ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

88 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
GroupTA551

TA551 has retrieved DLLs and installer binaries for malware execution from C2.

T1105
Ingress Tool Transfer
GroupBackdoorDiplomacy

BackdoorDiplomacy has downloaded additional files and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupDarkhotel

Darkhotel has used first-stage payloads that download additional malware from C2 servers.

T1105
Ingress Tool Transfer
GroupLazyScripter

LazyScripter had downloaded additional tools to a compromised host.

T1105
Ingress Tool Transfer
GroupWindshift

Windshift has used tools to deploy additional payloads to compromised hosts.

T1105
Ingress Tool Transfer
GroupVolatile Cedar

Volatile Cedar can deploy additional tools.

T1105
Ingress Tool Transfer
GroupWhitefly

Whitefly has the ability to download additional tools from the C2.

T1105
Ingress Tool Transfer
GroupLuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1105
Ingress Tool Transfer
GroupMetador

Metador has downloaded tools and malware onto a compromised system.

T1105
Ingress Tool Transfer
GroupFox Kitten

Fox Kitten has downloaded additional tools including PsExec directly to endpoints.

T1105
Ingress Tool Transfer
GroupAPT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

T1105
Ingress Tool Transfer
GroupWinnti Group

Winnti Group has downloaded an auxiliary program named ff.exe to infected machines.

T1105
Ingress Tool Transfer
GroupTonto Team

Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1105
Ingress Tool Transfer
GroupINC Ransom

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.

T1105
Ingress Tool Transfer
GroupSilence

Silence has downloaded additional modules and malware to victim’s machines.

T1105
Ingress Tool Transfer
GroupCobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

T1105
Ingress Tool Transfer
GroupWizard Spider

Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.

T1105
Ingress Tool Transfer
GroupMolerats

Molerats used executables to download malicious files from different sources.

T1105
Ingress Tool Transfer
GroupIndigoZebra

IndigoZebra has downloaded additional files and tools from its C2 server.

T1105
Ingress Tool Transfer
GroupMoonstone Sleet

Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.

T1105
Ingress Tool Transfer
GroupVOID MANTICORE

VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.

T1105
Ingress Tool Transfer
GroupPlay

Play has used Cobalt Strike to download files to compromised machines.

T1105
Ingress Tool Transfer
GroupHEXANE

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.

T1105
Ingress Tool Transfer
GroupDaggerfly

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.

T1105
Ingress Tool Transfer
GroupRancor

Rancor has downloaded additional malware, including by using certutil.

T1105
Ingress Tool Transfer
GroupWIRTE

WIRTE has downloaded PowerShell code from the C2 server to be executed.

T1105
Ingress Tool Transfer
GroupPLATINUM

PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1105
Ingress Tool Transfer
GroupAjax Security Team

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.

T1105
Ingress Tool Transfer
GroupThreat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .

T1105
Ingress Tool Transfer
GroupAPT33

APT33 has downloaded additional files and programs from its C2 server.

T1105
Ingress Tool Transfer
GroupFIN8

FIN8 has used remote code execution to download subsequent payloads.

T1105
Ingress Tool Transfer
GroupFIN13

FIN13 has downloaded additional tools and malware to compromised systems.

T1105
Ingress Tool Transfer
GroupNomadic Octopus

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.

T1105
Ingress Tool Transfer
GroupTeamPCP

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.

T1105
Ingress Tool Transfer
GroupShinyHunters

ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.