1200KM / simulation
T1620 Reflective Code Loading — Attack Simulation
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex:…
Technique description
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex:…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Reflective PE Injection via PowerSploit
Procedure 114c2b95-d992-4c03-8c38-fc58420a3eb5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Reflectively load Mimik@tz into memory
Procedure 56b9589c-9170-4682-8c3d-33b86ecb5119; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Turla Mosquito (CommanderDLL.dll) Dynamic Export Address Table (EAT) Patching
Procedure 7c3e0b89-09e6-4f3c-a1e8-1c1dfa9288ce; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.