Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102.002 Bidirectional Communication |
MalwareDOGCALL | DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2. |
| T1102.002 Bidirectional Communication |
MalwareLOWBALL | LOWBALL uses the Dropbox cloud storage service for command and control. |
| T1102.002 Bidirectional Communication |
MalwareKARAE | KARAE can use public cloud-based storage providers for command and control. |
| T1102.002 Bidirectional Communication |
MalwareSLOWDRIFT | SLOWDRIFT uses cloud based services for C2. |
| T1102.002 Bidirectional Communication |
MalwareODAgent | ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. |
| T1102.002 Bidirectional Communication |
MalwareRegDuke | RegDuke can use Dropbox as its C2 server. |
| T1102.002 Bidirectional Communication |
MalwareTRANSLATEXT | TRANSLATEXT has used a Github repository for C2. |
| T1102.002 Bidirectional Communication |
MalwareUBoatRAT | UBoatRAT has used GitHub and a public blog service in Hong Kong for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareKazuar | Kazuar has used compromised WordPress blogs as C2 servers. |
| T1102.002 Bidirectional Communication |
MalwarePOORAIM | POORAIM has used AOL Instant Messenger for C2. |
| T1102.002 Bidirectional Communication |
MalwareCALENDAR | The CALENDAR malware communicates through the use of events in Google Calendar. |
| T1102.002 Bidirectional Communication |
MalwareROKRAT | ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareClambling | Clambling can use Dropbox to download malicious payloads, send commands, and receive information. |
| T1102.002 Bidirectional Communication |
MalwareCreepyDrive | CreepyDrive can use OneDrive for C2. |
| T1102.002 Bidirectional Communication |
MalwareSagerunex | Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants. |
| T1102.002 Bidirectional Communication |
MalwareBLUELIGHT | BLUELIGHT can use different cloud providers for its C2. |
| T1102.002 Bidirectional Communication |
MalwareRogueRobin | RogueRobin has used Google Drive as a Command and Control channel. |
| T1102.002 Bidirectional Communication |
MalwareBoxCaon | BoxCaon has used DropBox for C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareCrutch | Crutch can use Dropbox to receive commands and upload stolen data. |
| T1102.002 Bidirectional Communication |
MalwareGrandoreiro | Grandoreiro can utilize web services including Google sites to send and receive C2 data. |
| T1102.002 Bidirectional Communication |
MalwareOilCheck | OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication. |
| T1102.002 Bidirectional Communication |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages. |
| T1102.002 Bidirectional Communication |
MalwareOilBooster | OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data. |
| T1102.002 Bidirectional Communication |
MalwareRevenge RAT | Revenge RAT used blogpost.com as its primary command and control server during a campaign. |
| T1102.002 Bidirectional Communication |
MalwareLAMEHUG | LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers. |
| T1102.002 Bidirectional Communication |
MalwareCloudDuke | One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators. |
| T1102.002 Bidirectional Communication |
MalwareRIFLESPINE | RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive. |
| T1102.002 Bidirectional Communication |
MalwareBLACKCOFFEE | BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github. |
| T1102.002 Bidirectional Communication |
MalwareComRAT | ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. |
| T1102.002 Bidirectional Communication |
MalwarePowerStallion | PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with |
| T1102.002 Bidirectional Communication |
MalwareCozyCar | CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file. |
| T1102.002 Bidirectional Communication |
MalwareBADNEWS | BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs. |
| T1102.002 Bidirectional Communication |
MalwareGLOOXMAIL | GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol. |
| T1102.002 Bidirectional Communication |
MalwareComnie | Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server. |
| T1102.002 Bidirectional Communication |
MalwareSmall Sieve | Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages. |
| T1102.002 Bidirectional Communication |
ToolEmpire | Empire can use Dropbox and GitHub for C2. |
| T1102.003 One-Way Communication |
CampaignArcaneDoor | ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed. |
| T1102.003 One-Way Communication |
GroupGamaredon Group | Gamaredon Group has used Telegram Messenger content to discover the IP address for C2 communications. |
| T1102.003 One-Way Communication |
GroupLeviathan | Leviathan has received C2 instructions from user profiles created on legitimate websites such as Github and TechNet. |
| T1102.003 One-Way Communication |
MalwareUPSTYLE | UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server. |
| T1102.003 One-Way Communication |
MalwareHAMMERTOSS | The "tDiscoverer" variant of HAMMERTOSS establishes a C2 channel by downloading resources from Web services like Twitter and GitHub. HAMMERTOSS binaries contain an algorithm that generates a different Twitter handle for the malware to check for instructions every day. |
| T1102.003 One-Way Communication |
MalwareEVILNUM | EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2. |
| T1102.003 One-Way Communication |
MalwareSagerunex | Sagerunex has used web services such as Twitter for command and control purposes. |
| T1102.003 One-Way Communication |
MalwareMetamorfo | Metamorfo has downloaded a zip file for execution on the system. |
| T1102.003 One-Way Communication |
MalwareOnionDuke | OnionDuke uses Twitter as a backup C2. |
| T1104 Multi-Stage Channels |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2. |
| T1104 Multi-Stage Channels |
GroupAPT3 | An APT3 downloader first establishes a SOCKS5 connection to 192.157.198[.]103 using TCP port 1913; once the server response is verified, it then requests a connection to 192.184.60[.]229 on TCP port 81. |
| T1104 Multi-Stage Channels |
GroupAPT41 | APT41 used the storescyncsvc.dll BEACON backdoor to download a secondary backdoor. |
| T1104 Multi-Stage Channels |
GroupMuddyWater | MuddyWater has used one C2 to obtain enumeration scripts and monitor web logs, but a different C2 to send data back. |
| T1104 Multi-Stage Channels |
GroupLazarus Group | Lazarus Group has used multi-stage malware components that inject later stages into separate processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.