ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1055
Process Injection
MalwaremetaMain

metaMain can inject the loader file, Speech02.db, into a process.

T1055
Process Injection
MalwareMis-Type

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1055
Process Injection
MalwareAgent Tesla

Agent Tesla can inject into known, vulnerable binaries on targeted hosts.

T1055
Process Injection
MalwareShadowPad

ShadowPad has injected an install module into a newly created process.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1055
Process Injection
MalwareDOWNIISSA

DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe.

T1055
Process Injection
MalwareBBK

BBK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareWaterbear

Waterbear can inject decrypted shellcode into the LanmanServer service.

T1055
Process Injection
MalwareLizar

Lizar can migrate the loader into another process.

T1055
Process Injection
MalwareWarzoneRAT

WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation.

T1055
Process Injection
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can inject into running processes on a compromised host.

T1055
Process Injection
ToolSliver

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1055
Process Injection
ToolSILENTTRINITY

SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process.

T1055
Process Injection
ToolEmpire

Empire contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolPcShare

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1055
Process Injection
ToolPoshC2

PoshC2 contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolRemcos

Remcos has a command to hide itself by injecting into another process.

T1055
Process Injection
ToolDonut

Donut includes a subproject DonutTest to inject shellcode into a target process.

T1055
Process Injection
ToolIronNetInjector

IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process.

T1055
Process Injection
ToolHTRAN

HTRAN can inject into into running processes.

T1055.001
Dynamic-link Library Injection
MalwareBumblebee

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.001
Dynamic-link Library Injection
MalwareStuxnet

Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.

T1055.001
Dynamic-link Library Injection
MalwareGet2

Get2 has the ability to inject DLLs into processes.

T1055.001
Dynamic-link Library Injection
MalwareEmissary

Emissary injects its DLL file into a newly spawned Internet Explorer process.

T1055.001
Dynamic-link Library Injection
MalwarePS1

PS1 can inject its payload DLL Into memory.

T1055.001
Dynamic-link Library Injection
MalwareHavoc

Havoc has DLL spawn and injection modules.

T1055.001
Dynamic-link Library Injection
MalwareMatryoshka

Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT.

T1055.001
Dynamic-link Library Injection
MalwareTONESHELL

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1055.001
Dynamic-link Library Injection
MalwareAria-body

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1055.001
Dynamic-link Library Injection
MalwareEmotet

Emotet has been observed injecting in to Explorer.exe and other processes.

T1055.001
Dynamic-link Library Injection
MalwareBADHATCH

BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine.

T1055.001
Dynamic-link Library Injection
MalwareSombRAT

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1055.001
Dynamic-link Library Injection
MalwareConti

Conti has loaded an encrypted DLL into memory and then executes it.

T1055.001
Dynamic-link Library Injection
MalwareKazuar

If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes.

T1055.001
Dynamic-link Library Injection
MalwareBlackEnergy

BlackEnergy injects its DLL component into svchost.exe.

T1055.001
Dynamic-link Library Injection
MalwareDarkTortilla

DarkTortilla can use a .NET-based DLL named `RunPe6` for process injection.

T1055.001
Dynamic-link Library Injection
MalwareDyre

Dyre injects into other processes to load modules.

T1055.001
Dynamic-link Library Injection
MalwareRemsec

Remsec can perform DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareSykipot

Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe.

T1055.001
Dynamic-link Library Injection
MalwareMongall

Mongall can inject a DLL into `rundll32.exe` for execution.

T1055.001
Dynamic-link Library Injection
MalwareNetwalker

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1055.001
Dynamic-link Library Injection
MalwareSaint Bot

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.001
Dynamic-link Library Injection
MalwareSagerunex

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1055.001
Dynamic-link Library Injection
MalwareUroburos

Uroburos can use DLL injection to load embedded files and modules.

T1055.001
Dynamic-link Library Injection
MalwareMetamorfo

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1055.001
Dynamic-link Library Injection
MalwarePipeMon

PipeMon can inject its modules into various processes using reflective DLL loading.

T1055.001
Dynamic-link Library Injection
MalwareRARSTONE

After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system.

T1055.001
Dynamic-link Library Injection
MalwareMegaCortex

MegaCortex loads injecthelper.dll into a newly created rundll32.exe process.

T1055.001
Dynamic-link Library Injection
MalwareSDBbot

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.