Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1559 Inter-Process Communication |
MalwareHyperStack | HyperStack can connect to the IPC$ share on remote machines. |
| T1559 Inter-Process Communication |
MalwareRaspberry Robin | Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory. |
| T1559 Inter-Process Communication |
MalwareUroburos | Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes. |
| T1559 Inter-Process Communication |
MalwareOilBooster | OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| T1559 Inter-Process Communication |
MalwareCyclops Blink | Cyclops Blink has the ability to create a pipe to enable inter-process communication. |
| T1559 Inter-Process Communication |
MalwareROADSWEEP | ROADSWEEP can pipe command output to a targeted process. |
| T1559 Inter-Process Communication |
MalwareStealBit | StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner. |
| T1559 Inter-Process Communication |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has leveraged IPC using a UNIX domain socket between the dsmdm process and the web process. |
| T1559 Inter-Process Communication |
MalwarePITSTOP | PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`. |
| T1559 Inter-Process Communication |
MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| T1559 Inter-Process Communication |
MalwareMini Shai-Hulud | Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory. |
| T1559.001 Component Object Model |
GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| T1559.001 Component Object Model |
GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| T1559.001 Component Object Model |
GroupGamaredon Group | Gamaredon Group malware can insert malicious macros into documents using a |
| T1559.001 Component Object Model |
GroupMedusa Group | Medusa Group has leveraged Component Object Model (COM) to bypass UAC. |
| T1559.001 Component Object Model |
MalwareTrickBot | TrickBot used COM to setup scheduled task for persistence. |
| T1559.001 Component Object Model |
MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| T1559.001 Component Object Model |
MalwareUrsnif | Ursnif droppers have used COM objects to execute the malware's full executable payload. |
| T1559.001 Component Object Model |
MalwareSTATICPLUGIN | STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file. |
| T1559.001 Component Object Model |
MalwareInvisiMole | InvisiMole can use the |
| T1559.001 Component Object Model |
MalwareCLAIMLOADER | CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface. |
| T1559.001 Component Object Model |
MalwareNeoichor | Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2. |
| T1559.001 Component Object Model |
MalwareRaspberry Robin | Raspberry Robin creates an elevated COM object for |
| T1559.001 Component Object Model |
MalwareRustyWater | RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
| T1559.001 Component Object Model |
MalwareDarkTortilla | DarkTortilla has used the `WshShortcut` COM object to create a .lnk shortcut file in the Windows startup folder. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1559.001 Component Object Model |
MalwareMilan | Milan can use a COM component to generate scheduled tasks. |
| T1559.001 Component Object Model |
MalwareRamsay | Ramsay can use the Windows COM API to schedule tasks and maintain persistence. |
| T1559.001 Component Object Model |
MalwareFunnyDream | FunnyDream can use com objects identified with `CLSID_ShellLink`(`IShellLink` and `IPersistFile`) and `WScript.Shell`(`RegWrite` method) to enable persistence mechanisms. |
| T1559.001 Component Object Model |
MalwarePOWERSTATS | POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts. |
| T1559.001 Component Object Model |
MalwareGelsemium | Gelsemium can use the `IARPUinstallerStringLauncher` COM interface are part of its UAC bypass process. |
| T1559.001 Component Object Model |
MalwareHermeticWizard | HermeticWizard can execute files on remote machines using DCOM. |
| T1559.001 Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object. |
| T1559.002 Dynamic Data Exchange |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims. |
| T1559.002 Dynamic Data Exchange |
GroupPatchwork | Patchwork leveraged the DDE protocol to deliver their malware. |
| T1559.002 Dynamic Data Exchange |
GroupMuddyWater | MuddyWater has used malware that can execute PowerShell scripts via DDE. |
| T1559.002 Dynamic Data Exchange |
GroupGallmaker | Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution. |
| T1559.002 Dynamic Data Exchange |
GroupFIN7 | FIN7 spear phishing campaigns have included malicious Word documents with DDE execution. |
| T1559.002 Dynamic Data Exchange |
GroupSidewinder | Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer. |
| T1559.002 Dynamic Data Exchange |
GroupAPT37 | APT37 has used Windows DDE for execution of commands and a malicious VBS. |
| T1559.002 Dynamic Data Exchange |
GroupLeviathan | Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents. |
| T1559.002 Dynamic Data Exchange |
GroupTA505 | TA505 has leveraged malicious Word documents that abused DDE. |
| T1559.002 Dynamic Data Exchange |
GroupBITTER | BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads. |
| T1559.002 Dynamic Data Exchange |
GroupAPT28 | APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents. |
| T1559.002 Dynamic Data Exchange |
GroupCobalt Group | Cobalt Group has sent malicious Word OLE compound documents to victims. |
| T1559.002 Dynamic Data Exchange |
MalwareHAWKBALL | HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode. |
| T1559.002 Dynamic Data Exchange |
MalwareGravityRAT | GravityRAT has been delivered via Word documents using DDE for execution. |
| T1559.002 Dynamic Data Exchange |
MalwareKeyBoy | KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads. |
| T1559.002 Dynamic Data Exchange |
MalwareRTM | RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism. |
| T1559.002 Dynamic Data Exchange |
MalwareValak | Valak can execute tasks via OLE. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.