ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1105
Ingress Tool Transfer
GroupDragonfly

Dragonfly has copied and installed tools for operations once in the victim environment.

T1105
Ingress Tool Transfer
GroupEvilnum

Evilnum can deploy additional components or tools as needed.

T1105
Ingress Tool Transfer
GroupGorgon Group

Gorgon Group malware can download additional files from C2 servers.

T1105
Ingress Tool Transfer
GroupmenuPass

menuPass has installed updates and new malware on victims.

T1105
Ingress Tool Transfer
GroupAPT32

APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.

T1105
Ingress Tool Transfer
GroupHAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1105
Ingress Tool Transfer
GroupStorm-1811

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1105
Ingress Tool Transfer
GroupTeamTNT

TeamTNT has the curl and wget commands as well as batch scripts to download new tools.

T1105
Ingress Tool Transfer
GroupFIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.

T1105
Ingress Tool Transfer
GroupSandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1105
Ingress Tool Transfer
GroupAPT18

APT18 can upload a file to the victim’s machine.

T1105
Ingress Tool Transfer
GroupAndariel

Andariel has downloaded additional tools and malware onto compromised hosts.

T1105
Ingress Tool Transfer
GroupSidewinder

Sidewinder has used LNK files to download remote files to the victim's network.

T1105
Ingress Tool Transfer
GroupMustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.

T1105
Ingress Tool Transfer
GroupZIRCONIUM

ZIRCONIUM has used tools to download malicious files to compromised hosts.

T1105
Ingress Tool Transfer
GroupRocke

Rocke used malware to download additional malicious files to the target system.

T1105
Ingress Tool Transfer
GroupScattered Spider

Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.

T1105
Ingress Tool Transfer
GroupAPT39

APT39 has downloaded tools to compromised hosts.

T1105
Ingress Tool Transfer
GroupTA2541

TA2541 has used malicious scripts and macros with the ability to download additional payloads.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1105
Ingress Tool Transfer
GroupMoses Staff

Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.

T1105
Ingress Tool Transfer
GroupOilRig

OilRig had downloaded remote files onto victim infrastructure.

T1105
Ingress Tool Transfer
GroupTropic Trooper

Tropic Trooper has used a delivered trojan to download additional files.

T1105
Ingress Tool Transfer
GroupAquatic Panda

Aquatic Panda has downloaded additional malware onto compromised hosts.

T1105
Ingress Tool Transfer
GroupKe3chang

Ke3chang has used tools to download files to compromised machines.

T1105
Ingress Tool Transfer
GroupConfucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1105
Ingress Tool Transfer
GroupLeviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.

T1105
Ingress Tool Transfer
GroupWinter Vivern

Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.

T1105
Ingress Tool Transfer
GroupTurla

Turla has used shellcode to download Meterpreter after compromising a victim.

T1105
Ingress Tool Transfer
GroupTA505

TA505 has downloaded additional malware to execute on victim systems.

T1105
Ingress Tool Transfer
GroupBITTER

BITTER has downloaded additional malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1105
Ingress Tool Transfer
GroupCinnamon Tempest

Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.

T1105
Ingress Tool Transfer
GroupChimera

Chimera has remotely copied tools and malware onto targeted systems.

T1105
Ingress Tool Transfer
GroupMedusa Group

Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.

T1105
Ingress Tool Transfer
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).

T1105
Ingress Tool Transfer
GroupTA551

TA551 has retrieved DLLs and installer binaries for malware execution from C2.

T1105
Ingress Tool Transfer
GroupBackdoorDiplomacy

BackdoorDiplomacy has downloaded additional files and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupDarkhotel

Darkhotel has used first-stage payloads that download additional malware from C2 servers.

T1105
Ingress Tool Transfer
GroupLazyScripter

LazyScripter had downloaded additional tools to a compromised host.

T1105
Ingress Tool Transfer
GroupWindshift

Windshift has used tools to deploy additional payloads to compromised hosts.

T1105
Ingress Tool Transfer
GroupVolatile Cedar

Volatile Cedar can deploy additional tools.

T1105
Ingress Tool Transfer
GroupWhitefly

Whitefly has the ability to download additional tools from the C2.

T1105
Ingress Tool Transfer
GroupLuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1105
Ingress Tool Transfer
GroupMetador

Metador has downloaded tools and malware onto a compromised system.

T1105
Ingress Tool Transfer
GroupFox Kitten

Fox Kitten has downloaded additional tools including PsExec directly to endpoints.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.