ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareDRATzarus

DRATzarus can deploy additional tools onto an infected machine.

T1105
Ingress Tool Transfer
MalwareShimRat

ShimRat can download additional files.

T1105
Ingress Tool Transfer
MalwareChrommme

Chrommme can download its code from C2.

T1105
Ingress Tool Transfer
MalwareConficker

Conficker downloads an HTTP server to the infected machine.

T1105
Ingress Tool Transfer
MalwareSocGholish

SocGholish can download additional malware to infected hosts.

T1105
Ingress Tool Transfer
MalwareFlagpro

Flagpro can download additional malware from the C2 server.

T1105
Ingress Tool Transfer
MalwareHi-Zor

Hi-Zor has the ability to upload and download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareSpicyOmelette

SpicyOmelette can download malicious files from threat actor controlled AWS URL's.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1105
Ingress Tool Transfer
MalwareLightSpy

On macOS, LightSpy downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections.

T1105
Ingress Tool Transfer
MalwarePUNCHBUGGY

PUNCHBUGGY can download additional files and payloads to compromised hosts.

T1105
Ingress Tool Transfer
MalwareGoldMax

GoldMax can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareCostaBricks

CostaBricks has been used to load SombRAT onto a compromised host.

T1105
Ingress Tool Transfer
MalwareKeyBoy

KeyBoy has a download and upload functionality.

T1105
Ingress Tool Transfer
MalwarePOSHSPY

POSHSPY downloads and executes additional PowerShell code and Windows binaries.

T1105
Ingress Tool Transfer
MalwareMiniDuke

MiniDuke can download additional encrypted backdoors onto the victim via GIF files.

T1105
Ingress Tool Transfer
MalwareHyperBro

HyperBro has the ability to download additional files.

T1105
Ingress Tool Transfer
MalwareAnchor

Anchor can download additional payloads.

T1105
Ingress Tool Transfer
MalwarePteranodon

Pteranodon can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareDarkTortilla

DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.

T1105
Ingress Tool Transfer
MalwareBeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1105
Ingress Tool Transfer
MalwareCORESHELL

CORESHELL downloads another dropper from its C2 server.

T1105
Ingress Tool Transfer
MalwareDyre

Dyre has a command to download and executes additional files.

T1105
Ingress Tool Transfer
MalwareBlackMould

BlackMould has the ability to download files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareJavali

Javali can download payloads from remote C2 servers.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1105
Ingress Tool Transfer
MalwareBisonal

Bisonal has the capability to download files to execute on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareS-Type

S-Type can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareSeaDuke

SeaDuke is capable of uploading and downloading files.

T1105
Ingress Tool Transfer
MalwareRemsec

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareExplosive

Explosive has a function to download a file to the infected system.

T1105
Ingress Tool Transfer
MalwareXbash

Xbash can download additional malicious files from its C2 server.

T1105
Ingress Tool Transfer
MalwareLightNeuron

LightNeuron has the ability to download and execute additional files.

T1105
Ingress Tool Transfer
MalwarePeppy

Peppy can download and execute remote files.

T1105
Ingress Tool Transfer
MalwareCuba

Cuba can download files from its C2 server.

T1105
Ingress Tool Transfer
MalwareDEATHRANSOM

DEATHRANSOM can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwarePureCrypter

PureCrypter can download additional payloads for execution on the compromised host.

T1105
Ingress Tool Transfer
MalwareDarkGate

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads. DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1105
Ingress Tool Transfer
MalwareMongall

Mongall can download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareNanHaiShu

NanHaiShu can download additional files from URLs.

T1105
Ingress Tool Transfer
MalwareSVCReady

SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.

T1105
Ingress Tool Transfer
MalwareThiefQuest

ThiefQuest can download and execute payloads in-memory or from disk.

T1105
Ingress Tool Transfer
MalwareFoggyWeb

FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.

T1105
Ingress Tool Transfer
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.

T1105
Ingress Tool Transfer
MalwareSHARPSTATS

SHARPSTATS has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwareCreepyDrive

CreepyDrive can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to download and upload files to the system.

T1105
Ingress Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1105
Ingress Tool Transfer
MalwareElise

Elise can download additional files from the C2 server for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.