ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1090.004
Domain Fronting
ToolMythic

Mythic supports domain fronting via custom request headers.

T1091
Replication Through Removable Media
MalwareStuxnet

Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability.

T1091
Replication Through Removable Media
MalwareUrsnif

Ursnif has copied itself to and infected removable drives for propagation.

T1091
Replication Through Removable Media
MalwareCrimson

Crimson can spread across systems by infecting removable media.

T1091
Replication Through Removable Media
MalwareAgent.btz

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

T1091
Replication Through Removable Media
MalwareRaspberry Robin

Raspberry Robin has historically used infected USB media to spread to new victims.

T1091
Replication Through Removable Media
MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1091
Replication Through Removable Media
MalwarePlugX

PlugX has copied itself to infected removable drives for propagation to other victim devices.

T1091
Replication Through Removable Media
MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

T1091
Replication Through Removable Media
MalwareUSBferry

USBferry can copy its installer to attached USB storage devices.

T1091
Replication Through Removable Media
MalwareUnknown Logger

Unknown Logger is capable of spreading to USB devices.

T1091
Replication Through Removable Media
MalwareUSBStealer

USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system.

T1091
Replication Through Removable Media
MalwareSHIPSHAPE

APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document.

T1091
Replication Through Removable Media
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on removable drives.

T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1091
Replication Through Removable Media
MalwareHIUPAN

HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device.

T1091
Replication Through Removable Media
MalwareANDROMEDA

ANDROMEDA has been spread via infected USB keys.

T1091
Replication Through Removable Media
MalwareQakBot

QakBot has the ability to use removable drives to spread through compromised networks.

T1091
Replication Through Removable Media
MalwareH1N1

H1N1 has functionality to copy itself to removable media.

T1091
Replication Through Removable Media
MalwareFlame

Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality.

T1092
Communication Through Removable Media
MalwareUSBStealer

USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim.

T1092
Communication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

T1095
Non-Application Layer Protocol
Malwarecd00r

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol using a type, length, value format over TCP.

T1095
Non-Application Layer Protocol
MalwareCOATHANGER

COATHANGER uses ICMP for transmitting configuration information to and from its command and control server.

T1095
Non-Application Layer Protocol
MalwareSardonic

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1095
Non-Application Layer Protocol
MalwareMisdat

Misdat network traffic communicates over a raw socket.

T1095
Non-Application Layer Protocol
MalwarereGeorg

reGeorg can tunnel TCP sessions into targeted networks.

T1095
Non-Application Layer Protocol
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using SOCKS.

T1095
Non-Application Layer Protocol
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket.

T1095
Non-Application Layer Protocol
MalwareInvisibleFerret

InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000.

T1095
Non-Application Layer Protocol
MalwareNebulae

Nebulae can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareTONESHELL

TONESHELL has utilized TCP-based reverse shells.

T1095
Non-Application Layer Protocol
MalwareRainyDay

RainyDay can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareJ-magic

J-magic can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareAria-body

Aria-body has used TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareCrimson

Crimson uses a custom TCP protocol for C2.

T1095
Non-Application Layer Protocol
MalwareSystemBC

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1095
Non-Application Layer Protocol
MalwarePingPull

PingPull variants have the ability to communicate with C2 servers using ICMP or TCP.

T1095
Non-Application Layer Protocol
MalwareMafalda

Mafalda can use raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareUmbreon

Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate.

T1095
Non-Application Layer Protocol
MalwareAuTo Stealer

AuTo Stealer can use TCP to communicate with command and control servers.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1095
Non-Application Layer Protocol
MalwareSUGARUSH

SUGARUSH has used TCP for C2.

T1095
Non-Application Layer Protocol
MalwareCuckoo Stealer

Cuckoo Stealer can use sockets for communications to its C2 server.

T1095
Non-Application Layer Protocol
MalwareInvisiMole

InvisiMole has used TCP to download additional modules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.