Real-world descriptions of how a group, tool or campaign used a technique.
88 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
Malwarecd00r | cd00r can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareRotaJakiro | RotaJakiro uses a custom binary protocol using a type, length, value format over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareCOATHANGER | COATHANGER uses ICMP for transmitting configuration information to and from its command and control server. |
| T1095 Non-Application Layer Protocol |
MalwareSardonic | Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol. |
| T1095 Non-Application Layer Protocol |
MalwareMisdat | Misdat network traffic communicates over a raw socket. |
| T1095 Non-Application Layer Protocol |
MalwarereGeorg | reGeorg can tunnel TCP sessions into targeted networks. |
| T1095 Non-Application Layer Protocol |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using SOCKS. |
| T1095 Non-Application Layer Protocol |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket. |
| T1095 Non-Application Layer Protocol |
MalwareInvisibleFerret | InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000. |
| T1095 Non-Application Layer Protocol |
MalwareNebulae | Nebulae can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareTONESHELL | TONESHELL has utilized TCP-based reverse shells. |
| T1095 Non-Application Layer Protocol |
MalwareRainyDay | RainyDay can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareNETWIRE | NETWIRE can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareJ-magic | J-magic can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareAria-body | Aria-body has used TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareCrimson | Crimson uses a custom TCP protocol for C2. |
| T1095 Non-Application Layer Protocol |
MalwareSystemBC | SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries. |
| T1095 Non-Application Layer Protocol |
MalwarePingPull | PingPull variants have the ability to communicate with C2 servers using ICMP or TCP. |
| T1095 Non-Application Layer Protocol |
MalwareMafalda | Mafalda can use raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareUmbreon | Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate. |
| T1095 Non-Application Layer Protocol |
MalwareAuTo Stealer | AuTo Stealer can use TCP to communicate with command and control servers. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareSUGARUSH | SUGARUSH has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareCuckoo Stealer | Cuckoo Stealer can use sockets for communications to its C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareInvisiMole | InvisiMole has used TCP to download additional modules. |
| T1095 Non-Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can establish a TCP connection as part of its initial connection to the C2. |
| T1095 Non-Application Layer Protocol |
MalwareRegin | The Regin malware platform can use ICMP to communicate between infected computers. |
| T1095 Non-Application Layer Protocol |
MalwareREPTILE | REPTILE can communicate using TLS over raw TCP. |
| T1095 Non-Application Layer Protocol |
MalwareNETEAGLE | If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs. |
| T1095 Non-Application Layer Protocol |
MalwareSnappyTCP | SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation. |
| T1095 Non-Application Layer Protocol |
MalwareAnchor | Anchor has used ICMP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwarePlugX | PlugX can be configured to use raw TCP or UDP for command and control. |
| T1095 Non-Application Layer Protocol |
MalwareReaver | Some Reaver variants use raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareBisonal | Bisonal has used raw sockets for network communication. |
| T1095 Non-Application Layer Protocol |
MalwareRemsec | Remsec is capable of using ICMP, TCP, and UDP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareKEYPLUG | KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareClambling | Clambling has the ability to use TCP and UDP for communication. |
| T1095 Non-Application Layer Protocol |
MalwareTSCookie | TSCookie can use ICMP to receive information on the destination server. |
| T1095 Non-Application Layer Protocol |
MalwarePay2Key | Pay2Key has sent its public key to the C2 server over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareRoyal | Royal establishes a TCP socket for C2 communication using the API `WSASocketW`. |
| T1095 Non-Application Layer Protocol |
MalwareUroburos | Uroburos can communicate through custom methodologies for UDP, ICMP, and TCP that use distinct sessions to ride over the legitimate protocols. |
| T1095 Non-Application Layer Protocol |
MalwareMetamorfo | Metamorfo has used raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareSpica | Spica can use JSON over WebSockets for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareBandook | Bandook has a command built in to use a raw TCP socket. |
| T1095 Non-Application Layer Protocol |
MalwarePipeMon | The PipeMon communication module can use a custom protocol based on TLS over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Linux | Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications. |
| T1095 Non-Application Layer Protocol |
Malwaregh0st RAT | gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2. |
| T1095 Non-Application Layer Protocol |
MalwareRARSTONE | RARSTONE uses SSL to encrypt its communication with its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.