ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareZIPLINE

ZIPLINE can download files to be saved on the compromised system.

T1105
Ingress Tool Transfer
MalwareTURNEDUP

TURNEDUP is capable of downloading additional files.

T1105
Ingress Tool Transfer
MalwareChChes

ChChes is capable of downloading files, including additional modules.

T1105
Ingress Tool Transfer
MalwareANDROMEDA

ANDROMEDA can download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareShai-Hulud

Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.

T1105
Ingress Tool Transfer
MalwareJPIN

JPIN can download files and upgrade itself.

T1105
Ingress Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA has the ability to upload and download files.

T1105
Ingress Tool Transfer
MalwaremetaMain

metaMain can download files onto compromised systems.

T1105
Ingress Tool Transfer
MalwareSideTwist

SideTwist has the ability to download additional files.

T1105
Ingress Tool Transfer
MalwareKOCTOPUS

KOCTOPUS has executed a PowerShell command to download a file to the system.

T1105
Ingress Tool Transfer
MalwareMechaFlounder

MechaFlounder has the ability to upload and download files to and from a compromised host.

T1105
Ingress Tool Transfer
MalwarePsylo

Psylo has a command to download a file to the system from its C2 server.

T1105
Ingress Tool Transfer
MalwareHTTPBrowser

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.

T1105
Ingress Tool Transfer
MalwareMis-Type

Mis-Type has downloaded additional malware and files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareXCSSET

XCSSET downloads browser specific AppleScript modules using a constructed URL with the curl command, https://" & domain & "/agent/scripts/" & moduleName & ".applescript.

T1105
Ingress Tool Transfer
MalwareDisco

Disco can download files to targeted systems via SMB.

T1105
Ingress Tool Transfer
MalwareDipsind

Dipsind can download remote files.

T1105
Ingress Tool Transfer
MalwareOctopus

Octopus can download additional files and tools onto the victim’s machine.

T1105
Ingress Tool Transfer
MalwareSoreFang

SoreFang can download additional payloads from C2.

T1105
Ingress Tool Transfer
MalwareIndustroyer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.

T1105
Ingress Tool Transfer
MalwareKevin

Kevin can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareAgent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePasam

Pasam creates a backdoor through which remote attackers can upload files.

T1105
Ingress Tool Transfer
MalwarePOWERSTATS

POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.

T1105
Ingress Tool Transfer
MalwareBADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.

T1105
Ingress Tool Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.

T1105
Ingress Tool Transfer
MalwareShadowPad

ShadowPad has downloaded code from a C2 server.

T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1105
Ingress Tool Transfer
MalwareDOWNIISSA

DOWNIISSA can download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareCookieMiner

CookieMiner can download additional scripts from a web server.

T1105
Ingress Tool Transfer
MalwareHancitor

Hancitor has the ability to download additional files from C2.

T1105
Ingress Tool Transfer
MalwareGelsemium

Gelsemium can download additional plug-ins to a compromised host.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

T1105
Ingress Tool Transfer
MalwareHelminth

Helminth can download additional files.

T1105
Ingress Tool Transfer
MalwareBBK

BBK has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
MalwareOSX/Shlayer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1105
Ingress Tool Transfer
MalwareDenis

Denis deploys additional backdoors and hacking tools to the system.

T1105
Ingress Tool Transfer
MalwareWaterbear

Waterbear can receive and load executables from remote C2 servers.

T1105
Ingress Tool Transfer
MalwareVasport

Vasport can download files.

T1105
Ingress Tool Transfer
MalwareJSS Loader

JSS Loader has the ability to download malicious executables to a compromised host.

T1105
Ingress Tool Transfer
MalwareLizar

Lizar can download additional plugins, files, and tools.

T1105
Ingress Tool Transfer
MalwareDtrack

Dtrack’s can download and upload a file to the victim’s computer.

T1105
Ingress Tool Transfer
MalwareH1N1

H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.

T1105
Ingress Tool Transfer
MalwareSeth-Locker

Seth-Locker has the ability to download and execute files on a compromised host.

T1105
Ingress Tool Transfer
MalwareLoudMiner

LoudMiner used SCP to update the miner from the C2.

T1105
Ingress Tool Transfer
MalwareAzorult

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.

T1105
Ingress Tool Transfer
MalwareZox

Zox can download files to a compromised machine.

T1105
Ingress Tool Transfer
MalwareUPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareStrifeWater

StrifeWater can download updates and auxiliary modules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.