FORENSIA

ATT&CK · T1106

Native API

Tactics: execution

About

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors. Similar to Command and Scripting Interpreter, the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system. Native API functions (such as <code>NtCreateProcess</code>) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries. For example, functions such as the Windows API <code>CreateProcess()</code> or GNU <code>fork()</code> will allow programs and scripts to start other processes. This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations. Higher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code. Adversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks. Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via Disable or Modify Tools.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

20 known groups

Software

203 malware/tools implement this

TaidoorPlugXUroburosgh0st RATADVSTORESHELLMisdatMis-TypeS-TypeComRATBADNEWSWinnti for WindowsPteranodonRTMCobalt StrikeXAgentOSXVolgmerNETWIREBandookBankshotROKRATSynAckMosquitoInnaputRATInvisiMoleTrickBotBisonalDenisKONNIEmpireEmotetDridexnjRATUrsnifHAWKBALLLightNeuronEvilBunnyHyperBroZxShellRDFSNIFFERHotCroissantImminent MonitorPLEADAttorShimRatShimRatReporterRyukLokibotRising SunMazePonyMetamorfoAria-bodyNetwalkerRamsayWindTailBBKbuild_downerBackConfigGoopyIcedIDCarberpGoldenSpyREvilHancitorPipeMonFatDukePillowmintPolyglotDukeBloodHoundGrandoreiroBazarHyperStackEgregorGuLoaderSUNSPOTExplosiveBitPaymerBendyBearContiMegaCortexWaterbearThiefQuestStuxnetBad RabbitKillDiskSideTwistClopWastedLockerCostaBricksSombRATAppleSeedSiloscapeCubaSodaMasterRainyDayNebulaeChaesGrimAgentBabukAvaddonQakBotBoxCaonMarkiRATxCaonDiavolFoggyWebRCSessionSysUpdateGelsemiumChrommmeTinyTurlaKOCTOPUSWarzoneRATTorismaLitePowerLizarCyclops BlinkMeteorWhisperGateSILENTTRINITYCaddyWiperDRATzarusDonutFlagproHermeticWiperHermeticWizardZxxZMilanMacMaSaint BotKevinAmadeyDCSrvStrifeWaterBumblebeeFunnyDreamPcShareDEADEYEAvosLockerPrestigemetaMainMafaldaBrute Ratel C4SVCReadyWoody RATDarkTortillaBlack BastaRoyalQUIETCANARYRotaJakiroBADHATCHSardonicAsyncRATSharpDiscoNightClubSamuraiNinjaDarkGateMispaduAkiraINC RansomwarePikabotCHIMNEYSWEEPZeroCleareIMAPLoaderLatrodectusMangoODAgentOilBoosterExbyteBlackByte RansomwareKapekaStealBitLockBit 3.0XLoaderSagerunexBOOKWORMStarProxyPUBLOADHavocSplatDropperPAKLOGSplatCloakCLAIMLOADERCANONSTAGERTONESHELLQilinMedusa RansomwareEmbargoSystemBCHTTPTroyTRAILBLAZECaminhoHeartCryptLODEINFODOWNIISSANOOPLDRANELLDRMuddyViperFooderLP-NotesRustyWaterDynoWiper

Corpus indicators tagged with this technique

909 indicators in the corpus carry T1106.

IndicatorTypeFamilySevSrc
cve-2016-15047cve854
cve-2025-34054cve854
cve-2026-3102cve853
cve-2021-27076cve851
cve-2021-27137cve858
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
a7bd8869293212e1671df90d2d41b96d4933eb9408b1111bd830e111a91bb202hashphishing802
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
bd46890121106b43f0c01ab82629400chashcryptojacking802
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4hashphishing802
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802

Showing the top 30 by severity of 909.