Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can send `HTTP GET` requests to C2. |
| T1071.001 Web Protocols |
MalwareFatDuke | FatDuke can be controlled via a custom C2 protocol over HTTP. |
| T1071.001 Web Protocols |
MalwareBlackEnergy | BlackEnergy communicates with its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareDRATzarus | DRATzarus can use HTTP or HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareRising Sun | Rising Sun has used HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareShimRat | ShimRat communicated over HTTP and HTTPS with C2 servers. |
| T1071.001 Web Protocols |
MalwareFlagpro | Flagpro can communicate with its C2 using HTTP. |
| T1071.001 Web Protocols |
MalwareHi-Zor | Hi-Zor communicates with its C2 server over HTTPS. |
| T1071.001 Web Protocols |
MalwareChina Chopper | China Chopper's server component executes code sent via HTTP POST commands. |
| T1071.001 Web Protocols |
MalwareSnappyTCP | SnappyTCP connects to the command and control server via a TCP socket using HTTP. |
| T1071.001 Web Protocols |
MalwareLightSpy | LightSpy's C2 communication is performed over WebSockets using the open source library SocketRocket with functionality such as, heartbeat, receiving commands, and updating command status. |
| T1071.001 Web Protocols |
MalwarePUNCHBUGGY | PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests. |
| T1071.001 Web Protocols |
MalwareGoldMax | GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2. |
| T1071.001 Web Protocols |
MalwareLIGHTWIRE | LIGHTWIRE can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareMiniDuke | MiniDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareHyperBro | HyperBro has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareAnchor | Anchor has used HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareLine Runner | Line Runner utilizes an HTTP-based Lua backdoor on victim machines. |
| T1071.001 Web Protocols |
MalwarePteranodon | Pteranodon can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkTortilla | DarkTortilla has used HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareBeaverTail | BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
| T1071.001 Web Protocols |
MalwareROKRAT | ROKRAT can use HTTP and HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareCORESHELL | CORESHELL can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkWatchman | DarkWatchman uses HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareDyre | Dyre uses HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBlackMould | BlackMould can send commands to C2 in the body of HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareBBSRAT | BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareReaver | Some Reaver variants use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareBisonal | Bisonal has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareS-Type | S-Type uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareSeaDuke | SeaDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareDustySky | DustySky has used both HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareExplosive | Explosive has used HTTP for communication. |
| T1071.001 Web Protocols |
MalwareXbash | Xbash uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareEpic | Epic uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwarePeppy | Peppy can use HTTP to communicate with C2. |
| T1071.001 Web Protocols |
MalwareKEYPLUG | KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2. |
| T1071.001 Web Protocols |
MalwareDEATHRANSOM | DEATHRANSOM can use HTTPS to download files. |
| T1071.001 Web Protocols |
MalwareClambling | Clambling has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareMongall | Mongall can use HTTP for C2 communication. |
| T1071.001 Web Protocols |
MalwareLockBit 3.0 | LockBit 3.0 can use HTTP to send victim host information to C2. |
| T1071.001 Web Protocols |
MalwareSVCReady | SVCReady can communicate with its C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareThiefQuest | ThiefQuest uploads files via unencrypted HTTP. |
| T1071.001 Web Protocols |
MalwareFoggyWeb | FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests. |
| T1071.001 Web Protocols |
MalwareNGLite | NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003. |
| T1071.001 Web Protocols |
MalwareCarbanak | The Carbanak malware communicates to its command server using HTTP with an encrypted payload. |
| T1071.001 Web Protocols |
MalwareCreepyDrive | CreepyDrive can use HTTPS for C2 using the Microsoft Graph API. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.