Real-world descriptions of how a group, tool or campaign used a technique.
166 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareNETEAGLE | NETEAGLE is capable of reading files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1041 Exfiltration Over C2 Channel |
MalwareRising Sun | Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareChrommme | Chrommme can exfiltrate collected data via C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlagpro | Flagpro has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightSpy | To exfiltrate data, LightSpy configures each module to send an obfuscated JSON blob to hardcoded URL endpoints or paths aligned to the module name. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Runner | Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer. |
| T1041 Exfiltration Over C2 Channel |
MalwarePteranodon | Pteranodon exfiltrates screenshot files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareROKRAT | ROKRAT can send collected files back over same C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDyre | Dyre has the ability to send information staged on a compromised host externally to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePlugX | PlugX has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBisonal | Bisonal has added the exfiltrated data to the URL over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareS-Type | S-Type has uploaded data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareDustySky | DustySky has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightNeuron | LightNeuron exfiltrates data over its email C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDarkGate | DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials. |
| T1041 Exfiltration Over C2 Channel |
MalwareMongall | Mongall can upload files and information from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSVCReady | SVCReady can send collected data in JSON format to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareThiefQuest | ThiefQuest exfiltrates targeted file extensions in the |
| T1041 Exfiltration Over C2 Channel |
MalwareFoggyWeb | FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server. |
| T1041 Exfiltration Over C2 Channel |
MalwareCaterpillar WebShell | Caterpillar WebShell can upload files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLatrodectus | Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLODEINFO | LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareCharmPower | CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST. |
| T1041 Exfiltration Over C2 Channel |
MalwareMuddyViper | MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk. |
| T1041 Exfiltration Over C2 Channel |
MalwareEVILNUM | EVILNUM can upload files over the C2 channel from the infected host. |
| T1041 Exfiltration Over C2 Channel |
MalwareSMOKEDHAM | SMOKEDHAM has exfiltrated data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSagerunex | Sagerunex encrypts collected system data then exfiltrates via existing command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareMetamorfo | Metamorfo can send the data it collects to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBandook | Bandook can upload files from a victim's machine over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMagicRAT | MagicRAT exfiltrates data via HTTP over existing command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareKONNI | KONNI has sent data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDnsSystem | DnsSystem can exfiltrate collected data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBLUELIGHT | BLUELIGHT has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareKGH_SPY | KGH_SPY can exfiltrate collected information from the host to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareRedLine Stealer | RedLine Stealer has sent victim data to its C2 server or RedLine panel server. |
| T1041 Exfiltration Over C2 Channel |
MalwareOopsIE | OopsIE can upload files from the victim's machine to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareAttor | Attor has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLitePower | LitePower can send collected data, including screenshots, over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBoxCaon | BoxCaon uploads files and data from a compromised host over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareNightClub | NightClub can use SMTP and DNS for file exfiltration and C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrutch | Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API). |
| T1041 Exfiltration Over C2 Channel |
MalwareSDBbot | SDBbot has sent collected data from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrandoreiro | Grandoreiro can send data it retrieves to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDrovorub | Drovorub can exfiltrate files over C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareShark | Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.