Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
MalwarenjRAT | njRAT has used port 1177 for HTTP C2 communications. |
| T1571 Non-Standard Port |
MalwareVIRTUALPITA | VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098. |
| T1571 Non-Standard Port |
ToolCovenant | Covenant listeners and controllers can be configured to use non-standard ports. |
| T1571 Non-Standard Port |
ToolQuasarRAT | QuasarRAT can use port 4782 on the compromised host for TCP callbacks. |
| T1572 Protocol Tunneling |
MalwareBRICKSTORM | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1572 Protocol Tunneling |
MalwarereGeorg | reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
| T1572 Protocol Tunneling |
MalwareFLIPSIDE | FLIPSIDE uses RDP to tunnel traffic from a victim environment. |
| T1572 Protocol Tunneling |
MalwareUroburos | Uroburos has the ability to communicate over custom communications methodologies that ride over common network protocols including raw TCP and UDP sockets, HTTP, SMTP, and DNS. |
| T1572 Protocol Tunneling |
MalwareHiddenFace | HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2. |
| T1572 Protocol Tunneling |
MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1572 Protocol Tunneling |
MalwareMilan | Milan can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareCyclops Blink | Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes. |
| T1572 Protocol Tunneling |
MalwareNeo-reGeorg | Neo-reGeorg can tunnel data in and out of targeted networks. |
| T1572 Protocol Tunneling |
MalwareFunnyDream | FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1572 Protocol Tunneling |
MalwareHeyoka Backdoor | Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers. |
| T1572 Protocol Tunneling |
MalwareLunarWeb | LunarWeb can run a custom binary protocol under HTTPS for C2. |
| T1572 Protocol Tunneling |
MalwareIndustroyer | Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel. |
| T1572 Protocol Tunneling |
MalwareKevin | Kevin can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareQakBot | The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol. |
| T1572 Protocol Tunneling |
Toolngrok | ngrok can tunnel RDP and other services securely over internet connections. |
| T1572 Protocol Tunneling |
ToolFRP | FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT. |
| T1572 Protocol Tunneling |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1572 Protocol Tunneling |
ToolMythic | Mythic can use SOCKS proxies to tunnel traffic through another protocol. |
| T1572 Protocol Tunneling |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| T1573 Encrypted Channel |
MalwareRCSession | RCSession can use an encrypted beacon to check in with C2. |
| T1573 Encrypted Channel |
MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| T1573 Encrypted Channel |
MalwareGomir | Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| T1573 Encrypted Channel |
MalwareEmotet | Emotet has encrypted data before sending to the C2 server. |
| T1573 Encrypted Channel |
MalwarePowerLess | PowerLess can use an encrypted channel for C2 communications. |
| T1573 Encrypted Channel |
MalwareChaes | Chaes has used encryption for its C2 channel. |
| T1573 Encrypted Channel |
Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| T1573 Encrypted Channel |
MalwareCryptoistic | Cryptoistic can engage in encrypted communications with C2. |
| T1573 Encrypted Channel |
MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| T1573 Encrypted Channel |
MalwarePowGoop | PowGoop can receive encrypted commands from C2. |
| T1573 Encrypted Channel |
MalwareLizar | Lizar can support encrypted communications between the client and server. |
| T1573.001 Symmetric Cryptography |
MalwareTrickBot | TrickBot uses a custom crypter leveraging Microsoft’s CryptoAPI to encrypt C2 traffic.Newer versions of TrickBot have been known to use `bcrypt` to encrypt and digitally sign responses to their C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareBLINDINGCAN | BLINDINGCAN has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareNinja | Ninja can XOR and AES encrypt C2 messages. |
| T1573.001 Symmetric Cryptography |
MalwarePikabot | Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information. |
| T1573.001 Symmetric Cryptography |
MalwareBumblebee | Bumblebee can encrypt C2 requests and responses with RC4 |
| T1573.001 Symmetric Cryptography |
MalwareTorisma | Torisma has encrypted its C2 communications using XOR and VEST-32. |
| T1573.001 Symmetric Cryptography |
MalwareStuxnet | Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant. |
| T1573.001 Symmetric Cryptography |
MalwareDowndelph | Downdelph uses RC4 to encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
MalwareRotaJakiro | RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression. |
| T1573.001 Symmetric Cryptography |
MalwareSardonic | Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers. |
| T1573.001 Symmetric Cryptography |
MalwareEmissary | The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data. |
| T1573.001 Symmetric Cryptography |
MalwareKEYMARBLE | KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareTAMECAT | TAMECAT has used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.