T1055 Process Injection in real malware
ATT&CK technique T1055 Process Injection appears in 583 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.5% of the analyzed corpus. Seven-day prevalence is flat (1 recent vs 1 prior). Most associated families: HUILoader, Delf, Azov, Viking, Emotet.
Tactics: stealth, privilege-escalation
Prevalence in the corpus
- Samples exhibiting T1055: 583
- Share of analyzed corpus: 0.5%
- Last 7 days: 1 · prior 7 days: 1 (flat)
Malware families using T1055
Example samples
- ADInsight64.exe - malicious
- mimikaz.exe - malicious
- 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6.exe - malicious
- c5c7032ed404dec1f9970a019167220ff011b4ce117e7e775262278ba900e195 - malicious
- 86e038d9fb1bb8e60915593a3f0ebb053408825037bf13767856d1c5a21f9d42 - malicious
- 46cfeb049ec1b54df89c49003c2b772750bbcd89e6ebb235bf1861771a6613a3 - malicious
- bae6157ecc8725f45770344bd174e6eef095660d3b89e042130bb154909e95ad - malicious
- 48724945d19df93be99ee36fa558472f08bd346fb1afd5ce8ace0ab8407f9c04 - malicious
- 81183faa59218eab4d03ea4b73c00773d78885075ae12afae7f25f4aeccc7eb8 - malicious
- c261d38419991cfdbd46ef65acfa3668340b9cfa31e82d2137c3d355a0d5a50b - malicious
- 5ad664ee2b91614eedc60ab3386b3bc70c87f26f94250f1ad2394c22ec28a04c - malicious
- e06abdc0104845361a19f0ab2019f70bfe792a11d94c70810c62591ac29f3a07 - malicious
- 9c935537a96baeeedbba8e32189e0aa8116e0fbf6ed2f0eb8e20b68e9a56d22e - malicious
- f4dc4093baa6cdb4659d46b901f762245809992bc700ac57a9035c1618306909 - malicious
- 4747225404488963ae617a0c01d2917d8322977ba87695263634f6cf474b38f2 - malicious
- fa8eda9fd609bf23a2b895146f33405c03bebd6a715726355bf696fb79dd3a6b - malicious
- 76e11752c8d9e5ed2cf30b7ba5fef5a209afa78608b2cc39e969874d86c0c708 - malicious
- 289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe - malicious
- f404ff2a028f0df8c970f4b090013749a7f36eda010f946dd30946da94dc0b0e - malicious
- virussign.com_93b192eb81fa44a518bb0709bfd36ad0.vir - malicious
- virussign.com_436271535f272acd7391058fbcb2ebc0.vir - malicious
- virussign.com_303d06ebda1c6fd4997d0f2c248fe2e0.vir - malicious
- ddc37b7ee958ed291e9bbe63ce53cf275d3e8b783db017cbcc30d3e92f3122f0 - malicious
- 8d80a1f9eb5069e0f024d93fad575b483d0094e704ad447f19692da0f4332dec - malicious
- f384ae4d2842443ba72a4e8f5f34ad97c71a28bba4f70abc88af3e5fc235f66b - malicious
Canonical technique definition: MITRE ATT&CK T1055 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1055
- How common is ATT&CK T1055 (Process Injection) in real malware?
- ATT&CK technique T1055 Process Injection appears in 583 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.5% of the analyzed corpus. Seven-day prevalence is flat (1 recent vs 1 prior). Most associated families: HUILoader, Delf, Azov, Viking, Emotet.
- Is T1055 becoming more common?
- Prevalence is flat: 1 sample in the last seven days against 1 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1055?
- In this corpus T1055 is most associated with HUILoader (58), Delf (53), Azov (49), Viking (34), Emotet (24). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1055?
- 0.5% of the publicly analyzed corpus (583 of 114610 samples) exhibits T1055. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats