ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1573.002
Asymmetric Cryptography
ToolTor

Tor encapsulates traffic in multiple layers of encryption, using TLS by default.

T1573.002
Asymmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`.

T1573.002
Asymmetric Cryptography
GroupShinyHunters

ShinyHunters has established a connection between the staging host and the C2 using SSH.

T1574
Hijack Execution Flow
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched.

T1574
Hijack Execution Flow
CampaignC0017

During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries.

T1574
Hijack Execution Flow
MalwareCOATHANGER

COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`.

T1574
Hijack Execution Flow
MalwareRaspberry Robin

Raspberry Robin will drop a copy of itself to a subfolder in %Program Data% or %Program Data%\\Microsoft\\ to attempt privilege elevation and defense evasion if not running in Session 0.

T1574
Hijack Execution Flow
MalwareNightdoor

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

T1574
Hijack Execution Flow
MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

T1574
Hijack Execution Flow
MalwareDarkGate

DarkGate edits the Registry key HKCU\Software\Classes\mscfile\shell\open\command to execute a malicious AutoIt script. When eventvwr.exe is executed, this will call the Microsoft Management Console (mmc.exe), which in turn references the modified Registry key.

T1574
Hijack Execution Flow
MalwareSaint Bot

Saint Bot will use the malicious file slideshow.mp4 if present to load the core API provided by ntdll.dll to avoid any hooks placed on calls to the original ntdll.dll file by endpoint detection and response or antimalware software.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1574
Hijack Execution Flow
MalwareDenis

Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe.

T1574
Hijack Execution Flow
MalwareDtrack

One of Dtrack can replace the normal flow of a program execution with malicious code.

T1574.001
DLL
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations.

T1574.001
DLL
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence.

T1574.001
DLL
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs.

T1574.001
DLL
CampaignAPT41 DUST

APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller.

T1574.001
DLL
GroupSideCopy

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1574.001
DLL
GroupGALLIUM

GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.

T1574.001
DLL
GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

T1574.001
DLL
GroupPatchwork

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1574.001
DLL
GroupEvilnum

Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

T1574.001
DLL
GroupMuddyWater

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.

T1574.001
DLL
GroupNaikon

Naikon has used DLL side-loading to load malicious DLL's into legitimate executables.

T1574.001
DLL
GroupStorm-1811

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.

T1574.001
DLL
GroupSidewinder

Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
GroupHigaisa

Higaisa’s JavaScript file used a legitimate Microsoft Office 2007 package to side-load the OINFO12.OCX dynamic link library.

T1574.001
DLL
GroupTropic Trooper

Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1574.001
DLL
GroupBlackTech

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

T1574.001
DLL
GroupCinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.

T1574.001
DLL
GroupChimera

Chimera has used side loading to place malicious DLLs in memory.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1574.001
DLL
GroupBRONZE BUTLER

BRONZE BUTLER has used legitimate applications to side-load malicious DLLs.

T1574.001
DLL
GroupBackdoorDiplomacy

BackdoorDiplomacy has executed DLL search order hijacking.

T1574.001
DLL
GroupWhitefly

Whitefly has used search order hijacking to run the loader Vcrodat.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1574.001
DLL
GroupRTM

RTM has used search order hijacking to force TeamViewer to load a malicious DLL.

T1574.001
DLL
GroupAPT-C-36

APT-C-36 has used side-loading to execute the HijackLoader payload.

T1574.001
DLL
GroupTonto Team

Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL.

T1574.001
DLL
GroupLazarus Group

Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`.

T1574.001
DLL
GroupEarth Lusca

Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service.

T1574.001
DLL
GroupVelvet Ant

Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

T1574.001
DLL
GroupWIRTE

WIRTE has used RAR archives containing a legitimate executable and a lure document to execute malicious DLLs via sideloading.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.