Real-world descriptions of how a group, tool or campaign used a technique.
88 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
GroupTA551 | TA551 has retrieved DLLs and installer binaries for malware execution from C2. |
| T1105 Ingress Tool Transfer |
GroupBackdoorDiplomacy | BackdoorDiplomacy has downloaded additional files and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupDarkhotel | Darkhotel has used first-stage payloads that download additional malware from C2 servers. |
| T1105 Ingress Tool Transfer |
GroupLazyScripter | LazyScripter had downloaded additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
GroupWindshift | Windshift has used tools to deploy additional payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupVolatile Cedar | Volatile Cedar can deploy additional tools. |
| T1105 Ingress Tool Transfer |
GroupWhitefly | Whitefly has the ability to download additional tools from the C2. |
| T1105 Ingress Tool Transfer |
GroupLuminousMoth | LuminousMoth has downloaded additional malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1105 Ingress Tool Transfer |
GroupMetador | Metador has downloaded tools and malware onto a compromised system. |
| T1105 Ingress Tool Transfer |
GroupFox Kitten | Fox Kitten has downloaded additional tools including PsExec directly to endpoints. |
| T1105 Ingress Tool Transfer |
GroupAPT-C-36 | APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened. |
| T1105 Ingress Tool Transfer |
GroupWinnti Group | Winnti Group has downloaded an auxiliary program named ff.exe to infected machines. |
| T1105 Ingress Tool Transfer |
GroupTonto Team | Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupINC Ransom | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. |
| T1105 Ingress Tool Transfer |
GroupSilence | Silence has downloaded additional modules and malware to victim’s machines. |
| T1105 Ingress Tool Transfer |
GroupCobalt Group | Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files. |
| T1105 Ingress Tool Transfer |
GroupWizard Spider | Wizard Spider can transfer malicious payloads such as ransomware to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupMolerats | Molerats used executables to download malicious files from different sources. |
| T1105 Ingress Tool Transfer |
GroupIndigoZebra | IndigoZebra has downloaded additional files and tools from its C2 server. |
| T1105 Ingress Tool Transfer |
GroupMoonstone Sleet | Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems. |
| T1105 Ingress Tool Transfer |
GroupVOID MANTICORE | VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website. |
| T1105 Ingress Tool Transfer |
GroupPlay | Play has used Cobalt Strike to download files to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupHEXANE | HEXANE has downloaded additional payloads and malicious scripts onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupDaggerfly | Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines. |
| T1105 Ingress Tool Transfer |
GroupRancor | Rancor has downloaded additional malware, including by using certutil. |
| T1105 Ingress Tool Transfer |
GroupWIRTE | WIRTE has downloaded PowerShell code from the C2 server to be executed. |
| T1105 Ingress Tool Transfer |
GroupPLATINUM | PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1105 Ingress Tool Transfer |
GroupAjax Security Team | Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system. |
| T1105 Ingress Tool Transfer |
GroupThreat Group-3390 | Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host . |
| T1105 Ingress Tool Transfer |
GroupAPT33 | APT33 has downloaded additional files and programs from its C2 server. |
| T1105 Ingress Tool Transfer |
GroupFIN8 | FIN8 has used remote code execution to download subsequent payloads. |
| T1105 Ingress Tool Transfer |
GroupFIN13 | FIN13 has downloaded additional tools and malware to compromised systems. |
| T1105 Ingress Tool Transfer |
GroupNomadic Octopus | Nomadic Octopus has used malicious macros to download additional files to the victim's machine. |
| T1105 Ingress Tool Transfer |
GroupTeamPCP | TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2. |
| T1105 Ingress Tool Transfer |
GroupShinyHunters | ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.