Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.003 Multi-hop Proxy |
MalwareUroburos | Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network. |
| T1090.003 Multi-hop Proxy |
MalwareAttor | |
| T1090.003 Multi-hop Proxy |
MalwareKobalos | Kobalos can chain together multiple compromised machines as proxies to reach their final targets. |
| T1090.003 Multi-hop Proxy |
MalwareCyclops Blink | Cyclops Blink has used Tor nodes for C2 traffic. |
| T1090.003 Multi-hop Proxy |
MalwareNKAbuse | NKAbuse has abused the NKN public blockchain protocol for its C2 communications. |
| T1090.003 Multi-hop Proxy |
MalwareIndustroyer | Industroyer used Tor nodes for C2. |
| T1090.003 Multi-hop Proxy |
MalwareDridex | Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareDok | |
| T1090.003 Multi-hop Proxy |
MalwareMacSpy | |
| T1090.003 Multi-hop Proxy |
ToolFRP | The FRP client can be configured to connect to the server through a proxy. |
| T1090.003 Multi-hop Proxy |
ToolAsyncRAT | |
| T1090.003 Multi-hop Proxy |
ToolTor | Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination. |
| T1090.003 Multi-hop Proxy |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network. |
| T1090.003 Multi-hop Proxy |
GroupShinyHunters | ShinyHunters has used Tor to host their DLS. |
| T1090.004 Domain Fronting |
GroupAPT29 | APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic. |
| T1090.004 Domain Fronting |
MalwareSMOKEDHAM | SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain. |
| T1090.004 Domain Fronting |
MalwareCobalt Strike | Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting. |
| T1090.004 Domain Fronting |
Toolmeek | meek uses Domain Fronting to disguise the destination of network traffic as another server that is hosted in the same Content Delivery Network (CDN) as the intended destination. |
| T1090.004 Domain Fronting |
ToolMythic | Mythic supports domain fronting via custom request headers. |
| T1091 Replication Through Removable Media |
GroupGamaredon Group | Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host. |
| T1091 Replication Through Removable Media |
GroupFIN7 | FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands. |
| T1091 Replication Through Removable Media |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could spread through USB connections. |
| T1091 Replication Through Removable Media |
GroupTropic Trooper | Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine. |
| T1091 Replication Through Removable Media |
GroupAoqin Dragon | Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment. |
| T1091 Replication Through Removable Media |
GroupDarkhotel | Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| T1091 Replication Through Removable Media |
GroupLuminousMoth | LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| T1091 Replication Through Removable Media |
GroupAPT28 | APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted. |
| T1091 Replication Through Removable Media |
MalwareStuxnet | Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability. |
| T1091 Replication Through Removable Media |
MalwareUrsnif | Ursnif has copied itself to and infected removable drives for propagation. |
| T1091 Replication Through Removable Media |
MalwareCrimson | Crimson can spread across systems by infecting removable media. |
| T1091 Replication Through Removable Media |
MalwareAgent.btz | Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware. |
| T1091 Replication Through Removable Media |
MalwareRaspberry Robin | Raspberry Robin has historically used infected USB media to spread to new victims. |
| T1091 Replication Through Removable Media |
MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1091 Replication Through Removable Media |
MalwarePlugX | PlugX has copied itself to infected removable drives for propagation to other victim devices. |
| T1091 Replication Through Removable Media |
MalwareDustySky | DustySky searches for removable media and duplicates itself onto it. |
| T1091 Replication Through Removable Media |
MalwareUSBferry | USBferry can copy its installer to attached USB storage devices. |
| T1091 Replication Through Removable Media |
MalwareUnknown Logger | Unknown Logger is capable of spreading to USB devices. |
| T1091 Replication Through Removable Media |
MalwareUSBStealer | USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. |
| T1091 Replication Through Removable Media |
MalwareSHIPSHAPE | APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document. |
| T1091 Replication Through Removable Media |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on removable drives. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1091 Replication Through Removable Media |
MalwarenjRAT | njRAT can be configured to spread via removable drives. |
| T1091 Replication Through Removable Media |
MalwareHIUPAN | HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device. |
| T1091 Replication Through Removable Media |
MalwareANDROMEDA | ANDROMEDA has been spread via infected USB keys. |
| T1091 Replication Through Removable Media |
MalwareQakBot | QakBot has the ability to use removable drives to spread through compromised networks. |
| T1091 Replication Through Removable Media |
MalwareH1N1 | H1N1 has functionality to copy itself to removable media. |
| T1091 Replication Through Removable Media |
MalwareFlame | Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
| T1092 Communication Through Removable Media |
GroupAPT28 | APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted. |
| T1092 Communication Through Removable Media |
MalwareUSBStealer | USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.