TACTIC: DEFENSE EVASION

Process Hollowing (T1055.012): real cases

MITRE Definition ↗
Adversaries hollow out legitimate executables in memory and overwrite them with malicious payloads.

Key Facts

Technique ID
T1055.012
Defense Evasion
Mapped Cases
1
Primary sources
Related Laws
4
Criminal statutes
  • ATT&CK Technique Identifier: T1055.012.
  • Tactical Phase: Defense Evasion.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 52, Page 27
"Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity."
U.S. District Court for the Western District of Pennsylvania View full case dossier →

Commonly Charged Criminal Statutes

18 U.S.C. § 1030(a)(2)

Unauthorized Access to Obtain Protected Information

Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.

18 U.S.C. § 1030(a)(5)(A)

Intentional Damage to a Protected Computer

Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.

18 U.S.C. § 1030(a)(7)

Extortion in Connection with Computers

Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.

18 U.S.C. § 1030(b)

Conspiracy to Commit Computer Fraud

Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.