Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareZIPLINE | ZIPLINE can download files to be saved on the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareTURNEDUP | TURNEDUP is capable of downloading additional files. |
| T1105 Ingress Tool Transfer |
MalwareChChes | ChChes is capable of downloading files, including additional modules. |
| T1105 Ingress Tool Transfer |
MalwareANDROMEDA | ANDROMEDA can download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareShai-Hulud | Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data. |
| T1105 Ingress Tool Transfer |
MalwareJPIN | JPIN can download files and upgrade itself. |
| T1105 Ingress Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwaremetaMain | metaMain can download files onto compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareSideTwist | SideTwist has the ability to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareKOCTOPUS | KOCTOPUS has executed a PowerShell command to download a file to the system. |
| T1105 Ingress Tool Transfer |
MalwareMechaFlounder | MechaFlounder has the ability to upload and download files to and from a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePsylo | Psylo has a command to download a file to the system from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHTTPBrowser | HTTPBrowser is capable of writing a file to the compromised system from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareMis-Type | Mis-Type has downloaded additional malware and files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareXCSSET | XCSSET downloads browser specific AppleScript modules using a constructed URL with the |
| T1105 Ingress Tool Transfer |
MalwareDisco | Disco can download files to targeted systems via SMB. |
| T1105 Ingress Tool Transfer |
MalwareDipsind | Dipsind can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareOctopus | Octopus can download additional files and tools onto the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareSoreFang | SoreFang can download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareIndustroyer | Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory. |
| T1105 Ingress Tool Transfer |
MalwareKevin | Kevin can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAgent Tesla | Agent Tesla can download additional files for execution on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwarePasam | Pasam creates a backdoor through which remote attackers can upload files. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSTATS | POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareBADNEWS | BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself. |
| T1105 Ingress Tool Transfer |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can download files onto compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareShadowPad | ShadowPad has downloaded code from a C2 server. |
| T1105 Ingress Tool Transfer |
MalwareAstaroth | Astaroth uses certutil and BITSAdmin to download additional malware. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1105 Ingress Tool Transfer |
MalwareDOWNIISSA | DOWNIISSA can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareCookieMiner | CookieMiner can download additional scripts from a web server. |
| T1105 Ingress Tool Transfer |
MalwareHancitor | Hancitor has the ability to download additional files from C2. |
| T1105 Ingress Tool Transfer |
MalwareGelsemium | Gelsemium can download additional plug-ins to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarejRAT | jRAT can download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareHelminth | Helminth can download additional files. |
| T1105 Ingress Tool Transfer |
MalwareBBK | BBK has the ability to download files from C2 to the infected host. |
| T1105 Ingress Tool Transfer |
MalwareOSX/Shlayer | OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the |
| T1105 Ingress Tool Transfer |
MalwareDenis | Denis deploys additional backdoors and hacking tools to the system. |
| T1105 Ingress Tool Transfer |
MalwareWaterbear | Waterbear can receive and load executables from remote C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareVasport | Vasport can download files. |
| T1105 Ingress Tool Transfer |
MalwareJSS Loader | JSS Loader has the ability to download malicious executables to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareLizar | Lizar can download additional plugins, files, and tools. |
| T1105 Ingress Tool Transfer |
MalwareDtrack | Dtrack’s can download and upload a file to the victim’s computer. |
| T1105 Ingress Tool Transfer |
MalwareH1N1 | H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests. |
| T1105 Ingress Tool Transfer |
MalwareSeth-Locker | Seth-Locker has the ability to download and execute files on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareLoudMiner | LoudMiner used SCP to update the miner from the C2. |
| T1105 Ingress Tool Transfer |
MalwareAzorult | Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes. |
| T1105 Ingress Tool Transfer |
MalwareZox | Zox can download files to a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareUPPERCUT | UPPERCUT can download and upload files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareStrifeWater | StrifeWater can download updates and auxiliary modules. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.