ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1071.002
File Transfer Protocols
MalwareBADHATCH

BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers.

T1071.002
File Transfer Protocols
MalwareMachete

Machete uses FTP for Command & Control.

T1071.002
File Transfer Protocols
MalwarePUBLOAD

PUBLOAD has used `curl` for data exfiltration over FTP.

T1071.002
File Transfer Protocols
MalwareRegin

The Regin malware platform supports many standard protocols, including SMB.

T1071.002
File Transfer Protocols
MalwareKazuar

Kazuar uses FTP and FTPS to communicate with the C2 server.

T1071.002
File Transfer Protocols
MalwareXAgentOSX

XAgentOSX contains the ftpUpload function to use the FTPManager:uploadFile method to upload files from the target system.

T1071.002
File Transfer Protocols
MalwareAttor

Attor has used FTP protocol for C2 communication.

T1071.002
File Transfer Protocols
MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1071.002
File Transfer Protocols
MalwarePoetRAT

PoetRAT has used FTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareZxShell

ZxShell has used FTP for C2 connections.

T1071.002
File Transfer Protocols
MalwareJPIN

JPIN can communicate over FTP.

T1071.002
File Transfer Protocols
MalwareDisco

Disco can use SMB to transfer files.

T1071.002
File Transfer Protocols
MalwareQilin

Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.

T1071.002
File Transfer Protocols
MalwareShadowPad

ShadowPad has used FTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareSYSCON

SYSCON has the ability to use FTP in C2 communications.

T1071.002
File Transfer Protocols
ToolCARROTBALL

CARROTBALL has the ability to use FTP in C2 communications.

T1071.002
File Transfer Protocols
ToolMythic

Mythic supports SMB-based peer-to-peer C2 profiles.

T1071.003
Mail Protocols
GroupKimsuky

Kimsuky has used e-mail to send exfiltrated data to C2 servers.

T1071.003
Mail Protocols
GroupAPT32

APT32 has used email for C2 via an Office macro.

T1071.003
Mail Protocols
GroupContagious Interview

Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement.

T1071.003
Mail Protocols
GroupSilverTerrier

SilverTerrier uses SMTP for C2 communications.

T1071.003
Mail Protocols
GroupTurla

Turla has used multiple backdoors which communicate with a C2 server via email attachments.

T1071.003
Mail Protocols
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

T1071.003
Mail Protocols
MalwarePowerExchange

PowerExchange can receive and send back the results of executed C2 commands through email.

T1071.003
Mail Protocols
MalwareOLDBAIT

OLDBAIT can use SMTP for C2.

T1071.003
Mail Protocols
MalwareIMAPLoader

IMAPLoader uses the IMAP email protocol for command and control purposes.

T1071.003
Mail Protocols
MalwareRDAT

RDAT can use email attachments for C2 communications.

T1071.003
Mail Protocols
MalwareNavRAT

NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP.

T1071.003
Mail Protocols
MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.003
Mail Protocols
MalwareLightNeuron

LightNeuron uses SMTP for C2.

T1071.003
Mail Protocols
MalwareUroburos

Uroburos can use custom communications protocols that ride over SMTP.

T1071.003
Mail Protocols
MalwareNightClub

NightClub can use emails for C2 communications.

T1071.003
Mail Protocols
MalwareBadPatch

BadPatch uses SMTP for C2.

T1071.003
Mail Protocols
MalwareSUGARDUMP

A SUGARDUMP variant used SMTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareLunarMail

LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI).

T1071.003
Mail Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

T1071.003
Mail Protocols
MalwareCannon

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

T1071.003
Mail Protocols
MalwareComRAT

ComRAT can use email attachments for command and control.

T1071.003
Mail Protocols
MalwareJPIN

JPIN can send email over SMTP.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1071.003
Mail Protocols
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1071.004
DNS
CampaignCutting Edge

During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic.

T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1071.004
DNS
GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

T1071.004
DNS
GroupAPT18

APT18 uses DNS for C2 communications.

T1071.004
DNS
GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1071.004
DNS
GroupTropic Trooper

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.