ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1129×

21 examples

TechniqueUsed byProcedure example
T1129
Shared Modules
MalwareBLINDINGCAN

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

T1129
Shared Modules
MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

T1129
Shared Modules
MalwareStuxnet

Stuxnet calls LoadLibrary then executes exports from a DLL.

T1129
Shared Modules
MalwareRotaJakiro

RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`.

T1129
Shared Modules
MalwareVersaMem

VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory.

T1129
Shared Modules
MalwareBOOSTWRITE

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

T1129
Shared Modules
MalwareLightSpy

LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class.

T1129
Shared Modules
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1129
Shared Modules
MalwareDarkWatchman

DarkWatchman can load DLLs.

T1129
Shared Modules
MalwareFoggyWeb

FoggyWeb's loader can call the load() function to load the FoggyWeb dll into an Application Domain on a compromised AD FS server.

T1129
Shared Modules
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can load and call DLL functions.

T1129
Shared Modules
MalwareMetamorfo

Metamorfo had used AutoIt to load and execute the DLL payload.

T1129
Shared Modules
MalwarePipeMon

PipeMon has used call to LoadLibrary to load its installer. PipeMon loads its modules using reflective loading or custom shellcode.

T1129
Shared Modules
Malwaregh0st RAT

gh0st RAT can load DLLs into memory.

T1129
Shared Modules
MalwareAttor

Attor's dispatcher can execute additional plugins by loading the respective DLLs.

T1129
Shared Modules
MalwareOSX_OCEANLOTUS.D

For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`.

T1129
Shared Modules
MalwareTajMahal

TajMahal has the ability to inject the LoadLibrary call template DLL into running processes.

T1129
Shared Modules
MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1129
Shared Modules
MalwareKillDisk

KillDisk loads and executes functions from a DLL.

T1129
Shared Modules
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

T1129
Shared Modules
MalwareDtrack

Dtrack contains a function that calls LoadLibrary and GetProcAddress.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.