Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102 Web Service |
MalwareBoomBox | BoomBox can download files from Dropbox using a hardcoded access token. |
| T1102 Web Service |
Toolngrok | ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains. |
| T1102 Web Service |
ToolBrute Ratel C4 | Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams. |
| T1102 Web Service |
MalwareKali365 | Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users. |
| T1102.001 Dead Drop Resolver |
MalwareTsundere Botnet | Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1102.001 Dead Drop Resolver |
MalwarePolyglotDuke | PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL. |
| T1102.001 Dead Drop Resolver |
MalwareTRANSLATEXT | TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.001 Dead Drop Resolver |
MalwareMiniDuke | Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1102.001 Dead Drop Resolver |
MalwareJavali | Javali can read C2 information from Google Documents and YouTube. |
| T1102.001 Dead Drop Resolver |
MalwarePlugX | PlugX uses Pastebin to store C2 addresses. |
| T1102.001 Dead Drop Resolver |
MalwareXbash | Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list. |
| T1102.001 Dead Drop Resolver |
MalwareKEYPLUG | The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums. |
| T1102.001 Dead Drop Resolver |
MalwareCharmPower | CharmPower can retrieve C2 domain information from actor-controlled S3 buckets. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1102.001 Dead Drop Resolver |
MalwareMetamorfo | Metamorfo has used YouTube to store and hide C&C server domains. |
| T1102.001 Dead Drop Resolver |
MalwareRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
| T1102.001 Dead Drop Resolver |
MalwareGrandoreiro | Grandoreiro can obtain C2 information from Google Docs. |
| T1102.001 Dead Drop Resolver |
MalwareMOPSLED | MOPSLED has the ability to retrieve a C2 address from a dead drop URL. |
| T1102.001 Dead Drop Resolver |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server. |
| T1102.001 Dead Drop Resolver |
MalwareBADNEWS | BADNEWS collects C2 information via a dead drop resolver. |
| T1102.001 Dead Drop Resolver |
MalwareAstaroth | Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook. |
| T1102.001 Dead Drop Resolver |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1102.002 Bidirectional Communication |
MalwareOrz | Orz has used Technet and Pastebin web pages for command and control. |
| T1102.002 Bidirectional Communication |
Malwareyty | yty communicates to the C2 server by retrieving a Google Doc. |
| T1102.002 Bidirectional Communication |
MalwareDOGCALL | DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2. |
| T1102.002 Bidirectional Communication |
MalwareLOWBALL | LOWBALL uses the Dropbox cloud storage service for command and control. |
| T1102.002 Bidirectional Communication |
MalwareKARAE | KARAE can use public cloud-based storage providers for command and control. |
| T1102.002 Bidirectional Communication |
MalwareSLOWDRIFT | SLOWDRIFT uses cloud based services for C2. |
| T1102.002 Bidirectional Communication |
MalwareODAgent | ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. |
| T1102.002 Bidirectional Communication |
MalwareRegDuke | RegDuke can use Dropbox as its C2 server. |
| T1102.002 Bidirectional Communication |
MalwareTRANSLATEXT | TRANSLATEXT has used a Github repository for C2. |
| T1102.002 Bidirectional Communication |
MalwareUBoatRAT | UBoatRAT has used GitHub and a public blog service in Hong Kong for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareKazuar | Kazuar has used compromised WordPress blogs as C2 servers. |
| T1102.002 Bidirectional Communication |
MalwarePOORAIM | POORAIM has used AOL Instant Messenger for C2. |
| T1102.002 Bidirectional Communication |
MalwareCALENDAR | The CALENDAR malware communicates through the use of events in Google Calendar. |
| T1102.002 Bidirectional Communication |
MalwareROKRAT | ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareClambling | Clambling can use Dropbox to download malicious payloads, send commands, and receive information. |
| T1102.002 Bidirectional Communication |
MalwareCreepyDrive | CreepyDrive can use OneDrive for C2. |
| T1102.002 Bidirectional Communication |
MalwareSagerunex | Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants. |
| T1102.002 Bidirectional Communication |
MalwareBLUELIGHT | BLUELIGHT can use different cloud providers for its C2. |
| T1102.002 Bidirectional Communication |
MalwareRogueRobin | RogueRobin has used Google Drive as a Command and Control channel. |
| T1102.002 Bidirectional Communication |
MalwareBoxCaon | BoxCaon has used DropBox for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareCrutch | Crutch can use Dropbox to receive commands and upload stolen data. |
| T1102.002 Bidirectional Communication |
MalwareGrandoreiro | Grandoreiro can utilize web services including Google sites to send and receive C2 data. |
| T1102.002 Bidirectional Communication |
MalwareOilCheck | OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. |
| T1102.002 Bidirectional Communication |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages. |
| T1102.002 Bidirectional Communication |
MalwareOilBooster | OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data. |
| T1102.002 Bidirectional Communication |
MalwareRevenge RAT | Revenge RAT used blogpost.com as its primary command and control server during a campaign. |
| T1102.002 Bidirectional Communication |
MalwareLAMEHUG | LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.