Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupBlackByte | BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure. |
| T1071.001 Web Protocols |
GroupKimsuky | Kimsuky has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
GroupAPT41 | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits. |
| T1071.001 Web Protocols |
GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| T1071.001 Web Protocols |
GroupHAFNIUM | HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1071.001 Web Protocols |
GroupMuddyWater | MuddyWater has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupRedEcho | RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1071.001 Web Protocols |
GroupSandworm Team | Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP. |
| T1071.001 Web Protocols |
GroupAPT18 | APT18 uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupSidewinder | Sidewinder has used HTTP in C2 communications. |
| T1071.001 Web Protocols |
GroupMustang Panda | Mustang Panda has communicated with its C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
GroupRocke | Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1071.001 Web Protocols |
GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1071.001 Web Protocols |
GroupTropic Trooper | Tropic Trooper has used HTTP in communication with the C2. |
| T1071.001 Web Protocols |
GroupOrangeworm | Orangeworm has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupSea Turtle | Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.001 Web Protocols |
GroupConfucius | Confucius has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWinter Vivern | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1071.001 Web Protocols |
GroupSilverTerrier | SilverTerrier uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTA505 | TA505 has used HTTP to communicate with C2 nodes. |
| T1071.001 Web Protocols |
GroupBITTER | BITTER has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
GroupRedCurl | RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications. |
| T1071.001 Web Protocols |
GroupStealth Falcon | Stealth Falcon malware communicates with its C2 server via HTTPS. |
| T1071.001 Web Protocols |
GroupDark Caracal | Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”. |
| T1071.001 Web Protocols |
GroupChimera | Chimera has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupMedusa Group | Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS). |
| T1071.001 Web Protocols |
GroupBRONZE BUTLER | BRONZE BUTLER malware has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupTA551 | TA551 has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWindshift | Windshift has used tools that communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
GroupLuminousMoth | LuminousMoth has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.001 Web Protocols |
GroupMetador | Metador has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupFIN4 | FIN4 has used HTTP POST requests to transmit data. |
| T1071.001 Web Protocols |
GroupCobalt Group | Cobalt Group has used HTTPS for C2. |
| T1071.001 Web Protocols |
GroupWizard Spider | Wizard Spider has used HTTP for network communications. |
| T1071.001 Web Protocols |
GroupMoonstone Sleet | Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1071.001 Web Protocols |
GroupInception | Inception has used HTTP, HTTPS, and WebDav in network communications. |
| T1071.001 Web Protocols |
GroupVOID MANTICORE | VOID MANTICORE has utilized HTTPS for communication to C2 domains. |
| T1071.001 Web Protocols |
GroupDaggerfly | Daggerfly uses HTTP for command and control communication. |
| T1071.001 Web Protocols |
GroupRancor | Rancor has used HTTP for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.