ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupAPT18

APT18 uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1071.001
Web Protocols
GroupRocke

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1071.001
Web Protocols
GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1071.001
Web Protocols
GroupTropic Trooper

Tropic Trooper has used HTTP in communication with the C2.

T1071.001
Web Protocols
GroupOrangeworm

Orangeworm has used HTTP for C2.

T1071.001
Web Protocols
GroupSea Turtle

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.001
Web Protocols
GroupConfucius

Confucius has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWinter Vivern

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1071.001
Web Protocols
GroupSilverTerrier

SilverTerrier uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTA505

TA505 has used HTTP to communicate with C2 nodes.

T1071.001
Web Protocols
GroupBITTER

BITTER has used HTTP POST requests for C2.

T1071.001
Web Protocols
GroupRedCurl

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

T1071.001
Web Protocols
GroupStealth Falcon

Stealth Falcon malware communicates with its C2 server via HTTPS.

T1071.001
Web Protocols
GroupDark Caracal

Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.

T1071.001
Web Protocols
GroupChimera

Chimera has used HTTPS for C2 communications.

T1071.001
Web Protocols
GroupMedusa Group

Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).

T1071.001
Web Protocols
GroupBRONZE BUTLER

BRONZE BUTLER malware has used HTTP for C2.

T1071.001
Web Protocols
GroupTA551

TA551 has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWindshift

Windshift has used tools that communicate with C2 over HTTP.

T1071.001
Web Protocols
GroupLuminousMoth

LuminousMoth has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.001
Web Protocols
GroupMetador

Metador has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1071.001
Web Protocols
GroupFIN4

FIN4 has used HTTP POST requests to transmit data.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.001
Web Protocols
GroupWizard Spider

Wizard Spider has used HTTP for network communications.

T1071.001
Web Protocols
GroupMoonstone Sleet

Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1071.001
Web Protocols
GroupVOID MANTICORE

VOID MANTICORE has utilized HTTPS for communication to C2 domains.

T1071.001
Web Protocols
GroupDaggerfly

Daggerfly uses HTTP for command and control communication.

T1071.001
Web Protocols
GroupRancor

Rancor has used HTTP for C2.

T1071.001
Web Protocols
GroupWIRTE

WIRTE has used HTTP for network communication.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1071.001
Web Protocols
GroupThreat Group-3390

Threat Group-3390 malware has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT33

APT33 has used HTTP for command and control.

T1071.001
Web Protocols
GroupFIN8

FIN8 has used HTTPS for command and control.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1071.001
Web Protocols
GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1071.001
Web Protocols
MalwareBLINDINGCAN

BLINDINGCAN has used HTTPS over port 443 for command and control.

T1071.001
Web Protocols
MalwareNinja

Ninja can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.