Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.002 File Transfer Protocols |
MalwareBADHATCH | BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwarePUBLOAD | PUBLOAD has used `curl` for data exfiltration over FTP. |
| T1071.002 File Transfer Protocols |
MalwareRegin | The Regin malware platform supports many standard protocols, including SMB. |
| T1071.002 File Transfer Protocols |
MalwareKazuar | Kazuar uses FTP and FTPS to communicate with the C2 server. |
| T1071.002 File Transfer Protocols |
MalwareXAgentOSX | XAgentOSX contains the ftpUpload function to use the FTPManager:uploadFile method to upload files from the target system. |
| T1071.002 File Transfer Protocols |
MalwareAttor | Attor has used FTP protocol for C2 communication. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwarePoetRAT | PoetRAT has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareZxShell | ZxShell has used FTP for C2 connections. |
| T1071.002 File Transfer Protocols |
MalwareJPIN | JPIN can communicate over FTP. |
| T1071.002 File Transfer Protocols |
MalwareDisco | Disco can use SMB to transfer files. |
| T1071.002 File Transfer Protocols |
MalwareQilin | Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system. |
| T1071.002 File Transfer Protocols |
MalwareShadowPad | ShadowPad has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareSYSCON | SYSCON has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolCARROTBALL | CARROTBALL has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolMythic | Mythic supports SMB-based peer-to-peer C2 profiles. |
| T1071.003 Mail Protocols |
GroupKimsuky | Kimsuky has used e-mail to send exfiltrated data to C2 servers. |
| T1071.003 Mail Protocols |
GroupAPT32 | APT32 has used email for C2 via an Office macro. |
| T1071.003 Mail Protocols |
GroupContagious Interview | Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement. |
| T1071.003 Mail Protocols |
GroupSilverTerrier | SilverTerrier uses SMTP for C2 communications. |
| T1071.003 Mail Protocols |
GroupTurla | Turla has used multiple backdoors which communicate with a C2 server via email attachments. |
| T1071.003 Mail Protocols |
GroupAPT28 | APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims. |
| T1071.003 Mail Protocols |
MalwarePowerExchange | PowerExchange can receive and send back the results of executed C2 commands through email. |
| T1071.003 Mail Protocols |
MalwareOLDBAIT | OLDBAIT can use SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareIMAPLoader | IMAPLoader uses the IMAP email protocol for command and control purposes. |
| T1071.003 Mail Protocols |
MalwareRDAT | RDAT can use email attachments for C2 communications. |
| T1071.003 Mail Protocols |
MalwareNavRAT | NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP. |
| T1071.003 Mail Protocols |
MalwareCORESHELL | CORESHELL can communicate over SMTP and POP3 for C2. |
| T1071.003 Mail Protocols |
MalwareRemsec | Remsec is capable of using SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareLightNeuron | LightNeuron uses SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareUroburos | Uroburos can use custom communications protocols that ride over SMTP. |
| T1071.003 Mail Protocols |
MalwareNightClub | NightClub can use emails for C2 communications. |
| T1071.003 Mail Protocols |
MalwareBadPatch | BadPatch uses SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant used SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1071.003 Mail Protocols |
MalwareLunarMail | LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI). |
| T1071.003 Mail Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3. |
| T1071.003 Mail Protocols |
MalwareCannon | Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails. |
| T1071.003 Mail Protocols |
MalwareComRAT | ComRAT can use email attachments for command and control. |
| T1071.003 Mail Protocols |
MalwareJPIN | JPIN can send email over SMTP. |
| T1071.003 Mail Protocols |
MalwareAgent Tesla | Agent Tesla has used SMTP for C2 communications. |
| T1071.003 Mail Protocols |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1071.004 DNS |
CampaignCutting Edge | During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic. |
| T1071.004 DNS |
GroupAPT41 | APT41 used DNS for C2 communications. |
| T1071.004 DNS |
GroupFIN7 | FIN7 has performed C2 using DNS via A, OPT, and TXT records. |
| T1071.004 DNS |
GroupAPT18 | APT18 uses DNS for C2 communications. |
| T1071.004 DNS |
GroupAPT39 | APT39 has used remote access tools that leverage DNS in communications with C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1071.004 DNS |
GroupTropic Trooper | Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.