ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
CampaignKV Botnet Activity

KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.

T1095
Non-Application Layer Protocol
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations.

T1095
Non-Application Layer Protocol
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

T1095
Non-Application Layer Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications.

T1095
Non-Application Layer Protocol
CampaignC0021

During C0021, the threat actors used TCP for some C2 communications.

T1095
Non-Application Layer Protocol
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control.

T1095
Non-Application Layer Protocol
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom protocol for command and control.

T1095
Non-Application Layer Protocol
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel.

T1095
Non-Application Layer Protocol
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1095
Non-Application Layer Protocol
GroupHAFNIUM

HAFNIUM has used TCP for C2.

T1095
Non-Application Layer Protocol
GroupFIN6

FIN6 has used Metasploit Bind and Reverse TCP stagers.

T1095
Non-Application Layer Protocol
GroupGamaredon Group

Gamaredon Group has used SOCKS5 over port 9050 for C2 communication.

T1095
Non-Application Layer Protocol
GroupMustang Panda

Mustang Panda has utilized TCP-based reverse shells using cmd.exe.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1095
Non-Application Layer Protocol
GroupBITTER

BITTER has used TCP for C2 communications.

T1095
Non-Application Layer Protocol
GroupBackdoorDiplomacy

BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.

T1095
Non-Application Layer Protocol
GroupEmber Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.

T1095
Non-Application Layer Protocol
GroupToddyCat

ToddyCat has used a passive backdoor that receives commands with UDP packets.

T1095
Non-Application Layer Protocol
GroupMetador

Metador has used TCP for C2.

T1095
Non-Application Layer Protocol
GroupPLATINUM

PLATINUM has used the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel for command and control.

T1095
Non-Application Layer Protocol
Malwarecd00r

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol using a type, length, value format over TCP.

T1095
Non-Application Layer Protocol
MalwareCOATHANGER

COATHANGER uses ICMP for transmitting configuration information to and from its command and control server.

T1095
Non-Application Layer Protocol
MalwareSardonic

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1095
Non-Application Layer Protocol
MalwareMisdat

Misdat network traffic communicates over a raw socket.

T1095
Non-Application Layer Protocol
MalwarereGeorg

reGeorg can tunnel TCP sessions into targeted networks.

T1095
Non-Application Layer Protocol
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using SOCKS.

T1095
Non-Application Layer Protocol
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket.

T1095
Non-Application Layer Protocol
MalwareInvisibleFerret

InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000.

T1095
Non-Application Layer Protocol
MalwareNebulae

Nebulae can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareTONESHELL

TONESHELL has utilized TCP-based reverse shells.

T1095
Non-Application Layer Protocol
MalwareRainyDay

RainyDay can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareJ-magic

J-magic can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareAria-body

Aria-body has used TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareCrimson

Crimson uses a custom TCP protocol for C2.

T1095
Non-Application Layer Protocol
MalwareSystemBC

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1095
Non-Application Layer Protocol
MalwarePingPull

PingPull variants have the ability to communicate with C2 servers using ICMP or TCP.

T1095
Non-Application Layer Protocol
MalwareMafalda

Mafalda can use raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareUmbreon

Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate.

T1095
Non-Application Layer Protocol
MalwareAuTo Stealer

AuTo Stealer can use TCP to communicate with command and control servers.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1095
Non-Application Layer Protocol
MalwareSUGARUSH

SUGARUSH has used TCP for C2.

T1095
Non-Application Layer Protocol
MalwareCuckoo Stealer

Cuckoo Stealer can use sockets for communications to its C2 server.

T1095
Non-Application Layer Protocol
MalwareInvisiMole

InvisiMole has used TCP to download additional modules.

T1095
Non-Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can establish a TCP connection as part of its initial connection to the C2.

T1095
Non-Application Layer Protocol
MalwareRegin

The Regin malware platform can use ICMP to communicate between infected computers.

T1095
Non-Application Layer Protocol
MalwareREPTILE

REPTILE can communicate using TLS over raw TCP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.