Technique.View on attack.mitre.org
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). For example, the `Assembly.Load()` method executed by PowerShell may be abused to load raw code into the running process.
Reflective code injection is very similar to Process Injection except that the “injection” loads code into the processes’ own memory instead of that of a separate process. Reflective loading may evade process-based detections since the execution of the arbitrary code may be masked within a legitimate or otherwise benign process. Reflectively loading payloads directly into memory may also avoid creating files or other artifacts on disk, while also enabling malware to keep these payloads encrypted (or otherwise obfuscated) until execution.
Rules on DetectionCode tagged with T1620.
| Rule | Level | Log source |
|---|---|---|
| Potential WinAPI Calls Via PowerShell Scripts | high | windows / ps_script |
| PowerShell Base64 Encoded Reflective Assembly Load | high | windows / process_creation |
| Potential In-Memory Execution Using Reflection.Assembly | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| PowerShell PInvoke Process Injection API Chain | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows MMC Loaded Script Engine DLL | Anomaly | NULL | Sysmon EventID 7 |
| Used by | Procedure example |
|---|---|
| GroupFIN7 | FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`. |
| GroupGamaredon Group | Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2. |
| GroupKimsuky | Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`. |
| GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
| Used by | Procedure example |
|---|---|
| MalwareBADHATCH | BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`. |
| MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| MalwareCobalt Strike | Cobalt Strike's |
| MalwareCuba | Cuba loaded the payload into memory using PowerShell. |
| ToolDonut | Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
| MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
| MalwareFoggyWeb | FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.