Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
CampaignKV Botnet Activity | KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication. |
| T1095 Non-Application Layer Protocol |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations. |
| T1095 Non-Application Layer Protocol |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2. |
| T1095 Non-Application Layer Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignC0021 | During C0021, the threat actors used TCP for some C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control. |
| T1095 Non-Application Layer Protocol |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom protocol for command and control. |
| T1095 Non-Application Layer Protocol |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel. |
| T1095 Non-Application Layer Protocol |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1095 Non-Application Layer Protocol |
GroupHAFNIUM | HAFNIUM has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
GroupFIN6 | FIN6 has used Metasploit Bind and Reverse TCP stagers. |
| T1095 Non-Application Layer Protocol |
GroupGamaredon Group | Gamaredon Group has used SOCKS5 over port 9050 for C2 communication. |
| T1095 Non-Application Layer Protocol |
GroupMustang Panda | Mustang Panda has utilized TCP-based reverse shells using cmd.exe. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1095 Non-Application Layer Protocol |
GroupBITTER | BITTER has used TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities. |
| T1095 Non-Application Layer Protocol |
GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| T1095 Non-Application Layer Protocol |
GroupToddyCat | ToddyCat has used a passive backdoor that receives commands with UDP packets. |
| T1095 Non-Application Layer Protocol |
GroupMetador | Metador has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
GroupPLATINUM | PLATINUM has used the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel for command and control. |
| T1095 Non-Application Layer Protocol |
Malwarecd00r | cd00r can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareRotaJakiro | RotaJakiro uses a custom binary protocol using a type, length, value format over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareCOATHANGER | COATHANGER uses ICMP for transmitting configuration information to and from its command and control server. |
| T1095 Non-Application Layer Protocol |
MalwareSardonic | Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol. |
| T1095 Non-Application Layer Protocol |
MalwareMisdat | Misdat network traffic communicates over a raw socket. |
| T1095 Non-Application Layer Protocol |
MalwarereGeorg | reGeorg can tunnel TCP sessions into targeted networks. |
| T1095 Non-Application Layer Protocol |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using SOCKS. |
| T1095 Non-Application Layer Protocol |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket. |
| T1095 Non-Application Layer Protocol |
MalwareInvisibleFerret | InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000. |
| T1095 Non-Application Layer Protocol |
MalwareNebulae | Nebulae can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareTONESHELL | TONESHELL has utilized TCP-based reverse shells. |
| T1095 Non-Application Layer Protocol |
MalwareRainyDay | RainyDay can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareNETWIRE | NETWIRE can use TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareJ-magic | J-magic can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareAria-body | Aria-body has used TCP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareCrimson | Crimson uses a custom TCP protocol for C2. |
| T1095 Non-Application Layer Protocol |
MalwareSystemBC | SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries. |
| T1095 Non-Application Layer Protocol |
MalwarePingPull | PingPull variants have the ability to communicate with C2 servers using ICMP or TCP. |
| T1095 Non-Application Layer Protocol |
MalwareMafalda | Mafalda can use raw TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareUmbreon | Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate. |
| T1095 Non-Application Layer Protocol |
MalwareAuTo Stealer | AuTo Stealer can use TCP to communicate with command and control servers. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareSUGARUSH | SUGARUSH has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareCuckoo Stealer | Cuckoo Stealer can use sockets for communications to its C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareInvisiMole | InvisiMole has used TCP to download additional modules. |
| T1095 Non-Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can establish a TCP connection as part of its initial connection to the C2. |
| T1095 Non-Application Layer Protocol |
MalwareRegin | The Regin malware platform can use ICMP to communicate between infected computers. |
| T1095 Non-Application Layer Protocol |
MalwareREPTILE | REPTILE can communicate using TLS over raw TCP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.