process_access |
| HackTool - RedMimicry Winnti Playbook Execution | high | windows / process_creation |
| HackTool - WinPwn Execution | high | windows / process_creation |
| HackTool - WinPwn Execution - ScriptBlock | high | windows / ps_script |
| Potential WinAPI Calls Via CommandLine | high | windows / process_creation |
| Potential WinAPI Calls Via PowerShell Scripts | high | windows / ps_script |
| Suspicious Mshta.EXE Execution Patterns | high | windows / process_creation |
| Potential Binary Proxy Execution Via Cdb.EXE | medium | windows / process_creation |
| Potential Direct Syscall of NtOpenProcess | medium | windows / process_access |
| Used by | Procedure example |
|---|---|
| GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| GroupAPT38 | APT38 has used the Windows API to execute code within a victim's system. |
| GroupBlackTech | BlackTech has used built-in API functions. |
| GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
| GroupGamaredon Group | Gamaredon Group malware has used |
| GroupGorgon Group | Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution. |
| GroupHigaisa | Higaisa has called various native OS APIs. |
| GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL is capable of starting a process using CreateProcess. |
| MalwareAkira | Akira executes native Windows functions such as |
| MalwareAmadey | Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`. |
| MalwareANELLDR | ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion. |
| MalwareAppleSeed | AppleSeed has the ability to use multiple dynamically resolved API calls. |
| MalwareAria-body | Aria-body has the ability to launch files using |
| ToolAsyncRAT | AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| MalwareAttor | Attor's dispatcher has used CreateProcessW API for execution. |
View all 203 software examples
| Used by | Procedure example |
|---|---|
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`. |
| CampaignOperation Sharpshooter | During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.