Reflective Code Loading

T1620

Technique.View on attack.mitre.org

About this technique

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). For example, the `Assembly.Load()` method executed by PowerShell may be abused to load raw code into the running process.

Reflective code injection is very similar to Process Injection except that the “injection” loads code into the processes’ own memory instead of that of a separate process. Reflective loading may evade process-based detections since the execution of the arbitrary code may be masked within a legitimate or otherwise benign process. Reflectively loading payloads directly into memory may also avoid creating files or other artifacts on disk, while also enabling malware to keep these payloads encrypted (or otherwise obfuscated) until execution.

Detection rules5

Rules on DetectionCode tagged with T1620.

Sigma3

RuleLevelLog source
Potential WinAPI Calls Via PowerShell Scriptshighwindows / ps_script
PowerShell Base64 Encoded Reflective Assembly Loadhighwindows / process_creation
Potential In-Memory Execution Using Reflection.Assemblymediumwindows / ps_script

Splunk2

RuleTypeRiskData source
PowerShell PInvoke Process Injection API ChainTTPNULLPowershell Script Block Logging 4104
Windows MMC Loaded Script Engine DLLAnomalyNULLSysmon EventID 7

Groups4

Software26

Show 2 more

Campaigns2

Procedure examples32

Groups4

Used byProcedure example
GroupFIN7

FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`.

GroupGamaredon Group

Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2.

GroupKimsuky

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.

GroupLazarus Group

Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime.

Software26

Used byProcedure example
MalwareBADHATCH

BADHATCH can copy a large byte array of 64-bit shellcode into process memory and execute it with a call to `CreateThread`.

MalwareBRUSHFIRE

BRUSHFIRE has executed its commands within memory and is not saved on disk.

ToolBrute Ratel C4

Brute Ratel C4 has used reflective loading to execute malicious DLLs.

MalwareCobalt Strike

Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process by loading the CLR.

MalwareCuba

Cuba loaded the payload into memory using PowerShell.

ToolDonut

Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads.

MalwareEmotet

Emotet has reflectively loaded payloads into memory.

MalwareFoggyWeb

FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory.

View all 26 software examples

Campaigns2

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

References8

  1. 00sec Droppers Open source
    0x00pico. (2017, September 25). Super-Stealthy Droppers. Retrieved October 4, 2021.
  2. Intezer ACBackdoor Open source
    Sanmillan, I. (2019, November 18). ACBackdoor: Analysis of a New Multiplatform Backdoor. Retrieved October 4, 2021.
  3. Introducing Donut Open source
    The Wover. (2019, May 9). Donut - Injecting .NET Assemblies as Shellcode. Retrieved October 4, 2021.
  4. Mandiant BYOL Open source
    Kirk, N. (2018, June 18). Bring Your Own Land (BYOL) – A Novel Red Teaming Technique. Retrieved October 4, 2021.
  5. Microsoft AssemblyLoad Open source
    Microsoft. (n.d.). Assembly.Load Method. Retrieved February 9, 2024.
  6. S1 Custom Shellcode Tool Open source
    Bunce, D. (2019, October 31). Building A Custom Tool For Shellcode Analysis. Retrieved October 4, 2021.
  7. S1 Old Rat New Tricks Open source
    Landry, J. (2016, April 21). Teaching an old RAT new tricks. Retrieved October 4, 2021.
  8. Stuart ELF Memory Open source
    Stuart. (2018, March 31). In-Memory-Only ELF Execution (Without tmpfs). Retrieved October 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.