ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1041×

166 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareNETEAGLE

NETEAGLE is capable of reading files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can upload collected files to the command-and-control server.

T1041
Exfiltration Over C2 Channel
MalwareRising Sun

Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2.

T1041
Exfiltration Over C2 Channel
MalwareChrommme

Chrommme can exfiltrate collected data via C2.

T1041
Exfiltration Over C2 Channel
MalwareFlagpro

Flagpro has exfiltrated data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLightSpy

To exfiltrate data, LightSpy configures each module to send an obfuscated JSON blob to hardcoded URL endpoints or paths aligned to the module name.

T1041
Exfiltration Over C2 Channel
MalwareGoldMax

GoldMax can exfiltrate files over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLine Runner

Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.

T1041
Exfiltration Over C2 Channel
MalwarePteranodon

Pteranodon exfiltrates screenshot files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBeaverTail

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareROKRAT

ROKRAT can send collected files back over same C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareDyre

Dyre has the ability to send information staged on a compromised host externally to C2.

T1041
Exfiltration Over C2 Channel
MalwarePlugX

PlugX has exfiltrated stolen data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBisonal

Bisonal has added the exfiltrated data to the URL over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareS-Type

S-Type has uploaded data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareLumma Stealer

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareDustySky

DustySky has exfiltrated data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLightNeuron

LightNeuron exfiltrates data over its email C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareDarkGate

DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials.

T1041
Exfiltration Over C2 Channel
MalwareMongall

Mongall can upload files and information from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSVCReady

SVCReady can send collected data in JSON format to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareThiefQuest

ThiefQuest exfiltrates targeted file extensions in the /Users/ folder to the command and control server via unencrypted HTTP. Network packets contain a string with two pieces of information: a file path and the contents of the file in a base64 encoded string.

T1041
Exfiltration Over C2 Channel
MalwareFoggyWeb

FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server.

T1041
Exfiltration Over C2 Channel
MalwareCaterpillar WebShell

Caterpillar WebShell can upload files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLODEINFO

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareCharmPower

CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST.

T1041
Exfiltration Over C2 Channel
MalwareMuddyViper

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1041
Exfiltration Over C2 Channel
MalwareEVILNUM

EVILNUM can upload files over the C2 channel from the infected host.

T1041
Exfiltration Over C2 Channel
MalwareSMOKEDHAM

SMOKEDHAM has exfiltrated data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSagerunex

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareMetamorfo

Metamorfo can send the data it collects to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBandook

Bandook can upload files from a victim's machine over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMagicRAT

MagicRAT exfiltrates data via HTTP over existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareKONNI

KONNI has sent data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDnsSystem

DnsSystem can exfiltrate collected data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBLUELIGHT

BLUELIGHT has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareKGH_SPY

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareRedLine Stealer

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1041
Exfiltration Over C2 Channel
MalwareOopsIE

OopsIE can upload files from the victim's machine to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareAttor

Attor has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLitePower

LitePower can send collected data, including screenshots, over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBoxCaon

BoxCaon uploads files and data from a compromised host over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareNightClub

NightClub can use SMTP and DNS for file exfiltration and C2.

T1041
Exfiltration Over C2 Channel
MalwareCrutch

Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API).

T1041
Exfiltration Over C2 Channel
MalwareSDBbot

SDBbot has sent collected data from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1041
Exfiltration Over C2 Channel
MalwareGrandoreiro

Grandoreiro can send data it retrieves to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDrovorub

Drovorub can exfiltrate files over C2 infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareShark

Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.