ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareWarzoneRAT

WarzoneRAT can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has downloaded files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareXORIndex Loader

XORIndex Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareSmall Sieve

Small Sieve has the ability to download files.

T1105
Ingress Tool Transfer
ToolRemoteUtilities

RemoteUtilities can upload and download files to and from a target machine.

T1105
Ingress Tool Transfer
Toolcertutil

certutil can be used to download files from a given URL.

T1105
Ingress Tool Transfer
ToolShimRatReporter

ShimRatReporter had the ability to download additional payloads.

T1105
Ingress Tool Transfer
ToolSliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.

T1105
Ingress Tool Transfer
ToolSILENTTRINITY

SILENTTRINITY can load additional files and tools, including Mimikatz.

T1105
Ingress Tool Transfer
ToolEmpire

Empire can upload and download to and from a victim machine.

T1105
Ingress Tool Transfer
ToolCSPY Downloader

CSPY Downloader can download additional tools to a compromised host.

T1105
Ingress Tool Transfer
ToolCARROTBALL

CARROTBALL has the ability to download and install a remote payload.

T1105
Ingress Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files.

T1105
Ingress Tool Transfer
ToolAsyncRAT

AsyncRAT has the ability to download files including over SFTP.

T1105
Ingress Tool Transfer
ToolBrute Ratel C4

Brute Ratel C4 can download files to compromised hosts.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1105
Ingress Tool Transfer
ToolMCMD

MCMD can upload additional files to a compromised host.

T1105
Ingress Tool Transfer
ToolDonut

Donut can download and execute previously staged shellcode payloads.

T1105
Ingress Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected external system.

T1105
Ingress Tool Transfer
Toolesentutl

esentutl can be used to copy files from a given URL.

T1105
Ingress Tool Transfer
ToolKoadic

Koadic can download additional files and tools.

T1105
Ingress Tool Transfer
ToolPupy

Pupy can upload and download to/from a victim machine.

T1105
Ingress Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1105
Ingress Tool Transfer
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems.

T1105
Ingress Tool Transfer
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure.

T1105
Ingress Tool Transfer
MalwareCanisterWorm

CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.

T1105
Ingress Tool Transfer
GroupTeamPCP

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.

T1105
Ingress Tool Transfer
GroupShinyHunters

ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.

T1105
Ingress Tool Transfer
MalwareBADFLICK

BADFLICK has download files from its C2 server.

T1106
Native API
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.

T1106
Native API
CampaignOperation Sharpshooter

During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`.

T1106
Native API
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`.

T1106
Native API
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

T1106
Native API
CampaignOperation Wocao

During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process.

T1106
Native API
GroupAPT38

APT38 has used the Windows API to execute code within a victim's system.

T1106
Native API
GroupSideCopy

SideCopy has executed malware by calling the API function `CreateProcessW`.

T1106
Native API
GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

T1106
Native API
GroupGorgon Group

Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution.

T1106
Native API
GroupmenuPass

menuPass has used native APIs including GetModuleFileName, lstrcat, CreateFile, and ReadFile.

T1106
Native API
GroupGamaredon Group

Gamaredon Group malware has used CreateProcess to launch additional malicious components.

T1106
Native API
GroupSandworm Team

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1106
Native API
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

T1106
Native API
GroupHigaisa

Higaisa has called various native OS APIs.

T1106
Native API
GroupTropic Trooper

Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl.

T1106
Native API
GroupBlackTech

BlackTech has used built-in API functions.

T1106
Native API
GroupTurla

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.

T1106
Native API
GroupTA505

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1106
Native API
GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.