Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1105 Ingress Tool Transfer |
GroupDragonfly | Dragonfly has copied and installed tools for operations once in the victim environment. |
| T1105 Ingress Tool Transfer |
GroupEvilnum | Evilnum can deploy additional components or tools as needed. |
| T1105 Ingress Tool Transfer |
GroupGorgon Group | Gorgon Group malware can download additional files from C2 servers. |
| T1105 Ingress Tool Transfer |
GroupmenuPass | menuPass has installed updates and new malware on victims. |
| T1105 Ingress Tool Transfer |
GroupAPT32 | APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors. |
| T1105 Ingress Tool Transfer |
GroupHAFNIUM | HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1105 Ingress Tool Transfer |
GroupStorm-1811 | Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices. |
| T1105 Ingress Tool Transfer |
GroupTeamTNT | TeamTNT has the |
| T1105 Ingress Tool Transfer |
GroupFIN7 | FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload. |
| T1105 Ingress Tool Transfer |
GroupSandworm Team | Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1105 Ingress Tool Transfer |
GroupAPT18 | APT18 can upload a file to the victim’s machine. |
| T1105 Ingress Tool Transfer |
GroupAndariel | Andariel has downloaded additional tools and malware onto compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupSidewinder | Sidewinder has used LNK files to download remote files to the victim's network. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1105 Ingress Tool Transfer |
GroupZIRCONIUM | ZIRCONIUM has used tools to download malicious files to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupRocke | Rocke used malware to download additional malicious files to the target system. |
| T1105 Ingress Tool Transfer |
GroupScattered Spider | Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers. |
| T1105 Ingress Tool Transfer |
GroupAPT39 | APT39 has downloaded tools to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupTA2541 | TA2541 has used malicious scripts and macros with the ability to download additional payloads. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1105 Ingress Tool Transfer |
GroupMoses Staff | Moses Staff has downloaded and installed web shells to following path |
| T1105 Ingress Tool Transfer |
GroupOilRig | OilRig had downloaded remote files onto victim infrastructure. |
| T1105 Ingress Tool Transfer |
GroupTropic Trooper | Tropic Trooper has used a delivered trojan to download additional files. |
| T1105 Ingress Tool Transfer |
GroupAquatic Panda | Aquatic Panda has downloaded additional malware onto compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupKe3chang | Ke3chang has used tools to download files to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupConfucius | Confucius has downloaded additional files and payloads onto a compromised host following initial access. |
| T1105 Ingress Tool Transfer |
GroupLeviathan | Leviathan has downloaded additional scripts and files from adversary-controlled servers. |
| T1105 Ingress Tool Transfer |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads. |
| T1105 Ingress Tool Transfer |
GroupTurla | Turla has used shellcode to download Meterpreter after compromising a victim. |
| T1105 Ingress Tool Transfer |
GroupTA505 | TA505 has downloaded additional malware to execute on victim systems. |
| T1105 Ingress Tool Transfer |
GroupBITTER | BITTER has downloaded additional malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1105 Ingress Tool Transfer |
GroupCinnamon Tempest | Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupChimera | Chimera has remotely copied tools and malware onto targeted systems. |
| T1105 Ingress Tool Transfer |
GroupMedusa Group | Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools. |
| T1105 Ingress Tool Transfer |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget). |
| T1105 Ingress Tool Transfer |
GroupTA551 | TA551 has retrieved DLLs and installer binaries for malware execution from C2. |
| T1105 Ingress Tool Transfer |
GroupBackdoorDiplomacy | BackdoorDiplomacy has downloaded additional files and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupDarkhotel | Darkhotel has used first-stage payloads that download additional malware from C2 servers. |
| T1105 Ingress Tool Transfer |
GroupLazyScripter | LazyScripter had downloaded additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
GroupWindshift | Windshift has used tools to deploy additional payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupVolatile Cedar | Volatile Cedar can deploy additional tools. |
| T1105 Ingress Tool Transfer |
GroupWhitefly | Whitefly has the ability to download additional tools from the C2. |
| T1105 Ingress Tool Transfer |
GroupLuminousMoth | LuminousMoth has downloaded additional malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1105 Ingress Tool Transfer |
GroupMetador | Metador has downloaded tools and malware onto a compromised system. |
| T1105 Ingress Tool Transfer |
GroupFox Kitten | Fox Kitten has downloaded additional tools including PsExec directly to endpoints. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.