Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupAPT18 | APT18 uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupSidewinder | Sidewinder has used HTTP in C2 communications. |
| T1071.001 Web Protocols |
GroupMustang Panda | Mustang Panda has communicated with its C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
GroupRocke | Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1071.001 Web Protocols |
GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupHigaisa | Higaisa used HTTP and HTTPS to send data back to its C2 server. |
| T1071.001 Web Protocols |
GroupTropic Trooper | Tropic Trooper has used HTTP in communication with the C2. |
| T1071.001 Web Protocols |
GroupOrangeworm | Orangeworm has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupSea Turtle | Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.001 Web Protocols |
GroupConfucius | Confucius has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWinter Vivern | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1071.001 Web Protocols |
GroupSilverTerrier | SilverTerrier uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupTA505 | TA505 has used HTTP to communicate with C2 nodes. |
| T1071.001 Web Protocols |
GroupBITTER | BITTER has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
GroupRedCurl | RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications. |
| T1071.001 Web Protocols |
GroupStealth Falcon | Stealth Falcon malware communicates with its C2 server via HTTPS. |
| T1071.001 Web Protocols |
GroupDark Caracal | Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”. |
| T1071.001 Web Protocols |
GroupChimera | Chimera has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupMedusa Group | Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS). |
| T1071.001 Web Protocols |
GroupBRONZE BUTLER | BRONZE BUTLER malware has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupTA551 | TA551 has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWindshift | Windshift has used tools that communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
GroupLuminousMoth | LuminousMoth has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.001 Web Protocols |
GroupMetador | Metador has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupFIN4 | FIN4 has used HTTP POST requests to transmit data. |
| T1071.001 Web Protocols |
GroupCobalt Group | Cobalt Group has used HTTPS for C2. |
| T1071.001 Web Protocols |
GroupWizard Spider | Wizard Spider has used HTTP for network communications. |
| T1071.001 Web Protocols |
GroupMoonstone Sleet | Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1071.001 Web Protocols |
GroupInception | Inception has used HTTP, HTTPS, and WebDav in network communications. |
| T1071.001 Web Protocols |
GroupVOID MANTICORE | VOID MANTICORE has utilized HTTPS for communication to C2 domains. |
| T1071.001 Web Protocols |
GroupDaggerfly | Daggerfly uses HTTP for command and control communication. |
| T1071.001 Web Protocols |
GroupRancor | Rancor has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupWIRTE | WIRTE has used HTTP for network communication. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupThreat Group-3390 | Threat Group-3390 malware has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT33 | APT33 has used HTTP for command and control. |
| T1071.001 Web Protocols |
GroupFIN8 | FIN8 has used HTTPS for command and control. |
| T1071.001 Web Protocols |
GroupFIN13 | FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data. |
| T1071.001 Web Protocols |
GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1071.001 Web Protocols |
MalwareBLINDINGCAN | BLINDINGCAN has used HTTPS over port 443 for command and control. |
| T1071.001 Web Protocols |
MalwareNinja | Ninja can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.