Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1055 Process Injection |
GroupKimsuky | Kimsuky has used Win7Elevate to inject malicious code into explorer.exe. |
| T1055 Process Injection |
GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| T1055 Process Injection |
GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| T1055 Process Injection |
GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
| T1055 Process Injection |
GroupTA2541 | TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe. |
| T1055 Process Injection |
GroupAPT37 | APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| T1055 Process Injection |
GroupTurla | Turla has also used PowerSploit's |
| T1055 Process Injection |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality. |
| T1055 Process Injection |
GroupSilence | Silence has injected a DLL library containing a Trojan into the fwmain32.exe process. |
| T1055 Process Injection |
GroupCobalt Group | Cobalt Group has injected code into trusted processes. |
| T1055 Process Injection |
GroupWizard Spider | Wizard Spider has used process injection to execute payloads to escalate privileges. |
| T1055 Process Injection |
GroupVelvet Ant | Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them. |
| T1055 Process Injection |
GroupPLATINUM | PLATINUM has used various methods of process injection including hot patching. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.