Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareCosmicDuke | CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers. |
| T1071.001 Web Protocols |
MalwareGreyEnergy | GreyEnergy uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareGomir | Gomir periodically communicates to its command and control infrastructure through HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareAria-body | Aria-body has used HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareEmotet | Emotet has used HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareSNUGRIDE | SNUGRIDE communicates with its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareBOLDMOVE | BOLDMOVE uses web services for command and control communication. |
| T1071.001 Web Protocols |
MalwareCrimson | Crimson can use a HTTP GET request to download its final payload. |
| T1071.001 Web Protocols |
MalwareTomiris | Tomiris can use HTTP to establish C2 communications. |
| T1071.001 Web Protocols |
MalwareTurian | Turian has the ability to use HTTP for its C2. |
| T1071.001 Web Protocols |
MalwareTHINCRUST | THINCRUST can use HTTP POST requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareBADHATCH | BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.001 Web Protocols |
MalwareAction RAT | Action RAT can use HTTP to communicate with C2 servers. |
| T1071.001 Web Protocols |
MalwareAvenger | Avenger has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.001 Web Protocols |
MalwarePingPull | A PingPull variant can communicate with its C2 servers by using HTTPS. |
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareDacls | Dacls can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareWoody RAT | Woody RAT can communicate with its C2 server using HTTP requests. |
| T1071.001 Web Protocols |
MalwareMafalda | Mafalda can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareSquirrelwaffle | Squirrelwaffle has used HTTP POST requests for C2 communications. |
| T1071.001 Web Protocols |
MalwareELMER | ELMER uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwarePolyglotDuke | PolyglotDuke has has used HTTP GET requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareHexEval Loader | HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2. |
| T1071.001 Web Protocols |
MalwareAuTo Stealer | AuTo Stealer can use HTTP to communicate with its C2 servers. |
| T1071.001 Web Protocols |
MalwareShrinkLocker | ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor. |
| T1071.001 Web Protocols |
MalwareFlawedAmmyy | FlawedAmmyy has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareCuckoo Stealer | Cuckoo Stealer can use the curl API for C2 communications. |
| T1071.001 Web Protocols |
MalwareGuLoader | GuLoader can use HTTP to retrieve additional binaries. |
| T1071.001 Web Protocols |
MalwareInvisiMole | InvisiMole uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareP.A.S. Webshell | P.A.S. Webshell can issue commands via HTTP POST. |
| T1071.001 Web Protocols |
MalwareWhisperGate | WhisperGate can make an HTTPS connection to download additional files. |
| T1071.001 Web Protocols |
MalwareZeroT | ZeroT has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareKeydnap | Keydnap uses HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareRDAT | RDAT can use HTTP communications for C2, as well as using the WinHTTP library to make requests to the Exchange Web Services API. |
| T1071.001 Web Protocols |
MalwareOkrum | Okrum uses HTTP for communication with its C2. |
| T1071.001 Web Protocols |
MalwareTRANSLATEXT | TRANSLATEXT has used HTTP to communicate with the C2 server. |
| T1071.001 Web Protocols |
MalwareRegin | The Regin malware platform supports many standard protocols, including HTTP and HTTPS. |
| T1071.001 Web Protocols |
MalwareLine Dancer | Line Dancer uses HTTP POST requests to interact with compromised devices. |
| T1071.001 Web Protocols |
MalwareNeoichor | Neoichor can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRaspberry Robin | Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution. |
| T1071.001 Web Protocols |
MalwareDiavol | Diavol has used HTTP GET and POST requests for C2. |
| T1071.001 Web Protocols |
MalwareDoki | Doki has communicated with C2 over HTTPS. |
| T1071.001 Web Protocols |
MalwareRustyWater | RustyWater has used the Rust request library for HTTP C2 communication. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1071.001 Web Protocols |
MalwareVERMIN | VERMIN uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareUBoatRAT | UBoatRAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareHTTPTroy | HTTPTroy has used HTTP POST requests to communicate with C2. |
| T1071.001 Web Protocols |
MalwareMarkiRAT | MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.