MITRE ATT&CK Technique
T1055Process Injection
- First Reported
- Aug 26, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific.
More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.
There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific.
More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.
- Tactics
- Stealth, Privilege Escalation
- Platforms
- Linux, macOS, Windows
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Sub-techniques (12)
T1055.001 · Dynamic-link Library InjectionT1055.002 · Portable Executable InjectionT1055.003 · Thread Execution HijackingT1055.004 · Asynchronous Procedure CallT1055.005 · Thread Local StorageT1055.008 · Ptrace System CallsT1055.009 · Proc MemoryT1055.011 · Extra Window Memory InjectionT1055.012 · Process HollowingT1055.013 · Process Doppelgänging
Reported Context (5)
- Cited open-source reporting says Remus obtains browser data through browser-process injection. CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
- The movinlike bundle injects into Discord clients. MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
- The payload injects decrypted Remcos RAT into MicrosoftEdgeUpdate.Exe for execution. Phishing Quote Requests Deliver Remcos RAT via Obfuscated PowerShell
- Kothamine Injector injected the agent DLL into a running process, typically explorer.exe, using remote-process memory and thread APIs. Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control
- Decrypted stages were injected into vssvc.exe, ctfmon.exe, and svchost.exe. Cambodia-Focused Malware Campaign Uses Multi-Stage Infection Chain and SparkRAT
CVE (1)
Malware (9)
Threat Actors (5)
MITRE ATT&CK (32)
Vendors (9)
Products (24)
Tools (7)
Industries (1)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.