Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareDRATzarus | DRATzarus can deploy additional tools onto an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareShimRat | ShimRat can download additional files. |
| T1105 Ingress Tool Transfer |
MalwareChrommme | Chrommme can download its code from C2. |
| T1105 Ingress Tool Transfer |
MalwareConficker | Conficker downloads an HTTP server to the infected machine. |
| T1105 Ingress Tool Transfer |
MalwareSocGholish | SocGholish can download additional malware to infected hosts. |
| T1105 Ingress Tool Transfer |
MalwareFlagpro | Flagpro can download additional malware from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHi-Zor | Hi-Zor has the ability to upload and download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareSpicyOmelette | SpicyOmelette can download malicious files from threat actor controlled AWS URL's. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareLightSpy | On macOS, LightSpy downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections. |
| T1105 Ingress Tool Transfer |
MalwarePUNCHBUGGY | PUNCHBUGGY can download additional files and payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareGoldMax | GoldMax can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareCostaBricks | CostaBricks has been used to load SombRAT onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKeyBoy | KeyBoy has a download and upload functionality. |
| T1105 Ingress Tool Transfer |
MalwarePOSHSPY | POSHSPY downloads and executes additional PowerShell code and Windows binaries. |
| T1105 Ingress Tool Transfer |
MalwareMiniDuke | MiniDuke can download additional encrypted backdoors onto the victim via GIF files. |
| T1105 Ingress Tool Transfer |
MalwareHyperBro | HyperBro has the ability to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareAnchor | Anchor can download additional payloads. |
| T1105 Ingress Tool Transfer |
MalwarePteranodon | Pteranodon can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareDarkTortilla | DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit. |
| T1105 Ingress Tool Transfer |
MalwareBeaverTail | BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1105 Ingress Tool Transfer |
MalwareROKRAT | ROKRAT can retrieve additional malicious payloads from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCORESHELL | CORESHELL downloads another dropper from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDyre | Dyre has a command to download and executes additional files. |
| T1105 Ingress Tool Transfer |
MalwareBlackMould | BlackMould has the ability to download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareJavali | Javali can download payloads from remote C2 servers. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareBisonal | Bisonal has the capability to download files to execute on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareS-Type | S-Type can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSeaDuke | SeaDuke is capable of uploading and downloading files. |
| T1105 Ingress Tool Transfer |
MalwareRemsec | Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareExplosive | Explosive has a function to download a file to the infected system. |
| T1105 Ingress Tool Transfer |
MalwareXbash | Xbash can download additional malicious files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareLightNeuron | LightNeuron has the ability to download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwarePeppy | Peppy can download and execute remote files. |
| T1105 Ingress Tool Transfer |
MalwareCuba | Cuba can download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDEATHRANSOM | DEATHRANSOM can download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePureCrypter | PureCrypter can download additional payloads for execution on the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDarkGate | DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the |
| T1105 Ingress Tool Transfer |
MalwareMongall | Mongall can download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareNanHaiShu | NanHaiShu can download additional files from URLs. |
| T1105 Ingress Tool Transfer |
MalwareSVCReady | SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host. |
| T1105 Ingress Tool Transfer |
MalwareThiefQuest | ThiefQuest can download and execute payloads in-memory or from disk. |
| T1105 Ingress Tool Transfer |
MalwareFoggyWeb | FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server. |
| T1105 Ingress Tool Transfer |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can download files and additional malware components. |
| T1105 Ingress Tool Transfer |
MalwareSHARPSTATS | SHARPSTATS has the ability to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwareCreepyDrive | CreepyDrive can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to download and upload files to the system. |
| T1105 Ingress Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1105 Ingress Tool Transfer |
MalwareElise | Elise can download additional files from the C2 server for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.