Mavinject

T1218.013

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application Virtualization Injector, a Windows utility that can inject code into external processes as part of Microsoft Application Virtualization (App-V).

Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL). Since mavinject.exe may be digitally signed by Microsoft, proxying execution via this method may evade detection by security products because the execution is masked under a legitimate process.

In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address.

Detection rules3

Rules on DetectionCode tagged with T1218.013.

Sigma2

RuleLevelLog source
Mavinject Inject DLL Into Running Processhighwindows / process_creation
Renamed Mavinject.EXE Executionhighwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows Binary Proxy Execution Mavinject DLL InjectionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareTONESHELL

TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`.

References4

  1. ATT Lazarus TTP Evolution Open source
    Fernando Martinez. (2021, July 6). Lazarus campaign TTPs and evolution. Retrieved September 22, 2021.
  2. LOLBAS Mavinject Open source
    LOLBAS. (n.d.). Mavinject.exe. Retrieved September 22, 2021.
  3. Mavinject Functionality Deconstructed Open source
    Matt Graeber. (2018, May 29). mavinject.exe Functionality Deconstructed. Retrieved September 22, 2021.
  4. Reaqta Mavinject Open source
    Reaqta. (2017, December 16). From False Positive to True Positive: the story of Mavinject.exe, the Microsoft Injector. Retrieved September 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.