FORENSIA

ATT&CK · T1055.013 · sub-technique

Process Doppelgänging

Tactics: stealth, privilege-escalation

About

Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges. Process doppelgänging is a method of executing arbitrary code in the address space of a separate live process. Windows Transactional NTFS (TxF) was introduced in Vista as a method to perform safe file operations. To ensure data integrity, TxF enables only one transacted handle to write to a file at a given time. Until the write handle transaction is terminated, all other handles are isolated from the writer and may only read the committed version of the file that existed at the time the handle was opened. To avoid corruption, TxF performs an automatic rollback if the system or application fails during a write transaction. Although deprecated, the TxF application programming interface (API) is still enabled as of Windows 10. Adversaries may abuse TxF to a perform a file-less variation of Process Injection. Similar to Process Hollowing, process doppelgänging involves replacing the memory of a legitimate process, enabling the veiled execution of malicious code that may evade defenses and detection. Process doppelgänging's use of TxF also avoids the use of highly-monitored API functions such as <code>NtUnmapViewOfSection</code>, <code>VirtualProtectEx</code>, and <code>SetThreadContext</code>. Process Doppelgänging is implemented in 4 steps: * Transact – Create a TxF transaction using a legitimate executable then overwrite the file with malicious code. These changes will be isolated and only visible within the context of the transaction. * Load – Create a shared section of memory and load the malicious executable. * Rollback – Undo changes to original executable, effectively removing malicious code from the file system. * Animate – Create a process from the tainted section of memory and initiate execution. This behavior will likely not result in elevated privileges since the injected process was spawned from (and thus inherits the security context) of the injecting process. However, execution via process doppelgänging may evade detection from security products since the execution is masked under a legitimate process.

Platforms: WindowsParent: T1055 Process InjectionMITRE ATT&CK ↗

Used by actors

1 known groups

Software

2 malware/tools implement this

SynAckBazar

Corpus indicators tagged with this technique

76 indicators in the corpus carry T1055.013.

IndicatorTypeFamilySevSrc
09bedbf7a41e0f8dabe4f41d331db58373ce15b2e9204540873a1884f38bdde1sha256802
17aae57cf6255c7eb169bf62ea67376d9708976eb7831f8cdd0ea38bdcb37dc4sha256802
7887e919555fb5948c217556ba149392a72982b1bc427d3db779db9dcbf09ee8sha256801
c5b1e9aafc8f2b4ab05effc00fd43f3114b9ef1d592a086c952793ac4e299809sha256801
59ad96dd3b4d5f10a5c53bbd465446e52dc7701a4ac633632f762bf1336d3347sha256802
6dbd6f9f2fa636c16ac4fa81418b68a604424861b9650dd9c4f2b0ba6f67d6acsha256801
c46e907886e2158cbc453e767183aecf07887b5ac8848f19684451883d69f5f0sha256801
c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926csha256801
66dbe675480dc229e5b3ab8ad74207f73486e64e57805074f784bb2e01bcb865sha256801
a6fb779be35592fb0ff624a8f8e12ab3cafe7bcfc312cd98263814db7fb01e02sha256801
3c181f642e24c28602a87be7f195e2f3d1ffa30b37e20f5121d99f88b22ab80esha256802
2fdfdd13a0c548bb68c9d5aa8599a9265d4659da3e237fe7a42ac6ac06b9a06asha256802
bc61ef6d7ad9ee878028f24d50e9dcf6d7d88bf2sha1782
080fdb73a6bbc99625c2190730257d1e54723952sha1782
2aa47fb23074e8ae776a369f9e28d1a2f6e70739sha1782
63bfd6567f4c704e8ed6530f5cdd704emd5762
26b2da88cb95b98b46bb985f67f76154md5762
4f1773a1228e2c009cbcf61e9e550e01md5762
http://jsiruytrawey.gu.ccurl751
http://kawosyetw.gu.ccurl751
https://almacensantangel.com/wp-includes/assets/yourssa_documents_0000000676152_05_187_2026_document_0000000676152.rarurl752
http://hsahyteiows.gu.ccurl751
http://jaiydteds.loveurl751
http://kawuuterta.gu.ccurl751
http://fiusyevr.liveurl751
http://faeytrdeaw.gu.ccurl751
http://figyuyrqwr.gu.ccurl751
http://fuaytrwese.loveurl751
http://hfyuayustrv.gu.ccurl751
http://laiwutrencr.gu.ccurl751

Showing the top 30 by severity of 76.