ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1104
Multi-Stage Channels
MalwareJumbledPath

JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1104
Multi-Stage Channels
MalwareChaos

After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system.

T1104
Multi-Stage Channels
MalwareLatrodectus

Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure.

T1104
Multi-Stage Channels
MalwareUroburos

Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation.

T1104
Multi-Stage Channels
MalwareBazar

The Bazar loader is used to download and execute the Bazar backdoor.

T1104
Multi-Stage Channels
MalwareValak

Valak can download additional modules and malware capable of using separate C2 channels.

T1104
Multi-Stage Channels
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines.

T1104
Multi-Stage Channels
MalwareLunarWeb

LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands.

T1104
Multi-Stage Channels
MalwareBACKSPACE

BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware.

T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
CampaignKV Botnet Activity

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.

T1105
Ingress Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware.

T1105
Ingress Tool Transfer
CampaignFrankenstein

During Frankenstein, the threat actors downloaded files and tools onto a victim machine.

T1105
Ingress Tool Transfer
CampaignRedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignOperation Sharpshooter

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.

T1105
Ingress Tool Transfer
CampaignOperation Honeybee

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1105
Ingress Tool Transfer
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1105
Ingress Tool Transfer
CampaignCutting Edge

During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1105
Ingress Tool Transfer
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory.

T1105
Ingress Tool Transfer
CampaignShadowRay

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.

T1105
Ingress Tool Transfer
CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

T1105
Ingress Tool Transfer
CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

T1105
Ingress Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.

T1105
Ingress Tool Transfer
CampaignFunnyDream

During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system.

T1105
Ingress Tool Transfer
CampaignOuter Space

During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure.

T1105
Ingress Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.

T1105
Ingress Tool Transfer
CampaignC0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

T1105
Ingress Tool Transfer
CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1105
Ingress Tool Transfer
CampaignNight Dragon

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.

T1105
Ingress Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors downloaded additional files to the infected system.

T1105
Ingress Tool Transfer
CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

T1105
Ingress Tool Transfer
CampaignC0026

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.

T1105
Ingress Tool Transfer
CampaignC0027

During C0027, Scattered Spider downloaded tools using victim organization systems.

T1105
Ingress Tool Transfer
CampaignQuad7 Activity

Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices.

T1105
Ingress Tool Transfer
CampaignCostaRicto

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupAPT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine.

T1105
Ingress Tool Transfer
GroupIndrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupBlackByte

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.

T1105
Ingress Tool Transfer
GroupElderwood

The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location.

T1105
Ingress Tool Transfer
GroupSideCopy

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.

T1105
Ingress Tool Transfer
GroupGALLIUM

GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN.

T1105
Ingress Tool Transfer
GroupAPT3

APT3 has a tool that can copy files to remote machines.

T1105
Ingress Tool Transfer
GroupMustard Tempest

Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts.

T1105
Ingress Tool Transfer
GroupKimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.

T1105
Ingress Tool Transfer
GroupVolt Typhoon

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.

T1105
Ingress Tool Transfer
GroupPatchwork

Patchwork payloads download additional files from the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.