Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareEmotet | Emotet has used HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareSNUGRIDE | SNUGRIDE communicates with its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareBOLDMOVE | BOLDMOVE uses web services for command and control communication. |
| T1071.001 Web Protocols |
MalwareCrimson | Crimson can use a HTTP GET request to download its final payload. |
| T1071.001 Web Protocols |
MalwareTomiris | Tomiris can use HTTP to establish C2 communications. |
| T1071.001 Web Protocols |
MalwareTurian | Turian has the ability to use HTTP for its C2. |
| T1071.001 Web Protocols |
MalwareTHINCRUST | THINCRUST can use HTTP POST requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareBADHATCH | BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.001 Web Protocols |
MalwareAction RAT | Action RAT can use HTTP to communicate with C2 servers. |
| T1071.001 Web Protocols |
MalwareAvenger | Avenger has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.001 Web Protocols |
MalwarePingPull | A PingPull variant can communicate with its C2 servers by using HTTPS. |
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareDacls | Dacls can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareWoody RAT | Woody RAT can communicate with its C2 server using HTTP requests. |
| T1071.001 Web Protocols |
MalwareMafalda | Mafalda can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareSquirrelwaffle | Squirrelwaffle has used HTTP POST requests for C2 communications. |
| T1071.001 Web Protocols |
MalwareELMER | ELMER uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwarePolyglotDuke | PolyglotDuke has has used HTTP GET requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareHexEval Loader | HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
| T1071.001 Web Protocols |
MalwareAuTo Stealer | AuTo Stealer can use HTTP to communicate with its C2 servers. |
| T1071.001 Web Protocols |
MalwareShrinkLocker | ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor. |
| T1071.001 Web Protocols |
MalwareFlawedAmmyy | FlawedAmmyy has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareCuckoo Stealer | Cuckoo Stealer can use the curl API for C2 communications. |
| T1071.001 Web Protocols |
MalwareGuLoader | GuLoader can use HTTP to retrieve additional binaries. |
| T1071.001 Web Protocols |
MalwareInvisiMole | InvisiMole uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareP.A.S. Webshell | P.A.S. Webshell can issue commands via HTTP POST. |
| T1071.001 Web Protocols |
MalwareWhisperGate | WhisperGate can make an HTTPS connection to download additional files. |
| T1071.001 Web Protocols |
MalwareZeroT | ZeroT has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareKeydnap | Keydnap uses HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareRDAT | RDAT can use HTTP communications for C2, as well as using the WinHTTP library to make requests to the Exchange Web Services API. |
| T1071.001 Web Protocols |
MalwareOkrum | Okrum uses HTTP for communication with its C2. |
| T1071.001 Web Protocols |
MalwareTRANSLATEXT | TRANSLATEXT has used HTTP to communicate with the C2 server. |
| T1071.001 Web Protocols |
MalwareRegin | The Regin malware platform supports many standard protocols, including HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareLine Dancer | Line Dancer uses HTTP POST requests to interact with compromised devices. |
| T1071.001 Web Protocols |
MalwareNeoichor | Neoichor can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRaspberry Robin | Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution. |
| T1071.001 Web Protocols |
MalwareDiavol | Diavol has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
MalwareDoki | Doki has communicated with C2 over HTTPS. |
| T1071.001 Web Protocols |
MalwareRustyWater | RustyWater has used the Rust request library for HTTP C2 communication. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1071.001 Web Protocols |
MalwareVERMIN | VERMIN uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareUBoatRAT | UBoatRAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareHTTPTroy | HTTPTroy has used HTTP POST requests to communicate with C2. |
| T1071.001 Web Protocols |
MalwareMarkiRAT | MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server. |
| T1071.001 Web Protocols |
MalwarePowerShower | PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions. |
| T1071.001 Web Protocols |
MalwareKazuar | Kazuar uses HTTP and HTTPS to communicate with the C2 server. Kazuar can also act as a webserver and listen for inbound HTTP requests through an exposed API. |
| T1071.001 Web Protocols |
MalwareDarkComet | DarkComet can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request. NETEAGLE will also use HTTP to download resources that contain an IP address and Port Number pair to connect to for further C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.