ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1041×

166 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareTrickBot

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBLINDINGCAN

BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests.

T1041
Exfiltration Over C2 Channel
MalwarePikabot

During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4.

T1041
Exfiltration Over C2 Channel
MalwareSpark

Spark has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBumblebee

Bumblebee can send collected data in JSON format to C2.

T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareAmadey

Amadey has sent victim data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareProxysvc

Proxysvc performs data exfiltration over the control server channel using a custom protocol.

T1041
Exfiltration Over C2 Channel
MalwareTorisma

Torisma can send victim data to an actor-controlled C2 server.

T1041
Exfiltration Over C2 Channel
MalwareStuxnet

Stuxnet sends compromised victim information via HTTP.

T1041
Exfiltration Over C2 Channel
MalwareRotaJakiro

RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP.

T1041
Exfiltration Over C2 Channel
MalwareKOPILUWAK

KOPILUWAK has exfiltrated collected data to its C2 via POST requests.

T1041
Exfiltration Over C2 Channel
MalwareMisdat

Misdat has uploaded files and data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHAWKBALL

HAWKBALL has sent system information and files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareUrsnif

Ursnif has used HTTP POSTs to exfil gathered information.

T1041
Exfiltration Over C2 Channel
MalwareZLib

ZLib has sent data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareInvisibleFerret

InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareBankshot

Bankshot exfiltrates data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareSharpDisco

SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2.

T1041
Exfiltration Over C2 Channel
MalwareStrongPity

StrongPity can exfiltrate collected documents through C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareAppleSeed

AppleSeed can exfiltrate files via the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePowerExchange

PowerExchange can exfiltrate files via its email C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareEmotet

Emotet has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareCrimson

Crimson can exfiltrate stolen information over its C2.

T1041
Exfiltration Over C2 Channel
MalwareTomiris

Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDUSTTRAP

DUSTTRAP can exfiltrate collected data over C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareBADHATCH

BADHATCH can exfiltrate data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMachete

Machete's collected data is exfiltrated over the same channel used for C2.

T1041
Exfiltration Over C2 Channel
MalwarePingPull

PingPull has the ability to exfiltrate stolen victim data through its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareWoody RAT

Woody RAT can exfiltrate files from an infected machine to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareMafalda

Mafalda can send network system data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSquirrelwaffle

Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHexEval Loader

HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareAuTo Stealer

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.

T1041
Exfiltration Over C2 Channel
MalwareShrinkLocker

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1041
Exfiltration Over C2 Channel
MalwareSombRAT

SombRAT has uploaded collected data and files from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files.

T1041
Exfiltration Over C2 Channel
MalwareFlawedAmmyy

FlawedAmmyy has sent data collected from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHOPLIGHT

HOPLIGHT has used its C2 channel to exfiltrate data.

T1041
Exfiltration Over C2 Channel
MalwareCuckoo Stealer

Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username.

T1041
Exfiltration Over C2 Channel
MalwareMobileOrder

MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareRDAT

RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOkrum

Data exfiltration is done by Okrum using the already opened channel with the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected credentials to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLine Dancer

Line Dancer exfiltrates collected data via command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareMispadu

Mispadu can sends the collected financial data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDoki

Doki has used Ngrok to establish C2 and exfiltrate data.

T1041
Exfiltration Over C2 Channel
MalwareHTTPTroy

HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command.

T1041
Exfiltration Over C2 Channel
MalwareMarkiRAT

MarkiRAT can exfiltrate locally stored data via its C2.

T1041
Exfiltration Over C2 Channel
MalwarePowerShower

PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.