Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1071.001 Web Protocols |
MalwareBLINDINGCAN | BLINDINGCAN has used HTTPS over port 443 for command and control. |
| T1071.001 Web Protocols |
MalwareNinja | Ninja can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareSpark | Spark has used HTTP POST requests to communicate with its C2 server to receive commands. |
| T1071.001 Web Protocols |
MalwareQuietSieve | QuietSieve can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareBRICKSTORM | BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls. |
| T1071.001 Web Protocols |
MalwareAmadey | Amadey has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareProxysvc | Proxysvc uses HTTP over SSL to communicate commands with the control server. |
| T1071.001 Web Protocols |
MalwareTorisma | Torisma can use HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareNOKKI | NOKKI has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareStuxnet | Stuxnet uses HTTP to communicate with a command and control server. |
| T1071.001 Web Protocols |
MalwareIronWind | IronWind can used HTTP to send information to C2 about the targeted system. |
| T1071.001 Web Protocols |
MalwareGet2 | Get2 has the ability to use HTTP to send information collected from an infected host to C2. |
| T1071.001 Web Protocols |
MalwarePOWRUNER | POWRUNER can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareKOPILUWAK | KOPILUWAK has used HTTP POST requests to send data to C2. |
| T1071.001 Web Protocols |
MalwareCOATHANGER | COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control. |
| T1071.001 Web Protocols |
MalwareSmoke Loader | Smoke Loader uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareWindTail | WindTail has the ability to use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwarereGeorg | reGeorg can use HTTP to tunnel connections in and out of targeted networks. |
| T1071.001 Web Protocols |
MalwareEmissary | Emissary uses HTTP or HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareExaramel for Linux | Exaramel for Linux uses HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using HTTP or HTTPS. |
| T1071.001 Web Protocols |
MalwareHAWKBALL | HAWKBALL has used HTTP to communicate with a single hard-coded C2 server. |
| T1071.001 Web Protocols |
MalwareTAMECAT | TAMECAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareZLib | ZLib communicates over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareRedLeaves | RedLeaves can communicate to its C2 over HTTP and HTTPS if directed. |
| T1071.001 Web Protocols |
MalwareTsundere Botnet | Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes. |
| T1071.001 Web Protocols |
MalwareFelismus | Felismus uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareZeus Panda | Zeus Panda uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareGeminiDuke | GeminiDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.001 Web Protocols |
MalwareGravityRAT | GravityRAT uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareInvisibleFerret | InvisibleFerret has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareBankshot | Bankshot uses HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareStrongPity | StrongPity can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwarexCaon | xCaon has communicated with the C2 server by sending POST requests over HTTP. |
| T1071.001 Web Protocols |
MalwarePony | Pony has sent collected information to the C2 via HTTP POST request. |
| T1071.001 Web Protocols |
MalwareWinMM | WinMM uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareTONESHELL | TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareRainyDay | RainyDay can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareAppleSeed | AppleSeed has the ability to communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareLOWBALL | LOWBALL command and control occurs via HTTPS over port 443. |
| T1071.001 Web Protocols |
MalwareNETWIRE | NETWIRE has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareTinyTurla | TinyTurla can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareBOOKWORM | BOOKWORM has communicated with its C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareHAMMERTOSS | The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands. |
| T1071.001 Web Protocols |
MalwareOLDBAIT | OLDBAIT can use HTTP for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.