Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.004 Domain Fronting |
ToolMythic | Mythic supports domain fronting via custom request headers. |
| T1091 Replication Through Removable Media |
MalwareStuxnet | Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability. |
| T1091 Replication Through Removable Media |
MalwareUrsnif | Ursnif has copied itself to and infected removable drives for propagation. |
| T1091 Replication Through Removable Media |
MalwareCrimson | Crimson can spread across systems by infecting removable media. |
| T1091 Replication Through Removable Media |
MalwareAgent.btz | Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware. |
| T1091 Replication Through Removable Media |
MalwareRaspberry Robin | Raspberry Robin has historically used infected USB media to spread to new victims. |
| T1091 Replication Through Removable Media |
MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1091 Replication Through Removable Media |
MalwarePlugX | PlugX has copied itself to infected removable drives for propagation to other victim devices. |
| T1091 Replication Through Removable Media |
MalwareDustySky | DustySky searches for removable media and duplicates itself onto it. |
| T1091 Replication Through Removable Media |
MalwareUSBferry | USBferry can copy its installer to attached USB storage devices. |
| T1091 Replication Through Removable Media |
MalwareUnknown Logger | Unknown Logger is capable of spreading to USB devices. |
| T1091 Replication Through Removable Media |
MalwareUSBStealer | USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. |
| T1091 Replication Through Removable Media |
MalwareSHIPSHAPE | APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document. |
| T1091 Replication Through Removable Media |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on removable drives. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1091 Replication Through Removable Media |
MalwarenjRAT | njRAT can be configured to spread via removable drives. |
| T1091 Replication Through Removable Media |
MalwareHIUPAN | HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device. |
| T1091 Replication Through Removable Media |
MalwareANDROMEDA | ANDROMEDA has been spread via infected USB keys. |
| T1091 Replication Through Removable Media |
MalwareQakBot | QakBot has the ability to use removable drives to spread through compromised networks. |
| T1091 Replication Through Removable Media |
MalwareH1N1 | H1N1 has functionality to copy itself to removable media. |
| T1091 Replication Through Removable Media |
MalwareFlame | Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
| T1092 Communication Through Removable Media |
MalwareUSBStealer | USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1095 Non-Application Layer Protocol |
Malwarecd00r | cd00r can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareRotaJakiro | RotaJakiro uses a custom binary protocol using a type, length, value format over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareCOATHANGER | COATHANGER uses ICMP for transmitting configuration information to and from its command and control server. |
| T1095 Non-Application Layer Protocol |
MalwareSardonic | Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol. |
| T1095 Non-Application Layer Protocol |
MalwareMisdat | Misdat network traffic communicates over a raw socket. |
| T1095 Non-Application Layer Protocol |
MalwarereGeorg | reGeorg can tunnel TCP sessions into targeted networks. |
| T1095 Non-Application Layer Protocol |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using SOCKS. |
| T1095 Non-Application Layer Protocol |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket. |
| T1095 Non-Application Layer Protocol |
MalwareInvisibleFerret | InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000. |
| T1095 Non-Application Layer Protocol |
MalwareNebulae | Nebulae can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareTONESHELL | TONESHELL has utilized TCP-based reverse shells. |
| T1095 Non-Application Layer Protocol |
MalwareRainyDay | RainyDay can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareNETWIRE | NETWIRE can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareJ-magic | J-magic can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareAria-body | Aria-body has used TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareCrimson | Crimson uses a custom TCP protocol for C2. |
| T1095 Non-Application Layer Protocol |
MalwareSystemBC | SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries. |
| T1095 Non-Application Layer Protocol |
MalwarePingPull | PingPull variants have the ability to communicate with C2 servers using ICMP or TCP. |
| T1095 Non-Application Layer Protocol |
MalwareMafalda | Mafalda can use raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareUmbreon | Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate. |
| T1095 Non-Application Layer Protocol |
MalwareAuTo Stealer | AuTo Stealer can use TCP to communicate with command and control servers. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareSUGARUSH | SUGARUSH has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareCuckoo Stealer | Cuckoo Stealer can use sockets for communications to its C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareInvisiMole | InvisiMole has used TCP to download additional modules. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.