ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
MalwareShadowPad

ShadowPad has used UDP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareQakBot

QakBot has the ability use TCP to send or receive C2 packets.

T1095
Non-Application Layer Protocol
MalwareGelsemium

Gelsemium has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwarePHOREAL

PHOREAL communicates via ICMP for C2.

T1095
Non-Application Layer Protocol
MalwareLizar

Lizar has used a raw TCP connection to communicate with the C2 server.

T1095
Non-Application Layer Protocol
MalwareHiddenWasp

HiddenWasp communicates with a simple network protocol over TCP.

T1095
Non-Application Layer Protocol
MalwareWarzoneRAT

WarzoneRAT can communicate with its C2 server via TCP over port 5200.

T1095
Non-Application Layer Protocol
ToolFRP

FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP.

T1095
Non-Application Layer Protocol
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use TCP for external C2.

T1095
Non-Application Layer Protocol
ToolMythic

Mythic supports WebSocket and TCP-based C2 profiles.

T1095
Non-Application Layer Protocol
ToolQuasarRAT

QuasarRAT can use TCP for C2 communication.

T1098
Account Manipulation
MalwareCalisto

Calisto adds permissions and remote logins to all users.

T1098
Account Manipulation
MalwareShai-Hulud

Shai-Hulud has modified GitHub account settings for private repositories and changed them to public.

T1098
Account Manipulation
ToolMimikatz

The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The LSADUMP::ChangeNTLM and LSADUMP::SetNTLM modules can also manipulate the password hash of an account without knowing the clear text value.

T1098.001
Additional Cloud Credentials
ToolPacu

Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users.

T1098.004
SSH Authorized Keys
MalwareSkidmap

Skidmap has the ability to add the public key of its handlers to the authorized_keys file to maintain persistence on an infected host.

T1098.004
SSH Authorized Keys
MalwareBundlore

Bundlore creates a new key pair with ssh-keygen and drops the newly created user key in authorized_keys to enable remote login.

T1098.004
SSH Authorized Keys
MalwareXCSSET

XCSSET will create an ssh key if necessary with the ssh-keygen -t rsa -f $HOME/.ssh/id_rsa -P command. XCSSET will upload a private key file to the server to remotely access the host without a password.

T1098.005
Device Registration
ToolAADInternals

AADInternals can register a device to Azure AD.

T1098.007
Additional Local or Domain Groups
MalwareDarkGate

DarkGate elevates accounts created through the malware to the local administration group during execution.

T1098.007
Additional Local or Domain Groups
MalwareSMOKEDHAM

SMOKEDHAM has added user accounts to local Admin groups.

T1098.007
Additional Local or Domain Groups
MalwareServHelper

ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups.

T1098.007
Additional Local or Domain Groups
ToolNet

The `net localgroup` and `net group` commands in Net can be used to add existing users to local and domain groups.

T1102
Web Service
MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

T1102
Web Service
MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1102
Web Service
MalwareSharpStage

SharpStage has used a legitimate web service for evading detection.

T1102
Web Service
MalwareNETWIRE

NETWIRE has used web services including Paste.ee to host payloads.

T1102
Web Service
MalwareBADHATCH

BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels.

T1102
Web Service
MalwareDropBook

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1102
Web Service
MalwareShrinkLocker

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1102
Web Service
MalwareHildegard

Hildegard has downloaded scripts from GitHub.

T1102
Web Service
MalwareSnip3

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1102
Web Service
MalwareGuLoader

GuLoader has the ability to download malware from Google Drive.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1102
Web Service
MalwareRaspberry Robin

Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers.

T1102
Web Service
MalwareDoki

Doki has used the dogechain.info API to generate a C2 address.

T1102
Web Service
MalwareNightdoor

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1102
Web Service
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell.

T1102
Web Service
MalwareSocGholish

SocGholish has used Amazon Web Services to host second-stage servers.

T1102
Web Service
MalwareDarkTortilla

DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin.

T1102
Web Service
MalwarePureCrypter

PureCrypter can use Telegram or Discord to send infection status messages.

T1102
Web Service
MalwareLatrodectus

Latrodectus has used Google Firebase to download malicious installation scripts.

T1102
Web Service
MalwareCharmPower

CharmPower can download additional modules from actor-controlled Amazon S3 buckets.

T1102
Web Service
MalwareSMOKEDHAM

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1102
Web Service
MalwareSibot

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1102
Web Service
MalwareBazar

Bazar downloads have been hosted on Google Docs.

T1102
Web Service
MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

T1102
Web Service
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

T1102
Web Service
MalwareMOPSLED

MOPSLED can use third-party web services such as GitHub and Google Drive for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.