Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
CampaignOperation Wocao | During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000. |
| T1571 Non-Standard Port |
CampaignQuad7 Activity | Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2. |
| T1572 Protocol Tunneling |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads. |
| T1572 Protocol Tunneling |
CampaignCutting Edge | During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS. |
| T1572 Protocol Tunneling |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment. |
| T1572 Protocol Tunneling |
CampaignC0027 | During C0027, Scattered Spider used SSH tunneling in targeted environments. |
| T1572 Protocol Tunneling |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler software to establish a “Yamux” TLS-based C2 channel with an external server(s). |
| T1572 Protocol Tunneling |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain. |
| T1573 Encrypted Channel |
CampaignKV Botnet Activity | KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation. |
| T1573 Encrypted Channel |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic. |
| T1573.001 Symmetric Cryptography |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server. |
| T1573.001 Symmetric Cryptography |
CampaignFrankenstein | During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC. |
| T1573.001 Symmetric Cryptography |
CampaignRedPenguin | During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages. |
| T1573.001 Symmetric Cryptography |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL communication module supports three commands to conduct the following actions: send implant data, execute shellcode, and terminate itself. |
| T1573.002 Asymmetric Cryptography |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
CampaignC0021 | During C0021, the threat actors used SSL via TCP port 443 for C2 communications. |
| T1573.002 Asymmetric Cryptography |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1573.002 Asymmetric Cryptography |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers. |
| T1573.002 Asymmetric Cryptography |
CampaignOperation Wocao | During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket. |
| T1574 Hijack Execution Flow |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched. |
| T1574 Hijack Execution Flow |
CampaignC0017 | During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries. |
| T1574.001 DLL |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations. |
| T1574.001 DLL |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence. |
| T1574.001 DLL |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs. |
| T1574.001 DLL |
CampaignAPT41 DUST | APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. |
| T1574.011 Services Registry Permissions Weakness |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process. |
| T1578.002 Create Cloud Instance |
CampaignC0027 | During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs. |
| T1583.001 Domains |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
| T1583.001 Domains |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains. |
| T1583.001 Domains |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains. |
| T1583.001 Domains |
CampaignOperation Honeybee | During Operation Honeybee, threat actors registered domains for C2. |
| T1583.001 Domains |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure. |
| T1583.001 Domains |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
CampaignOperation Spalax | For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit. |
| T1583.001 Domains |
CampaignC0021 | For C0021, the threat actors registered domains for use in C2. |
| T1583.001 Domains |
CampaignOperation Ghost | For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains. |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
| T1583.001 Domains |
CampaignFunnyDream | For FunnyDream, the threat actors registered a variety of domains. |
| T1583.001 Domains |
CampaignC0010 | For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer. |
| T1583.001 Domains |
CampaignC0011 | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India. |
| T1583.001 Domains |
CampaignC0026 | For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
| T1583.001 Domains |
CampaignCostaRicto | For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
| T1583.003 Virtual Private Server |
CampaignKV Botnet Activity | KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware. |
| T1583.003 Virtual Private Server |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors acquired VPS for use in C2. |
| T1583.003 Virtual Private Server |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure. |
| T1583.003 Virtual Private Server |
CampaignSPACEHOP Activity | SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network. |
| T1583.003 Virtual Private Server |
CampaignArcaneDoor | ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control. |
| T1583.003 Virtual Private Server |
CampaignFLORAHOX Activity | FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network. |
| T1583.004 Server |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools. |
| T1583.004 Server |
CampaignOperation Honeybee | For Operation Honeybee, at least one identified persona was used to register for a free account for a control server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.