Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102 Web Service |
Toolngrok | ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains. |
| T1102 Web Service |
ToolBrute Ratel C4 | Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams. |
| T1102 Web Service |
MalwareKali365 | Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users. |
| T1102.001 Dead Drop Resolver |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged a GitHub repository to host icon files containing the command and control URL. |
| T1102.001 Dead Drop Resolver |
CampaignC0017 | During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign. |
| T1102.001 Dead Drop Resolver |
GroupKimsuky | Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.001 Dead Drop Resolver |
GroupPatchwork | Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites. |
| T1102.001 Dead Drop Resolver |
GroupAPT41 | APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet. |
| T1102.001 Dead Drop Resolver |
GroupRocke | Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware. |
| T1102.001 Dead Drop Resolver |
GroupBRONZE BUTLER | BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads. |
| T1102.001 Dead Drop Resolver |
GroupRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. |
| T1102.001 Dead Drop Resolver |
MalwareTsundere Botnet | Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1102.001 Dead Drop Resolver |
MalwarePolyglotDuke | PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL. |
| T1102.001 Dead Drop Resolver |
MalwareTRANSLATEXT | TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.001 Dead Drop Resolver |
MalwareMiniDuke | Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1102.001 Dead Drop Resolver |
MalwareJavali | Javali can read C2 information from Google Documents and YouTube. |
| T1102.001 Dead Drop Resolver |
MalwarePlugX | PlugX uses Pastebin to store C2 addresses. |
| T1102.001 Dead Drop Resolver |
MalwareXbash | Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list. |
| T1102.001 Dead Drop Resolver |
MalwareKEYPLUG | The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums. |
| T1102.001 Dead Drop Resolver |
MalwareCharmPower | CharmPower can retrieve C2 domain information from actor-controlled S3 buckets. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1102.001 Dead Drop Resolver |
MalwareMetamorfo | Metamorfo has used YouTube to store and hide C&C server domains. |
| T1102.001 Dead Drop Resolver |
MalwareRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
| T1102.001 Dead Drop Resolver |
MalwareGrandoreiro | Grandoreiro can obtain C2 information from Google Docs. |
| T1102.001 Dead Drop Resolver |
MalwareMOPSLED | MOPSLED has the ability to retrieve a C2 address from a dead drop URL. |
| T1102.001 Dead Drop Resolver |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server. |
| T1102.001 Dead Drop Resolver |
MalwareBADNEWS | BADNEWS collects C2 information via a dead drop resolver. |
| T1102.001 Dead Drop Resolver |
MalwareAstaroth | Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook. |
| T1102.001 Dead Drop Resolver |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1102.002 Bidirectional Communication |
CampaignOperation Ghost | For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers. |
| T1102.002 Bidirectional Communication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had communicated to both Dropbox and Pastebin. |
| T1102.002 Bidirectional Communication |
GroupKimsuky | Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information. |
| T1102.002 Bidirectional Communication |
GroupMuddyWater | MuddyWater has used web services including OneHub to distribute remote access tools. |
| T1102.002 Bidirectional Communication |
GroupGamaredon Group | Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain. |
| T1102.002 Bidirectional Communication |
GroupFIN7 | FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2. |
| T1102.002 Bidirectional Communication |
GroupSandworm Team | Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1102.002 Bidirectional Communication |
GroupAPT39 | APT39 has communicated with C2 through files uploaded to and downloaded from DropBox. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1102.002 Bidirectional Communication |
GroupCarbanak | Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2. |
| T1102.002 Bidirectional Communication |
GroupPOLONIUM | POLONIUM has used OneDrive and DropBox for C2. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1102.002 Bidirectional Communication |
GroupAPT28 | APT28 has used Google Drive for C2. |
| T1102.002 Bidirectional Communication |
GroupAPT12 | APT12 has used blogs and WordPress for C2 infrastructure. |
| T1102.002 Bidirectional Communication |
GroupLazarus Group | Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories. |
| T1102.002 Bidirectional Communication |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for C2. |
| T1102.002 Bidirectional Communication |
GroupMagic Hound | Magic Hound malware can use a SOAP Web service to communicate with its C2 server. |
| T1102.002 Bidirectional Communication |
MalwareOrz | Orz has used Technet and Pastebin web pages for command and control. |
| T1102.002 Bidirectional Communication |
Malwareyty | yty communicates to the C2 server by retrieving a Google Doc. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.