ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1090.003
Multi-hop Proxy
MalwareUroburos

Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network.

T1090.003
Multi-hop Proxy
MalwareAttor

Attor has used Tor for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKobalos

Kobalos can chain together multiple compromised machines as proxies to reach their final targets.

T1090.003
Multi-hop Proxy
MalwareCyclops Blink

Cyclops Blink has used Tor nodes for C2 traffic.

T1090.003
Multi-hop Proxy
MalwareNKAbuse

NKAbuse has abused the NKN public blockchain protocol for its C2 communications.

T1090.003
Multi-hop Proxy
MalwareIndustroyer

Industroyer used Tor nodes for C2.

T1090.003
Multi-hop Proxy
MalwareDridex

Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareDok

Dok downloads and installs Tor via homebrew.

T1090.003
Multi-hop Proxy
MalwareMacSpy

MacSpy uses Tor for command and control.

T1090.003
Multi-hop Proxy
ToolFRP

The FRP client can be configured to connect to the server through a proxy.

T1090.003
Multi-hop Proxy
ToolAsyncRAT

AsyncRAT can proxy C2 through a Tor client.

T1090.003
Multi-hop Proxy
ToolTor

Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination.

T1090.003
Multi-hop Proxy
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network.

T1090.003
Multi-hop Proxy
GroupShinyHunters

ShinyHunters has used Tor to host their DLS.

T1090.004
Domain Fronting
GroupAPT29

APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic.

T1090.004
Domain Fronting
MalwareSMOKEDHAM

SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain.

T1090.004
Domain Fronting
MalwareCobalt Strike

Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.

T1090.004
Domain Fronting
Toolmeek

meek uses Domain Fronting to disguise the destination of network traffic as another server that is hosted in the same Content Delivery Network (CDN) as the intended destination.

T1090.004
Domain Fronting
ToolMythic

Mythic supports domain fronting via custom request headers.

T1091
Replication Through Removable Media
GroupGamaredon Group

Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host.

T1091
Replication Through Removable Media
GroupFIN7

FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands.

T1091
Replication Through Removable Media
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could spread through USB connections.

T1091
Replication Through Removable Media
GroupTropic Trooper

Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine.

T1091
Replication Through Removable Media
GroupAoqin Dragon

Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment.

T1091
Replication Through Removable Media
GroupDarkhotel

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

T1091
Replication Through Removable Media
GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1091
Replication Through Removable Media
GroupAPT28

APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted.

T1091
Replication Through Removable Media
MalwareStuxnet

Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability.

T1091
Replication Through Removable Media
MalwareUrsnif

Ursnif has copied itself to and infected removable drives for propagation.

T1091
Replication Through Removable Media
MalwareCrimson

Crimson can spread across systems by infecting removable media.

T1091
Replication Through Removable Media
MalwareAgent.btz

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

T1091
Replication Through Removable Media
MalwareRaspberry Robin

Raspberry Robin has historically used infected USB media to spread to new victims.

T1091
Replication Through Removable Media
MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1091
Replication Through Removable Media
MalwarePlugX

PlugX has copied itself to infected removable drives for propagation to other victim devices.

T1091
Replication Through Removable Media
MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

T1091
Replication Through Removable Media
MalwareUSBferry

USBferry can copy its installer to attached USB storage devices.

T1091
Replication Through Removable Media
MalwareUnknown Logger

Unknown Logger is capable of spreading to USB devices.

T1091
Replication Through Removable Media
MalwareUSBStealer

USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system.

T1091
Replication Through Removable Media
MalwareSHIPSHAPE

APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document.

T1091
Replication Through Removable Media
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on removable drives.

T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1091
Replication Through Removable Media
MalwareHIUPAN

HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device.

T1091
Replication Through Removable Media
MalwareANDROMEDA

ANDROMEDA has been spread via infected USB keys.

T1091
Replication Through Removable Media
MalwareQakBot

QakBot has the ability to use removable drives to spread through compromised networks.

T1091
Replication Through Removable Media
MalwareH1N1

H1N1 has functionality to copy itself to removable media.

T1091
Replication Through Removable Media
MalwareFlame

Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality.

T1092
Communication Through Removable Media
GroupAPT28

APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted.

T1092
Communication Through Removable Media
MalwareUSBStealer

USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim.

T1092
Communication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.