ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
GroupAPT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

T1105
Ingress Tool Transfer
GroupWinnti Group

Winnti Group has downloaded an auxiliary program named ff.exe to infected machines.

T1105
Ingress Tool Transfer
GroupTonto Team

Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1105
Ingress Tool Transfer
GroupINC Ransom

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.

T1105
Ingress Tool Transfer
GroupSilence

Silence has downloaded additional modules and malware to victim’s machines.

T1105
Ingress Tool Transfer
GroupCobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

T1105
Ingress Tool Transfer
GroupWizard Spider

Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.

T1105
Ingress Tool Transfer
GroupMolerats

Molerats used executables to download malicious files from different sources.

T1105
Ingress Tool Transfer
GroupIndigoZebra

IndigoZebra has downloaded additional files and tools from its C2 server.

T1105
Ingress Tool Transfer
GroupMoonstone Sleet

Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.

T1105
Ingress Tool Transfer
GroupVOID MANTICORE

VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.

T1105
Ingress Tool Transfer
GroupPlay

Play has used Cobalt Strike to download files to compromised machines.

T1105
Ingress Tool Transfer
GroupHEXANE

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.

T1105
Ingress Tool Transfer
GroupDaggerfly

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.

T1105
Ingress Tool Transfer
GroupRancor

Rancor has downloaded additional malware, including by using certutil.

T1105
Ingress Tool Transfer
GroupWIRTE

WIRTE has downloaded PowerShell code from the C2 server to be executed.

T1105
Ingress Tool Transfer
GroupPLATINUM

PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1105
Ingress Tool Transfer
GroupAjax Security Team

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.

T1105
Ingress Tool Transfer
GroupThreat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .

T1105
Ingress Tool Transfer
GroupAPT33

APT33 has downloaded additional files and programs from its C2 server.

T1105
Ingress Tool Transfer
GroupFIN8

FIN8 has used remote code execution to download subsequent payloads.

T1105
Ingress Tool Transfer
GroupFIN13

FIN13 has downloaded additional tools and malware to compromised systems.

T1105
Ingress Tool Transfer
GroupNomadic Octopus

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.

T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1105
Ingress Tool Transfer
MalwarePowerDuke

PowerDuke has a command to download a file.

T1105
Ingress Tool Transfer
MalwareBLINDINGCAN

BLINDINGCAN has downloaded files to a victim machine.

T1105
Ingress Tool Transfer
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can download files.

T1105
Ingress Tool Transfer
MalwareRCSession

RCSession has the ability to drop additional files to an infected machine.

T1105
Ingress Tool Transfer
MalwareQuietSieve

QuietSieve can download and execute payloads on a target host.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1105
Ingress Tool Transfer
MalwareBRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.

T1105
Ingress Tool Transfer
MalwareAmadey

Amadey can download and execute files to further infect a host machine with additional malware.

T1105
Ingress Tool Transfer
MalwareNICECURL

NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.

T1105
Ingress Tool Transfer
MalwareOrz

Orz can download files onto the victim.

T1105
Ingress Tool Transfer
MalwareNOKKI

NOKKI has downloaded a remote module for execution.

T1105
Ingress Tool Transfer
MalwareBackdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.

T1105
Ingress Tool Transfer
MalwareDOGCALL

DOGCALL can download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDowndelph

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.

T1105
Ingress Tool Transfer
MalwareSEASHARPEE

SEASHARPEE can download remote files onto victims.

T1105
Ingress Tool Transfer
MalwarePOWRUNER

POWRUNER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
MalwareTDTESS

TDTESS has a command to download and execute an additional file.

T1105
Ingress Tool Transfer
MalwareSharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1105
Ingress Tool Transfer
MalwareSardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.

T1105
Ingress Tool Transfer
MalwareSmoke Loader

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.

T1105
Ingress Tool Transfer
MalwareMisdat

Misdat is capable of downloading files from the C2.

T1105
Ingress Tool Transfer
MalwarereGeorg

reGeorg has the ability to download files to targeted systems.

T1105
Ingress Tool Transfer
MalwareEmissary

Emissary has the capability to download files from the C2 server.

T1105
Ingress Tool Transfer
MalwareExaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.