Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can establish a TCP connection as part of its initial connection to the C2. |
| T1095 Non-Application Layer Protocol |
MalwareRegin | The Regin malware platform can use ICMP to communicate between infected computers. |
| T1095 Non-Application Layer Protocol |
MalwareREPTILE | REPTILE can communicate using TLS over raw TCP. |
| T1095 Non-Application Layer Protocol |
MalwareNETEAGLE | If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs. |
| T1095 Non-Application Layer Protocol |
MalwareSnappyTCP | SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation. |
| T1095 Non-Application Layer Protocol |
MalwareAnchor | Anchor has used ICMP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwarePlugX | PlugX can be configured to use raw TCP or UDP for command and control. |
| T1095 Non-Application Layer Protocol |
MalwareReaver | Some Reaver variants use raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareBisonal | Bisonal has used raw sockets for network communication. |
| T1095 Non-Application Layer Protocol |
MalwareRemsec | Remsec is capable of using ICMP, TCP, and UDP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareKEYPLUG | KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareClambling | Clambling has the ability to use TCP and UDP for communication. |
| T1095 Non-Application Layer Protocol |
MalwareTSCookie | TSCookie can use ICMP to receive information on the destination server. |
| T1095 Non-Application Layer Protocol |
MalwarePay2Key | Pay2Key has sent its public key to the C2 server over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareRoyal | Royal establishes a TCP socket for C2 communication using the API `WSASocketW`. |
| T1095 Non-Application Layer Protocol |
MalwareUroburos | Uroburos can communicate through custom methodologies for UDP, ICMP, and TCP that use distinct sessions to ride over the legitimate protocols. |
| T1095 Non-Application Layer Protocol |
MalwareMetamorfo | Metamorfo has used raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareSpica | Spica can use JSON over WebSockets for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareBandook | Bandook has a command built in to use a raw TCP socket. |
| T1095 Non-Application Layer Protocol |
MalwarePipeMon | The PipeMon communication module can use a custom protocol based on TLS over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Linux | Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications. |
| T1095 Non-Application Layer Protocol |
Malwaregh0st RAT | gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2. |
| T1095 Non-Application Layer Protocol |
MalwareRARSTONE | RARSTONE uses SSL to encrypt its communication with its C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareSDBbot | SDBbot has the ability to communicate with C2 with TCP over port 443. |
| T1095 Non-Application Layer Protocol |
MalwareDerusbi | Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2. |
| T1095 Non-Application Layer Protocol |
MalwareWellMail | WellMail can use TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareWINDSHIELD | WINDSHIELD C2 traffic can communicate via TCP raw sockets. |
| T1095 Non-Application Layer Protocol |
MalwareDrovorub | Drovorub can use TCP to communicate between its agent and client modules. |
| T1095 Non-Application Layer Protocol |
MalwareMoonWind | MoonWind completes network communication via raw sockets. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1095 Non-Application Layer Protocol |
MalwareCryptoistic | Cryptoistic can use TCP in communications with C2. |
| T1095 Non-Application Layer Protocol |
MalwareLunarMail | LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain. |
| T1095 Non-Application Layer Protocol |
MalwareCobalt Strike | Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareSamurai | Samurai can use a proxy module to forward TCP packets to external hosts. |
| T1095 Non-Application Layer Protocol |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic. |
| T1095 Non-Application Layer Protocol |
MalwareTaidoor | Taidoor can use TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareCarbon | Carbon uses TCP and UDP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareNeo-reGeorg | Neo-reGeorg can create multiple TCP connections for a single session. |
| T1095 Non-Application Layer Protocol |
MalwareFakeM | Some variants of FakeM use SSL to communicate with C2 servers. |
| T1095 Non-Application Layer Protocol |
MalwareMacMa | MacMa has used a custom JSON-based protocol for its C&C communications. |
| T1095 Non-Application Layer Protocol |
MalwareFunnyDream | FunnyDream can communicate with C2 over TCP and UDP. |
| T1095 Non-Application Layer Protocol |
MalwareMOPSLED | MOPSLED can use a custom binary protocol over TCP for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareLookBack | LookBack uses a custom binary protocol over sockets for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareStealBit | StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints. |
| T1095 Non-Application Layer Protocol |
MalwarePenquin | The Penquin C2 mechanism is based on TCP and UDP packets. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Windows | Winnti for Windows can communicate using custom TCP. |
| T1095 Non-Application Layer Protocol |
MalwareZIPLINE | ZIPLINE can communicate with C2 using a custom binary protocol. |
| T1095 Non-Application Layer Protocol |
MalwaremetaMain | metaMain can establish an indirect and raw TCP socket-based connection to the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareMis-Type | Mis-Type network traffic can communicate over a raw socket. |
| T1095 Non-Application Layer Protocol |
MalwareStarProxy | StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.