Real-world descriptions of how a group, tool or campaign used a technique.
166 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBLINDINGCAN | BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwarePikabot | During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4. |
| T1041 Exfiltration Over C2 Channel |
MalwareSpark | Spark has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBumblebee | Bumblebee can send collected data in JSON format to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareBRICKSTORM | BRICKSTORM has uploaded files from the victim system to C2 servers. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1041 Exfiltration Over C2 Channel |
MalwareAmadey | Amadey has sent victim data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareProxysvc | Proxysvc performs data exfiltration over the control server channel using a custom protocol. |
| T1041 Exfiltration Over C2 Channel |
MalwareTorisma | Torisma can send victim data to an actor-controlled C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareStuxnet | Stuxnet sends compromised victim information via HTTP. |
| T1041 Exfiltration Over C2 Channel |
MalwareRotaJakiro | RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareKOPILUWAK | KOPILUWAK has exfiltrated collected data to its C2 via POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareMisdat | Misdat has uploaded files and data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHAWKBALL | HAWKBALL has sent system information and files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1041 Exfiltration Over C2 Channel |
MalwareZLib | ZLib has sent data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareInvisibleFerret | InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareBankshot | Bankshot exfiltrates data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareSharpDisco | SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrongPity | StrongPity can exfiltrate collected documents through C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerExchange | PowerExchange can exfiltrate files via its email C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareEmotet | Emotet has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrimson | Crimson can exfiltrate stolen information over its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareTomiris | Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDUSTTRAP | DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareBADHATCH | BADHATCH can exfiltrate data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMachete | Machete's collected data is exfiltrated over the same channel used for C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePingPull | PingPull has the ability to exfiltrate stolen victim data through its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareWoody RAT | Woody RAT can exfiltrate files from an infected machine to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareMafalda | Mafalda can send network system data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSquirrelwaffle | Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHexEval Loader | HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareAuTo Stealer | AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1041 Exfiltration Over C2 Channel |
MalwareSombRAT | SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlawedAmmyy | FlawedAmmyy has sent data collected from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHOPLIGHT | HOPLIGHT has used its C2 channel to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareCuckoo Stealer | Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username. |
| T1041 Exfiltration Over C2 Channel |
MalwareMobileOrder | MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareRDAT | RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOkrum | Data exfiltration is done by Okrum using the already opened channel with the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated collected credentials to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Dancer | Line Dancer exfiltrates collected data via command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareMispadu | Mispadu can sends the collected financial data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDoki | Doki has used Ngrok to establish C2 and exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareHTTPTroy | HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command. |
| T1041 Exfiltration Over C2 Channel |
MalwareMarkiRAT | MarkiRAT can exfiltrate locally stored data via its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerShower | PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.