Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102.002 Bidirectional Communication |
MalwareCloudDuke | One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators. |
| T1102.002 Bidirectional Communication |
MalwareRIFLESPINE | RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive. |
| T1102.002 Bidirectional Communication |
MalwareBLACKCOFFEE | BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github. |
| T1102.002 Bidirectional Communication |
MalwareComRAT | ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. |
| T1102.002 Bidirectional Communication |
MalwarePowerStallion | PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with |
| T1102.002 Bidirectional Communication |
MalwareCozyCar | CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file. |
| T1102.002 Bidirectional Communication |
MalwareBADNEWS | BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs. |
| T1102.002 Bidirectional Communication |
MalwareGLOOXMAIL | GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol. |
| T1102.002 Bidirectional Communication |
MalwareComnie | Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server. |
| T1102.002 Bidirectional Communication |
MalwareSmall Sieve | Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages. |
| T1102.002 Bidirectional Communication |
ToolEmpire | Empire can use Dropbox and GitHub for C2. |
| T1102.003 One-Way Communication |
MalwareUPSTYLE | UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server. |
| T1102.003 One-Way Communication |
MalwareHAMMERTOSS | The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day. |
| T1102.003 One-Way Communication |
MalwareEVILNUM | EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2. |
| T1102.003 One-Way Communication |
MalwareSagerunex | Sagerunex has used web services such as Twitter for command and control purposes. |
| T1102.003 One-Way Communication |
MalwareMetamorfo | Metamorfo has downloaded a zip file for execution on the system. |
| T1102.003 One-Way Communication |
MalwareOnionDuke | OnionDuke uses Twitter as a backup C2. |
| T1104 Multi-Stage Channels |
MalwareJumbledPath | JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices. |
| T1104 Multi-Stage Channels |
MalwareSnip3 | Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1104 Multi-Stage Channels |
MalwareChaos | After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system. |
| T1104 Multi-Stage Channels |
MalwareLatrodectus | Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure. |
| T1104 Multi-Stage Channels |
MalwareUroburos | Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation. |
| T1104 Multi-Stage Channels |
MalwareBazar | The Bazar loader is used to download and execute the Bazar backdoor. |
| T1104 Multi-Stage Channels |
MalwareValak | Valak can download additional modules and malware capable of using separate C2 channels. |
| T1104 Multi-Stage Channels |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines. |
| T1104 Multi-Stage Channels |
MalwareLunarWeb | LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands. |
| T1104 Multi-Stage Channels |
MalwareBACKSPACE | BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware. |
| T1105 Ingress Tool Transfer |
MalwareTrickBot | TrickBot downloads several additional files and saves them to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarePowerDuke | PowerDuke has a command to download a file. |
| T1105 Ingress Tool Transfer |
MalwareBLINDINGCAN | BLINDINGCAN has downloaded files to a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can download files. |
| T1105 Ingress Tool Transfer |
MalwareRCSession | RCSession has the ability to drop additional files to an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareQuietSieve | QuietSieve can download and execute payloads on a target host. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1105 Ingress Tool Transfer |
MalwareBRICKSTORM | BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareAmadey | Amadey can download and execute files to further infect a host machine with additional malware. |
| T1105 Ingress Tool Transfer |
MalwareNICECURL | NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`. |
| T1105 Ingress Tool Transfer |
MalwareOrz | Orz can download files onto the victim. |
| T1105 Ingress Tool Transfer |
MalwareNOKKI | NOKKI has downloaded a remote module for execution. |
| T1105 Ingress Tool Transfer |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can download additional modules from C2. |
| T1105 Ingress Tool Transfer |
MalwareDOGCALL | DOGCALL can download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDowndelph | After downloading its main config file, Downdelph downloads multiple payloads from C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareSEASHARPEE | SEASHARPEE can download remote files onto victims. |
| T1105 Ingress Tool Transfer |
MalwarePOWRUNER | POWRUNER can download or upload files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareTDTESS | TDTESS has a command to download and execute an additional file. |
| T1105 Ingress Tool Transfer |
MalwareSharpStage | SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1105 Ingress Tool Transfer |
MalwareSardonic | Sardonic has the ability to upload additional malicious files to a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareSmoke Loader | Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins. |
| T1105 Ingress Tool Transfer |
MalwareMisdat | Misdat is capable of downloading files from the C2. |
| T1105 Ingress Tool Transfer |
MalwarereGeorg | reGeorg has the ability to download files to targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.