Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
MalwareShadowPad | ShadowPad has used UDP for C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareQakBot | QakBot has the ability use TCP to send or receive C2 packets. |
| T1095 Non-Application Layer Protocol |
MalwareGelsemium | Gelsemium has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwarePHOREAL | PHOREAL communicates via ICMP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareLizar | Lizar has used a raw TCP connection to communicate with the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenWasp | HiddenWasp communicates with a simple network protocol over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareWarzoneRAT | WarzoneRAT can communicate with its C2 server via TCP over port 5200. |
| T1095 Non-Application Layer Protocol |
ToolFRP | FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP. |
| T1095 Non-Application Layer Protocol |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use TCP for external C2. |
| T1095 Non-Application Layer Protocol |
ToolMythic | Mythic supports WebSocket and TCP-based C2 profiles. |
| T1095 Non-Application Layer Protocol |
ToolQuasarRAT | QuasarRAT can use TCP for C2 communication. |
| T1098 Account Manipulation |
MalwareCalisto | Calisto adds permissions and remote logins to all users. |
| T1098 Account Manipulation |
MalwareShai-Hulud | Shai-Hulud has modified GitHub account settings for private repositories and changed them to public. |
| T1098 Account Manipulation |
ToolMimikatz | The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The |
| T1098.001 Additional Cloud Credentials |
ToolPacu | Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users. |
| T1098.004 SSH Authorized Keys |
MalwareSkidmap | Skidmap has the ability to add the public key of its handlers to the |
| T1098.004 SSH Authorized Keys |
MalwareBundlore | Bundlore creates a new key pair with |
| T1098.004 SSH Authorized Keys |
MalwareXCSSET | XCSSET will create an ssh key if necessary with the |
| T1098.005 Device Registration |
ToolAADInternals | AADInternals can register a device to Azure AD. |
| T1098.007 Additional Local or Domain Groups |
MalwareDarkGate | DarkGate elevates accounts created through the malware to the local administration group during execution. |
| T1098.007 Additional Local or Domain Groups |
MalwareSMOKEDHAM | SMOKEDHAM has added user accounts to local Admin groups. |
| T1098.007 Additional Local or Domain Groups |
MalwareServHelper | ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups. |
| T1098.007 Additional Local or Domain Groups |
ToolNet | The `net localgroup` and `net group` commands in Net can be used to add existing users to local and domain groups. |
| T1102 Web Service |
MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| T1102 Web Service |
MalwareBRICKSTORM | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications. |
| T1102 Web Service |
MalwareSharpStage | SharpStage has used a legitimate web service for evading detection. |
| T1102 Web Service |
MalwareNETWIRE | NETWIRE has used web services including Paste.ee to host payloads. |
| T1102 Web Service |
MalwareBADHATCH | BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels. |
| T1102 Web Service |
MalwareDropBook | DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions. |
| T1102 Web Service |
MalwareShrinkLocker | ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1102 Web Service |
MalwareHildegard | Hildegard has downloaded scripts from GitHub. |
| T1102 Web Service |
MalwareSnip3 | Snip3 can download additional payloads from web services including Pastebin and top4top. |
| T1102 Web Service |
MalwareGuLoader | GuLoader has the ability to download malware from Google Drive. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1102 Web Service |
MalwareRaspberry Robin | Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers. |
| T1102 Web Service |
MalwareDoki | Doki has used the dogechain.info API to generate a C2 address. |
| T1102 Web Service |
MalwareNightdoor | Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1102 Web Service |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell. |
| T1102 Web Service |
MalwareSocGholish | SocGholish has used Amazon Web Services to host second-stage servers. |
| T1102 Web Service |
MalwareDarkTortilla | DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin. |
| T1102 Web Service |
MalwarePureCrypter | PureCrypter can use Telegram or Discord to send infection status messages. |
| T1102 Web Service |
MalwareLatrodectus | Latrodectus has used Google Firebase to download malicious installation scripts. |
| T1102 Web Service |
MalwareCharmPower | CharmPower can download additional modules from actor-controlled Amazon S3 buckets. |
| T1102 Web Service |
MalwareSMOKEDHAM | SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1102 Web Service |
MalwareRedLine Stealer | RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads. |
| T1102 Web Service |
MalwareSibot | Sibot has used a legitimate compromised website to download DLLs to the victim's machine. |
| T1102 Web Service |
MalwareBazar | Bazar downloads have been hosted on Google Docs. |
| T1102 Web Service |
MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| T1102 Web Service |
MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| T1102 Web Service |
MalwareMOPSLED | MOPSLED can use third-party web services such as GitHub and Google Drive for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.