Asynchronous Procedure Call

T1055.004

Sub-technique of T1055 Process Injection.View on attack.mitre.org

About this technique

Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process.

APC injection is commonly performed by attaching malicious code to the APC Queue of a process's thread. Queued APC functions are executed when the thread enters an alterable state. A handle to an existing victim process is first created with native Windows API calls such as OpenThread. At this point QueueUserAPC can be used to invoke a function (such as LoadLibrayA pointing to a malicious DLL).

A variation of APC injection, dubbed "Early Bird injection", involves creating a suspended process in which malicious code can be written and executed before the process' entry point (and potentially subsequent anti-malware hooks) via an APC. AtomBombing is another variation that utilizes APCs to invoke malicious code previously written to the global atom table.

Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via APC injection may also evade detection from security products since the execution is masked under a legitimate process.

Detection rules1

Rules on DetectionCode tagged with T1055.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
PowerShell PInvoke Process Injection API ChainTTPNULLPowershell Script Block Logging 4104

Groups1

Software12

Campaigns0

None recorded.

Procedure examples13

Groups1

Used byProcedure example
GroupFIN8

FIN8 has injected malicious code into a new svchost.exe process.

Software12

Used byProcedure example
MalwareAttor

Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API.

MalwareBADHATCH

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

MalwareBumblebee

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

MalwareCarberp

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.

MalwareHeartCrypt

HeartCrypt has the ability to use `NtQueueApcThread` as an alternate method for process injection.

MalwareIcedID

IcedID has used ZwQueueApcThread to inject itself into remote processes.

MalwareInvisiMole

InvisiMole can inject its code into a trusted process via the APC queue.

MalwarePillowmint

Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe.

View all 12 software examples

References4

  1. CyberBit Early Bird Apr 2018 Open source
    Gavriel, H. & Erbesfeld, B. (2018, April 11). New ‘Early Bird’ Code Injection Technique Discovered. Retrieved May 24, 2018.
  2. ENSIL AtomBombing Oct 2016 Open source
    Liberman, T. (2016, October 27). ATOMBOMBING: BRAND NEW CODE INJECTION FOR WINDOWS. Retrieved December 8, 2017.
  3. Microsoft APC Open source
    Microsoft. (n.d.). Asynchronous Procedure Calls. Retrieved December 8, 2017.
  4. Microsoft Atom Table Open source
    Microsoft. (n.d.). About Atom Tables. Retrieved December 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.