Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareWarzoneRAT | WarzoneRAT can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has downloaded files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareXORIndex Loader | XORIndex Loader has been used to download a malicious payload to include BeaverTail. |
| T1105 Ingress Tool Transfer |
MalwareSmall Sieve | Small Sieve has the ability to download files. |
| T1105 Ingress Tool Transfer |
ToolRemoteUtilities | RemoteUtilities can upload and download files to and from a target machine. |
| T1105 Ingress Tool Transfer |
Toolcertutil | certutil can be used to download files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolShimRatReporter | ShimRatReporter had the ability to download additional payloads. |
| T1105 Ingress Tool Transfer |
ToolSliver | Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the |
| T1105 Ingress Tool Transfer |
ToolSILENTTRINITY | SILENTTRINITY can load additional files and tools, including Mimikatz. |
| T1105 Ingress Tool Transfer |
ToolEmpire | Empire can upload and download to and from a victim machine. |
| T1105 Ingress Tool Transfer |
ToolCSPY Downloader | CSPY Downloader can download additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolCARROTBALL | CARROTBALL has the ability to download and install a remote payload. |
| T1105 Ingress Tool Transfer |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files. |
| T1105 Ingress Tool Transfer |
ToolAsyncRAT | AsyncRAT has the ability to download files including over SFTP. |
| T1105 Ingress Tool Transfer |
ToolBrute Ratel C4 | Brute Ratel C4 can download files to compromised hosts. |
| T1105 Ingress Tool Transfer |
ToolRemcos | Remcos can upload and download files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
ToolMCMD | MCMD can upload additional files to a compromised host. |
| T1105 Ingress Tool Transfer |
ToolDonut | Donut can download and execute previously staged shellcode payloads. |
| T1105 Ingress Tool Transfer |
Toolcmd | cmd can be used to copy files to/from a remotely connected external system. |
| T1105 Ingress Tool Transfer |
Toolesentutl | esentutl can be used to copy files from a given URL. |
| T1105 Ingress Tool Transfer |
ToolKoadic | Koadic can download additional files and tools. |
| T1105 Ingress Tool Transfer |
ToolPupy | Pupy can upload and download to/from a victim machine. |
| T1105 Ingress Tool Transfer |
Toolftp | ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment. |
| T1105 Ingress Tool Transfer |
ToolQuasarRAT | QuasarRAT can download files to the victim’s machine and execute them. |
| T1105 Ingress Tool Transfer |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareCanisterWorm | CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1105 Ingress Tool Transfer |
GroupTeamPCP | TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2. |
| T1105 Ingress Tool Transfer |
GroupShinyHunters | ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment. |
| T1105 Ingress Tool Transfer |
MalwareBADFLICK | BADFLICK has download files from its C2 server. |
| T1106 Native API |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server. |
| T1106 Native API |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`. |
| T1106 Native API |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`. |
| T1106 Native API |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| T1106 Native API |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process. |
| T1106 Native API |
GroupAPT38 | APT38 has used the Windows API to execute code within a victim's system. |
| T1106 Native API |
GroupSideCopy | SideCopy has executed malware by calling the API function `CreateProcessW`. |
| T1106 Native API |
GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| T1106 Native API |
GroupGorgon Group | Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution. |
| T1106 Native API |
GroupmenuPass | menuPass has used native APIs including |
| T1106 Native API |
GroupGamaredon Group | Gamaredon Group malware has used |
| T1106 Native API |
GroupSandworm Team | Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1106 Native API |
GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| T1106 Native API |
GroupHigaisa | Higaisa has called various native OS APIs. |
| T1106 Native API |
GroupTropic Trooper | Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl. |
| T1106 Native API |
GroupBlackTech | BlackTech has used built-in API functions. |
| T1106 Native API |
GroupTurla | Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes. |
| T1106 Native API |
GroupTA505 | TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1106 Native API |
GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.