ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1098.007
Additional Local or Domain Groups
MalwareSMOKEDHAM

SMOKEDHAM has added user accounts to local Admin groups.

T1098.007
Additional Local or Domain Groups
MalwareServHelper

ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups.

T1098.007
Additional Local or Domain Groups
ToolNet

The `net localgroup` and `net group` commands in Net can be used to add existing users to local and domain groups.

T1102
Web Service
CampaignOperation Spalax

During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads.

T1102
Web Service
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1102
Web Service
CampaignC0017

During C0017, APT41 used the Cloudflare services for C2 communications.

T1102
Web Service
CampaignC0027

During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee.

T1102
Web Service
GroupEXOTIC LILY

EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads.

T1102
Web Service
GroupAPT32

APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1102
Web Service
GroupFIN6

FIN6 has used Pastebin and Google Storage to host content for their operations.

T1102
Web Service
GroupGamaredon Group

Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system.

T1102
Web Service
GroupTeamTNT

TeamTNT has leveraged iplogger.org to send collected data back to C2.

T1102
Web Service
GroupMustang Panda

Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads.

T1102
Web Service
GroupRocke

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.

T1102
Web Service
GroupTurla

Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications.

T1102
Web Service
GroupRedCurl

RedCurl has used web services to download malicious files.

T1102
Web Service
GroupLazyScripter

LazyScripter has used GitHub to host its payloads to operate spam campaigns.

T1102
Web Service
GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1102
Web Service
GroupFox Kitten

Fox Kitten has used Amazon Web Services to host C2.

T1102
Web Service
GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1102
Web Service
GroupVOID MANTICORE

VOID MANTICORE has utilized Telegram API for C2.

T1102
Web Service
GroupFIN8

FIN8 has used sslip.io, a free IP to domain mapping service that also makes SSL certificate generation easier for traffic encryption, as part of their command and control.

T1102
Web Service
MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

T1102
Web Service
MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1102
Web Service
MalwareSharpStage

SharpStage has used a legitimate web service for evading detection.

T1102
Web Service
MalwareNETWIRE

NETWIRE has used web services including Paste.ee to host payloads.

T1102
Web Service
MalwareBADHATCH

BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels.

T1102
Web Service
MalwareDropBook

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1102
Web Service
MalwareShrinkLocker

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1102
Web Service
MalwareHildegard

Hildegard has downloaded scripts from GitHub.

T1102
Web Service
MalwareSnip3

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1102
Web Service
MalwareGuLoader

GuLoader has the ability to download malware from Google Drive.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1102
Web Service
MalwareRaspberry Robin

Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers.

T1102
Web Service
MalwareDoki

Doki has used the dogechain.info API to generate a C2 address.

T1102
Web Service
MalwareNightdoor

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1102
Web Service
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell.

T1102
Web Service
MalwareSocGholish

SocGholish has used Amazon Web Services to host second-stage servers.

T1102
Web Service
MalwareDarkTortilla

DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin.

T1102
Web Service
MalwarePureCrypter

PureCrypter can use Telegram or Discord to send infection status messages.

T1102
Web Service
MalwareLatrodectus

Latrodectus has used Google Firebase to download malicious installation scripts.

T1102
Web Service
MalwareCharmPower

CharmPower can download additional modules from actor-controlled Amazon S3 buckets.

T1102
Web Service
MalwareSMOKEDHAM

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1102
Web Service
MalwareSibot

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1102
Web Service
MalwareBazar

Bazar downloads have been hosted on Google Docs.

T1102
Web Service
MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

T1102
Web Service
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

T1102
Web Service
MalwareMOPSLED

MOPSLED can use third-party web services such as GitHub and Google Drive for C2.

T1102
Web Service
MalwareBoomBox

BoomBox can download files from Dropbox using a hardcoded access token.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.