ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

88 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
GroupAPT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine.

T1105
Ingress Tool Transfer
GroupIndrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupBlackByte

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.

T1105
Ingress Tool Transfer
GroupElderwood

The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location.

T1105
Ingress Tool Transfer
GroupSideCopy

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.

T1105
Ingress Tool Transfer
GroupGALLIUM

GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN.

T1105
Ingress Tool Transfer
GroupAPT3

APT3 has a tool that can copy files to remote machines.

T1105
Ingress Tool Transfer
GroupMustard Tempest

Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts.

T1105
Ingress Tool Transfer
GroupKimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.

T1105
Ingress Tool Transfer
GroupVolt Typhoon

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.

T1105
Ingress Tool Transfer
GroupPatchwork

Patchwork payloads download additional files from the C2 server.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1105
Ingress Tool Transfer
GroupDragonfly

Dragonfly has copied and installed tools for operations once in the victim environment.

T1105
Ingress Tool Transfer
GroupEvilnum

Evilnum can deploy additional components or tools as needed.

T1105
Ingress Tool Transfer
GroupGorgon Group

Gorgon Group malware can download additional files from C2 servers.

T1105
Ingress Tool Transfer
GroupmenuPass

menuPass has installed updates and new malware on victims.

T1105
Ingress Tool Transfer
GroupAPT32

APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.

T1105
Ingress Tool Transfer
GroupHAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1105
Ingress Tool Transfer
GroupStorm-1811

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1105
Ingress Tool Transfer
GroupTeamTNT

TeamTNT has the curl and wget commands as well as batch scripts to download new tools.

T1105
Ingress Tool Transfer
GroupFIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.

T1105
Ingress Tool Transfer
GroupSandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1105
Ingress Tool Transfer
GroupAPT18

APT18 can upload a file to the victim’s machine.

T1105
Ingress Tool Transfer
GroupAndariel

Andariel has downloaded additional tools and malware onto compromised hosts.

T1105
Ingress Tool Transfer
GroupSidewinder

Sidewinder has used LNK files to download remote files to the victim's network.

T1105
Ingress Tool Transfer
GroupMustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.

T1105
Ingress Tool Transfer
GroupZIRCONIUM

ZIRCONIUM has used tools to download malicious files to compromised hosts.

T1105
Ingress Tool Transfer
GroupRocke

Rocke used malware to download additional malicious files to the target system.

T1105
Ingress Tool Transfer
GroupScattered Spider

Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.

T1105
Ingress Tool Transfer
GroupAPT39

APT39 has downloaded tools to compromised hosts.

T1105
Ingress Tool Transfer
GroupTA2541

TA2541 has used malicious scripts and macros with the ability to download additional payloads.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1105
Ingress Tool Transfer
GroupMoses Staff

Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.

T1105
Ingress Tool Transfer
GroupOilRig

OilRig had downloaded remote files onto victim infrastructure.

T1105
Ingress Tool Transfer
GroupTropic Trooper

Tropic Trooper has used a delivered trojan to download additional files.

T1105
Ingress Tool Transfer
GroupAquatic Panda

Aquatic Panda has downloaded additional malware onto compromised hosts.

T1105
Ingress Tool Transfer
GroupKe3chang

Ke3chang has used tools to download files to compromised machines.

T1105
Ingress Tool Transfer
GroupConfucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1105
Ingress Tool Transfer
GroupLeviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.

T1105
Ingress Tool Transfer
GroupWinter Vivern

Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.

T1105
Ingress Tool Transfer
GroupTurla

Turla has used shellcode to download Meterpreter after compromising a victim.

T1105
Ingress Tool Transfer
GroupTA505

TA505 has downloaded additional malware to execute on victim systems.

T1105
Ingress Tool Transfer
GroupBITTER

BITTER has downloaded additional malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1105
Ingress Tool Transfer
GroupCinnamon Tempest

Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.

T1105
Ingress Tool Transfer
GroupChimera

Chimera has remotely copied tools and malware onto targeted systems.

T1105
Ingress Tool Transfer
GroupMedusa Group

Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.

T1105
Ingress Tool Transfer
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.