Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.002 Asymmetric Cryptography |
ToolTor | Tor encapsulates traffic in multiple layers of encryption, using TLS by default. |
| T1573.002 Asymmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`. |
| T1573.002 Asymmetric Cryptography |
GroupShinyHunters | ShinyHunters has established a connection between the staging host and the C2 using SSH. |
| T1574 Hijack Execution Flow |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched. |
| T1574 Hijack Execution Flow |
CampaignC0017 | During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries. |
| T1574 Hijack Execution Flow |
MalwareCOATHANGER | COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`. |
| T1574 Hijack Execution Flow |
MalwareRaspberry Robin | Raspberry Robin will drop a copy of itself to a subfolder in |
| T1574 Hijack Execution Flow |
MalwareNightdoor | Nightdoor uses a legitimate executable to load a malicious DLL file for installation. |
| T1574 Hijack Execution Flow |
MalwareShimRat | ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls. |
| T1574 Hijack Execution Flow |
MalwareDarkGate | DarkGate edits the Registry key |
| T1574 Hijack Execution Flow |
MalwareSaint Bot | Saint Bot will use the malicious file |
| T1574 Hijack Execution Flow |
MalwareSPAWNCHIMERA | SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process. |
| T1574 Hijack Execution Flow |
MalwareDenis | Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe. |
| T1574 Hijack Execution Flow |
MalwareDtrack | One of Dtrack can replace the normal flow of a program execution with malicious code. |
| T1574.001 DLL |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations. |
| T1574.001 DLL |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence. |
| T1574.001 DLL |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs. |
| T1574.001 DLL |
CampaignAPT41 DUST | APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. |
| T1574.001 DLL |
GroupSideCopy | SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`. |
| T1574.001 DLL |
GroupGALLIUM | GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine. |
| T1574.001 DLL |
GroupAPT3 | APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools. |
| T1574.001 DLL |
GroupPatchwork | A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading. |
| T1574.001 DLL |
GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| T1574.001 DLL |
GroupEvilnum | Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
| T1574.001 DLL |
GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
| T1574.001 DLL |
GroupMuddyWater | MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware. |
| T1574.001 DLL |
GroupNaikon | Naikon has used DLL side-loading to load malicious DLL's into legitimate executables. |
| T1574.001 DLL |
GroupStorm-1811 | Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload. |
| T1574.001 DLL |
GroupSidewinder | Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
GroupHigaisa | Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the |
| T1574.001 DLL |
GroupTropic Trooper | Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools. |
| T1574.001 DLL |
GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| T1574.001 DLL |
GroupBlackTech | BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories. |
| T1574.001 DLL |
GroupCinnamon Tempest | Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs. |
| T1574.001 DLL |
GroupChimera | Chimera has used side loading to place malicious DLLs in memory. |
| T1574.001 DLL |
GroupMirrorFace | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading. |
| T1574.001 DLL |
GroupBRONZE BUTLER | BRONZE BUTLER has used legitimate applications to side-load malicious DLLs. |
| T1574.001 DLL |
GroupBackdoorDiplomacy | BackdoorDiplomacy has executed DLL search order hijacking. |
| T1574.001 DLL |
GroupWhitefly | Whitefly has used search order hijacking to run the loader Vcrodat. |
| T1574.001 DLL |
GroupLuminousMoth | LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware. |
| T1574.001 DLL |
GroupRTM | RTM has used search order hijacking to force TeamViewer to load a malicious DLL. |
| T1574.001 DLL |
GroupAPT-C-36 | APT-C-36 has used side-loading to execute the HijackLoader payload. |
| T1574.001 DLL |
GroupTonto Team | Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL. |
| T1574.001 DLL |
GroupLazarus Group | Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`. |
| T1574.001 DLL |
GroupEarth Lusca | Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service. |
| T1574.001 DLL |
GroupVelvet Ant | Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX. |
| T1574.001 DLL |
GroupDaggerfly | Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
| T1574.001 DLL |
GroupWIRTE | WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.