Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareMivast | Mivast has the capability to download and execute .exe files. |
| T1105 Ingress Tool Transfer |
MalwareHiddenWasp | HiddenWasp downloads a tar compressed archive from a download server to the system. |
| T1105 Ingress Tool Transfer |
MalwareWarzoneRAT | WarzoneRAT can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has downloaded files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareXORIndex Loader | XORIndex Loader has been used to download a malicious payload to include BeaverTail. |
| T1105 Ingress Tool Transfer |
MalwareSmall Sieve | Small Sieve has the ability to download files. |
| T1105 Ingress Tool Transfer |
ToolRemoteUtilities | RemoteUtilities can upload and download files to and from a target machine. |
| T1105 Ingress Tool Transfer |
Toolcertutil | certutil can be used to download files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolShimRatReporter | ShimRatReporter had the ability to download additional payloads. |
| T1105 Ingress Tool Transfer |
ToolSliver | Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the |
| T1105 Ingress Tool Transfer |
ToolSILENTTRINITY | SILENTTRINITY can load additional files and tools, including Mimikatz. |
| T1105 Ingress Tool Transfer |
ToolEmpire | Empire can upload and download to and from a victim machine. |
| T1105 Ingress Tool Transfer |
ToolCSPY Downloader | CSPY Downloader can download additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolCARROTBALL | CARROTBALL has the ability to download and install a remote payload. |
| T1105 Ingress Tool Transfer |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files. |
| T1105 Ingress Tool Transfer |
ToolAsyncRAT | AsyncRAT has the ability to download files including over SFTP. |
| T1105 Ingress Tool Transfer |
ToolBrute Ratel C4 | Brute Ratel C4 can download files to compromised hosts. |
| T1105 Ingress Tool Transfer |
ToolRemcos | Remcos can upload and download files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
ToolMCMD | MCMD can upload additional files to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolDonut | Donut can download and execute previously staged shellcode payloads. |
| T1105 Ingress Tool Transfer |
Toolcmd | cmd can be used to copy files to/from a remotely connected external system. |
| T1105 Ingress Tool Transfer |
Toolesentutl | esentutl can be used to copy files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolKoadic | Koadic can download additional files and tools. |
| T1105 Ingress Tool Transfer |
ToolPupy | Pupy can upload and download to/from a victim machine. |
| T1105 Ingress Tool Transfer |
Toolftp | ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment. |
| T1105 Ingress Tool Transfer |
ToolQuasarRAT | QuasarRAT can download files to the victim’s machine and execute them. |
| T1105 Ingress Tool Transfer |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareCanisterWorm | CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1105 Ingress Tool Transfer |
MalwareBADFLICK | BADFLICK has download files from its C2 server. |
| T1106 Native API |
MalwareTrickBot | TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used |
| T1106 Native API |
MalwareNinja | The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption. |
| T1106 Native API |
MalwarePikabot | Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution. |
| T1106 Native API |
MalwareRCSession | RCSession can use WinSock API for communication including |
| T1106 Native API |
MalwareSynAck | SynAck parses the export tables of system DLLs to locate and call various Windows API functions. |
| T1106 Native API |
MalwareBumblebee | Bumblebee can use multiple Native APIs. |
| T1106 Native API |
MalwareAmadey | Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`. |
| T1106 Native API |
MalwareRDFSNIFFER | RDFSNIFFER has used several Win32 API functions to interact with the victim machine. |
| T1106 Native API |
MalwareTorisma | Torisma has used various Windows API calls. |
| T1106 Native API |
MalwareStuxnet | Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels. |
| T1106 Native API |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect". |
| T1106 Native API |
MalwareAvosLocker | AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`. |
| T1106 Native API |
MalwarePAKLOG | PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions. |
| T1106 Native API |
MalwareSardonic | Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running. |
| T1106 Native API |
MalwareWindTail | WindTail can invoke Apple APIs |
| T1106 Native API |
MalwareMisdat | Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`. |
| T1106 Native API |
MalwareHAWKBALL | HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity. |
| T1106 Native API |
MalwareHeartCrypt | HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources. |
| T1106 Native API |
MalwareUrsnif | Ursnif has used |
| T1106 Native API |
MalwareHavoc | Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.