Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.001 DLL |
MalwarePandora | Pandora can use DLL side-loading to execute malicious payloads. |
| T1574.001 DLL |
MalwareFinFisher | FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking. |
| T1574.001 DLL |
MalwareWingbird | Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service. |
| T1574.001 DLL |
MalwareRamsay | Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload. |
| T1574.001 DLL |
MalwareAshTag | AshTag has enabled execution via DLL sideloading using a legitimate executable paired with a malicious DLL named wtsapi32. |
| T1574.001 DLL |
MalwareSysUpdate | SysUpdate can load DLLs through vulnerable legitimate executables. |
| T1574.001 DLL |
MalwarePowGoop | PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`. |
| T1574.001 DLL |
MalwareANELLDR | ANELLDR can use DLL sideloading from a legitimate application to initiate execution. |
| T1574.001 DLL |
MalwareLookBack | LookBack side loads its communications module as a DLL into the |
| T1574.001 DLL |
MalwareEgregor | Egregor has used DLL side-loading to execute its payload. |
| T1574.001 DLL |
MalwareMelcoz | Melcoz can use DLL hijacking to bypass security controls. |
| T1574.001 DLL |
MalwareHIUPAN | HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe. |
| T1574.001 DLL |
MalwaremetaMain | metaMain can support an HKCMD sideloading start method. |
| T1574.001 DLL |
MalwareHTTPBrowser | HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
| T1574.001 DLL |
MalwareMirageFox | MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary. |
| T1574.001 DLL |
MalwarePcexter | Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading. |
| T1574.001 DLL |
MalwareStarProxy | StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe. |
| T1574.001 DLL |
MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
| T1574.001 DLL |
MalwareGoopy | Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google. |
| T1574.001 DLL |
MalwareAstaroth | Astaroth can launch itself via DLL Search Order Hijacking. |
| T1574.001 DLL |
MalwareQakBot | QakBot has the ability to use DLL side-loading for execution. |
| T1574.001 DLL |
MalwareDridex | Dridex can abuse legitimate Windows executables to side-load malicious DLL files. |
| T1574.001 DLL |
MalwareDenis | Denis exploits a security vulnerability to load a fake DLL and execute its code. |
| T1574.001 DLL |
MalwareWaterbear | Waterbear has used DLL side loading to import and load a malicious DLL loader. |
| T1574.001 DLL |
MalwareUPPERCUT | UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation. |
| T1574.001 DLL |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes. |
| T1574.001 DLL |
ToolEmpire | Empire contains modules that can discover and exploit various DLL hijacking opportunities. |
| T1574.001 DLL |
ToolBrute Ratel C4 | Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe. |
| T1574.004 Dylib Hijacking |
ToolEmpire | Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application. |
| T1574.005 Executable Installer File Permissions Weakness |
GroupMustang Panda | Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload. |
| T1574.006 Dynamic Linker Hijacking |
GroupAPT41 | APT41 has configured payloads to load via LD_PRELOAD. |
| T1574.006 Dynamic Linker Hijacking |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1574.006 Dynamic Linker Hijacking |
GroupAquatic Panda | Aquatic Panda modified the |
| T1574.006 Dynamic Linker Hijacking |
MalwareMEDUSA | MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library. |
| T1574.006 Dynamic Linker Hijacking |
MalwareCOATHANGER | COATHANGER copies the malicious file |
| T1574.006 Dynamic Linker Hijacking |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to intercept shared library import functions. |
| T1574.006 Dynamic Linker Hijacking |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection. |
| T1574.006 Dynamic Linker Hijacking |
MalwareEbury | When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`. |
| T1574.006 Dynamic Linker Hijacking |
MalwareXCSSET | XCSSET adds malicious file paths to the |
| T1574.006 Dynamic Linker Hijacking |
MalwareHiddenWasp | HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable. |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareBRICKSTORM | BRICKSTORM has checked hard-coded paths of `/etc/sysconfig/` or `/etc/sysconfig/network` prior to execution and loading file contents from that path. |
| T1574.007 Path Interception by PATH Environment Variable |
MalwareDarkGate | DarkGate overrides the |
| T1574.007 Path Interception by PATH Environment Variable |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.007 Path Interception by PATH Environment Variable |
ToolEmpire | Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolEmpire | Empire contains modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolEmpire | Empire contains modules that can discover and exploit unquoted path vulnerabilities. |
| T1574.010 Services File Permissions Weakness |
MalwareBlackEnergy | One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence. |
| T1574.011 Services Registry Permissions Weakness |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.