Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1098.007 Additional Local or Domain Groups |
MalwareSMOKEDHAM | SMOKEDHAM has added user accounts to local Admin groups. |
| T1098.007 Additional Local or Domain Groups |
MalwareServHelper | ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups. |
| T1098.007 Additional Local or Domain Groups |
ToolNet | The `net localgroup` and `net group` commands in Net can be used to add existing users to local and domain groups. |
| T1102 Web Service |
CampaignOperation Spalax | During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads. |
| T1102 Web Service |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1102 Web Service |
CampaignC0017 | During C0017, APT41 used the Cloudflare services for C2 communications. |
| T1102 Web Service |
CampaignC0027 | During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee. |
| T1102 Web Service |
GroupEXOTIC LILY | EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads. |
| T1102 Web Service |
GroupAPT32 | APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1102 Web Service |
GroupFIN6 | FIN6 has used Pastebin and Google Storage to host content for their operations. |
| T1102 Web Service |
GroupGamaredon Group | Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system. |
| T1102 Web Service |
GroupTeamTNT | TeamTNT has leveraged iplogger.org to send collected data back to C2. |
| T1102 Web Service |
GroupMustang Panda | Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads. |
| T1102 Web Service |
GroupRocke | Rocke has used Pastebin, Gitee, and GitLab for Command and Control. |
| T1102 Web Service |
GroupTurla | Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications. |
| T1102 Web Service |
GroupRedCurl | RedCurl has used web services to download malicious files. |
| T1102 Web Service |
GroupLazyScripter | LazyScripter has used GitHub to host its payloads to operate spam campaigns. |
| T1102 Web Service |
GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1102 Web Service |
GroupFox Kitten | Fox Kitten has used Amazon Web Services to host C2. |
| T1102 Web Service |
GroupInception | Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe. |
| T1102 Web Service |
GroupVOID MANTICORE | VOID MANTICORE has utilized Telegram API for C2. |
| T1102 Web Service |
GroupFIN8 | FIN8 has used |
| T1102 Web Service |
MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| T1102 Web Service |
MalwareBRICKSTORM | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications. |
| T1102 Web Service |
MalwareSharpStage | SharpStage has used a legitimate web service for evading detection. |
| T1102 Web Service |
MalwareNETWIRE | NETWIRE has used web services including Paste.ee to host payloads. |
| T1102 Web Service |
MalwareBADHATCH | BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels. |
| T1102 Web Service |
MalwareDropBook | DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions. |
| T1102 Web Service |
MalwareShrinkLocker | ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1102 Web Service |
MalwareHildegard | Hildegard has downloaded scripts from GitHub. |
| T1102 Web Service |
MalwareSnip3 | Snip3 can download additional payloads from web services including Pastebin and top4top. |
| T1102 Web Service |
MalwareGuLoader | GuLoader has the ability to download malware from Google Drive. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1102 Web Service |
MalwareRaspberry Robin | Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers. |
| T1102 Web Service |
MalwareDoki | Doki has used the dogechain.info API to generate a C2 address. |
| T1102 Web Service |
MalwareNightdoor | Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1102 Web Service |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell. |
| T1102 Web Service |
MalwareSocGholish | SocGholish has used Amazon Web Services to host second-stage servers. |
| T1102 Web Service |
MalwareDarkTortilla | DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin. |
| T1102 Web Service |
MalwarePureCrypter | PureCrypter can use Telegram or Discord to send infection status messages. |
| T1102 Web Service |
MalwareLatrodectus | Latrodectus has used Google Firebase to download malicious installation scripts. |
| T1102 Web Service |
MalwareCharmPower | CharmPower can download additional modules from actor-controlled Amazon S3 buckets. |
| T1102 Web Service |
MalwareSMOKEDHAM | SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1102 Web Service |
MalwareRedLine Stealer | RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads. |
| T1102 Web Service |
MalwareSibot | Sibot has used a legitimate compromised website to download DLLs to the victim's machine. |
| T1102 Web Service |
MalwareBazar | Bazar downloads have been hosted on Google Docs. |
| T1102 Web Service |
MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| T1102 Web Service |
MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| T1102 Web Service |
MalwareMOPSLED | MOPSLED can use third-party web services such as GitHub and Google Drive for C2. |
| T1102 Web Service |
MalwareBoomBox | BoomBox can download files from Dropbox using a hardcoded access token. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.