ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1102.002
Bidirectional Communication
MalwareCloudDuke

One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.

T1102.002
Bidirectional Communication
MalwareRIFLESPINE

RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.

T1102.002
Bidirectional Communication
MalwareBLACKCOFFEE

BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github.

T1102.002
Bidirectional Communication
MalwareComRAT

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1102.002
Bidirectional Communication
MalwarePowerStallion

PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with net use.

T1102.002
Bidirectional Communication
MalwareCozyCar

CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file.

T1102.002
Bidirectional Communication
MalwareBADNEWS

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.

T1102.002
Bidirectional Communication
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.

T1102.002
Bidirectional Communication
MalwareComnie

Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server.

T1102.002
Bidirectional Communication
MalwareSmall Sieve

Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages.

T1102.002
Bidirectional Communication
ToolEmpire

Empire can use Dropbox and GitHub for C2.

T1102.003
One-Way Communication
MalwareUPSTYLE

UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server.

T1102.003
One-Way Communication
MalwareHAMMERTOSS

The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day.

T1102.003
One-Way Communication
MalwareEVILNUM

EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2.

T1102.003
One-Way Communication
MalwareSagerunex

Sagerunex has used web services such as Twitter for command and control purposes.

T1102.003
One-Way Communication
MalwareMetamorfo

Metamorfo has downloaded a zip file for execution on the system.

T1102.003
One-Way Communication
MalwareOnionDuke

OnionDuke uses Twitter as a backup C2.

T1104
Multi-Stage Channels
MalwareJumbledPath

JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1104
Multi-Stage Channels
MalwareChaos

After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system.

T1104
Multi-Stage Channels
MalwareLatrodectus

Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure.

T1104
Multi-Stage Channels
MalwareUroburos

Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation.

T1104
Multi-Stage Channels
MalwareBazar

The Bazar loader is used to download and execute the Bazar backdoor.

T1104
Multi-Stage Channels
MalwareValak

Valak can download additional modules and malware capable of using separate C2 channels.

T1104
Multi-Stage Channels
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines.

T1104
Multi-Stage Channels
MalwareLunarWeb

LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands.

T1104
Multi-Stage Channels
MalwareBACKSPACE

BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware.

T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1105
Ingress Tool Transfer
MalwarePowerDuke

PowerDuke has a command to download a file.

T1105
Ingress Tool Transfer
MalwareBLINDINGCAN

BLINDINGCAN has downloaded files to a victim machine.

T1105
Ingress Tool Transfer
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can download files.

T1105
Ingress Tool Transfer
MalwareRCSession

RCSession has the ability to drop additional files to an infected machine.

T1105
Ingress Tool Transfer
MalwareQuietSieve

QuietSieve can download and execute payloads on a target host.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1105
Ingress Tool Transfer
MalwareAmadey

Amadey can download and execute files to further infect a host machine with additional malware.

T1105
Ingress Tool Transfer
MalwareNICECURL

NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.

T1105
Ingress Tool Transfer
MalwareOrz

Orz can download files onto the victim.

T1105
Ingress Tool Transfer
MalwareNOKKI

NOKKI has downloaded a remote module for execution.

T1105
Ingress Tool Transfer
MalwareBackdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.

T1105
Ingress Tool Transfer
MalwareDOGCALL

DOGCALL can download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDowndelph

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.

T1105
Ingress Tool Transfer
MalwareSEASHARPEE

SEASHARPEE can download remote files onto victims.

T1105
Ingress Tool Transfer
MalwarePOWRUNER

POWRUNER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
MalwareTDTESS

TDTESS has a command to download and execute an additional file.

T1105
Ingress Tool Transfer
MalwareSharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1105
Ingress Tool Transfer
MalwareSardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.

T1105
Ingress Tool Transfer
MalwareSmoke Loader

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.

T1105
Ingress Tool Transfer
MalwareMisdat

Misdat is capable of downloading files from the C2.

T1105
Ingress Tool Transfer
MalwarereGeorg

reGeorg has the ability to download files to targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.