Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
GroupAPT-C-36 | APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened. |
| T1105 Ingress Tool Transfer |
GroupWinnti Group | Winnti Group has downloaded an auxiliary program named ff.exe to infected machines. |
| T1105 Ingress Tool Transfer |
GroupTonto Team | Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupINC Ransom | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. |
| T1105 Ingress Tool Transfer |
GroupSilence | Silence has downloaded additional modules and malware to victim’s machines. |
| T1105 Ingress Tool Transfer |
GroupCobalt Group | Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files. |
| T1105 Ingress Tool Transfer |
GroupWizard Spider | Wizard Spider can transfer malicious payloads such as ransomware to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupMolerats | Molerats used executables to download malicious files from different sources. |
| T1105 Ingress Tool Transfer |
GroupIndigoZebra | IndigoZebra has downloaded additional files and tools from its C2 server. |
| T1105 Ingress Tool Transfer |
GroupMoonstone Sleet | Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems. |
| T1105 Ingress Tool Transfer |
GroupVOID MANTICORE | VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website. |
| T1105 Ingress Tool Transfer |
GroupPlay | Play has used Cobalt Strike to download files to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupHEXANE | HEXANE has downloaded additional payloads and malicious scripts onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupDaggerfly | Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines. |
| T1105 Ingress Tool Transfer |
GroupRancor | Rancor has downloaded additional malware, including by using certutil. |
| T1105 Ingress Tool Transfer |
GroupWIRTE | WIRTE has downloaded PowerShell code from the C2 server to be executed. |
| T1105 Ingress Tool Transfer |
GroupPLATINUM | PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1105 Ingress Tool Transfer |
GroupAjax Security Team | Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system. |
| T1105 Ingress Tool Transfer |
GroupThreat Group-3390 | Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host . |
| T1105 Ingress Tool Transfer |
GroupAPT33 | APT33 has downloaded additional files and programs from its C2 server. |
| T1105 Ingress Tool Transfer |
GroupFIN8 | FIN8 has used remote code execution to download subsequent payloads. |
| T1105 Ingress Tool Transfer |
GroupFIN13 | FIN13 has downloaded additional tools and malware to compromised systems. |
| T1105 Ingress Tool Transfer |
GroupNomadic Octopus | Nomadic Octopus has used malicious macros to download additional files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareTrickBot | TrickBot downloads several additional files and saves them to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarePowerDuke | PowerDuke has a command to download a file. |
| T1105 Ingress Tool Transfer |
MalwareBLINDINGCAN | BLINDINGCAN has downloaded files to a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can download files. |
| T1105 Ingress Tool Transfer |
MalwareRCSession | RCSession has the ability to drop additional files to an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareQuietSieve | QuietSieve can download and execute payloads on a target host. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1105 Ingress Tool Transfer |
MalwareBRICKSTORM | BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareAmadey | Amadey can download and execute files to further infect a host machine with additional malware. |
| T1105 Ingress Tool Transfer |
MalwareNICECURL | NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`. |
| T1105 Ingress Tool Transfer |
MalwareOrz | Orz can download files onto the victim. |
| T1105 Ingress Tool Transfer |
MalwareNOKKI | NOKKI has downloaded a remote module for execution. |
| T1105 Ingress Tool Transfer |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can download additional modules from C2. |
| T1105 Ingress Tool Transfer |
MalwareDOGCALL | DOGCALL can download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDowndelph | After downloading its main config file, Downdelph downloads multiple payloads from C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareSEASHARPEE | SEASHARPEE can download remote files onto victims. |
| T1105 Ingress Tool Transfer |
MalwarePOWRUNER | POWRUNER can download or upload files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareTDTESS | TDTESS has a command to download and execute an additional file. |
| T1105 Ingress Tool Transfer |
MalwareSharpStage | SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1105 Ingress Tool Transfer |
MalwareSardonic | Sardonic has the ability to upload additional malicious files to a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareSmoke Loader | Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins. |
| T1105 Ingress Tool Transfer |
MalwareMisdat | Misdat is capable of downloading files from the C2. |
| T1105 Ingress Tool Transfer |
MalwarereGeorg | reGeorg has the ability to download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareEmissary | Emissary has the capability to download files from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareExaramel for Linux | Exaramel for Linux has a command to download a file from and to a remote C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.