Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1104 Multi-Stage Channels |
MalwareJumbledPath | JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices. |
| T1104 Multi-Stage Channels |
MalwareSnip3 | Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1104 Multi-Stage Channels |
MalwareChaos | After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system. |
| T1104 Multi-Stage Channels |
MalwareLatrodectus | Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure. |
| T1104 Multi-Stage Channels |
MalwareUroburos | Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation. |
| T1104 Multi-Stage Channels |
MalwareBazar | The Bazar loader is used to download and execute the Bazar backdoor. |
| T1104 Multi-Stage Channels |
MalwareValak | Valak can download additional modules and malware capable of using separate C2 channels. |
| T1104 Multi-Stage Channels |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines. |
| T1104 Multi-Stage Channels |
MalwareLunarWeb | LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands. |
| T1104 Multi-Stage Channels |
MalwareBACKSPACE | BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignKV Botnet Activity | KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes. |
| T1105 Ingress Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware. |
| T1105 Ingress Tool Transfer |
CampaignFrankenstein | During Frankenstein, the threat actors downloaded files and tools onto a victim machine. |
| T1105 Ingress Tool Transfer |
CampaignRedPenguin | During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignOperation Sharpshooter | During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader. |
| T1105 Ingress Tool Transfer |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1105 Ingress Tool Transfer |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1105 Ingress Tool Transfer |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs. |
| T1105 Ingress Tool Transfer |
CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| T1105 Ingress Tool Transfer |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory. |
| T1105 Ingress Tool Transfer |
CampaignShadowRay | During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
| T1105 Ingress Tool Transfer |
CampaignC0015 | During C0015, the threat actors downloaded additional tools and files onto a compromised network. |
| T1105 Ingress Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access. |
| T1105 Ingress Tool Transfer |
CampaignFunnyDream | During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system. |
| T1105 Ingress Tool Transfer |
CampaignOuter Space | During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure. |
| T1105 Ingress Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server. |
| T1105 Ingress Tool Transfer |
CampaignC0010 | During C0010, UNC3890 actors downloaded tools and malware onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1105 Ingress Tool Transfer |
CampaignNight Dragon | During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems. |
| T1105 Ingress Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors downloaded additional files to the infected system. |
| T1105 Ingress Tool Transfer |
CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
| T1105 Ingress Tool Transfer |
CampaignC0026 | During C0026, the threat actors downloaded malicious payloads onto select compromised hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0027 | During C0027, Scattered Spider downloaded tools using victim organization systems. |
| T1105 Ingress Tool Transfer |
CampaignQuad7 Activity | Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices. |
| T1105 Ingress Tool Transfer |
CampaignCostaRicto | During CostaRicto, the threat actors downloaded malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT38 | APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine. |
| T1105 Ingress Tool Transfer |
GroupIndrik Spider | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupBlackByte | BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites. |
| T1105 Ingress Tool Transfer |
GroupElderwood | The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location. |
| T1105 Ingress Tool Transfer |
GroupSideCopy | SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads. |
| T1105 Ingress Tool Transfer |
GroupGALLIUM | GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN. |
| T1105 Ingress Tool Transfer |
GroupAPT3 | APT3 has a tool that can copy files to remote machines. |
| T1105 Ingress Tool Transfer |
GroupMustard Tempest | Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupKimsuky | Kimsuky has downloaded additional scripts, tools, and malware onto victim systems. |
| T1105 Ingress Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder. |
| T1105 Ingress Tool Transfer |
GroupPatchwork | Patchwork payloads download additional files from the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.