ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055×

15 examples

TechniqueUsed byProcedure example
T1055
Process Injection
GroupAPT38

APT38 has injected malicious payloads into the `explorer.exe` process.

T1055
Process Injection
GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1055
Process Injection
GroupKimsuky

Kimsuky has used Win7Elevate to inject malicious code into explorer.exe.

T1055
Process Injection
GroupAPT41

APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.

T1055
Process Injection
GroupAPT32

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

T1055
Process Injection
GroupGamaredon Group

Gamaredon Group has injected Remcos into explorer.exe.

T1055
Process Injection
GroupTA2541

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1055
Process Injection
GroupAPT37

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

T1055
Process Injection
GroupTurla

Turla has also used PowerSploit's Invoke-ReflectivePEInjection.ps1 to reflectively load a PowerShell payload into a random process on the victim system.

T1055
Process Injection
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

T1055
Process Injection
GroupSilence

Silence has injected a DLL library containing a Trojan into the fwmain32.exe process.

T1055
Process Injection
GroupCobalt Group

Cobalt Group has injected code into trusted processes.

T1055
Process Injection
GroupWizard Spider

Wizard Spider has used process injection to execute payloads to escalate privileges.

T1055
Process Injection
GroupVelvet Ant

Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them.

T1055
Process Injection
GroupPLATINUM

PLATINUM has used various methods of process injection including hot patching.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.