ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
GroupKimsuky

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.

T1020
Automated Exfiltration
GroupGamaredon Group

Gamaredon Group has used modules that automatically upload gathered documents to the C2 server.

T1020
Automated Exfiltration
GroupSidewinder

Sidewinder has configured tools to automatically send collected files to attacker controlled servers.

T1020
Automated Exfiltration
GroupTropic Trooper

Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage.

T1020
Automated Exfiltration
GroupKe3chang

Ke3chang has performed frequent and scheduled data exfiltration from compromised networks.

T1020
Automated Exfiltration
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1020
Automated Exfiltration
GroupRedCurl

RedCurl has used batch scripts to exfiltrate data.

T1020
Automated Exfiltration
MalwareStrongPity

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1020
Automated Exfiltration
MalwareHannotog

Hannotog can upload encyrpted data for exfiltration.

T1020
Automated Exfiltration
MalwareCosmicDuke

CosmicDuke exfiltrates collected files automatically over FTP to remote servers.

T1020
Automated Exfiltration
MalwareMachete

Machete’s collected files are exfiltrated automatically to remote servers.

T1020
Automated Exfiltration
MalwareDoki

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

T1020
Automated Exfiltration
MalwareRover

Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe.

T1020
Automated Exfiltration
MalwareLightNeuron

LightNeuron can be configured to automatically exfiltrate files under a specified directory.

T1020
Automated Exfiltration
MalwarePeppy

Peppy has the ability to automatically exfiltrate files and keylogs.

T1020
Automated Exfiltration
MalwareTINYTYPHON

When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.

T1020
Automated Exfiltration
MalwareAttor

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

T1020
Automated Exfiltration
MalwareCrutch

Crutch has automatically exfiltrated stolen files to Dropbox.

T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1020
Automated Exfiltration
MalwareUSBStealer

USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine.

T1020
Automated Exfiltration
MalwareTajMahal

TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1020
Automated Exfiltration
MalwareSolar

Solar can automatically exfitrate files from compromised systems.

T1020
Automated Exfiltration
MalwareOutSteel

OutSteel can automatically upload collected files to its C2 server.

T1020
Automated Exfiltration
MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1020
Automated Exfiltration
ToolShimRatReporter

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1020
Automated Exfiltration
ToolEmpire

Empire has the ability to automatically send collected data back to the threat actors' C2.

T1020
Automated Exfiltration
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there.

T1021
Remote Services
GroupAquatic Panda

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.

T1021
Remote Services
GroupEmber Bear

Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so.

T1021
Remote Services
GroupWizard Spider

Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.

T1021
Remote Services
MalwareStuxnet

Stuxnet can propagate via peer-to-peer communication and updates using RPC.

T1021
Remote Services
MalwareKivars

Kivars has the ability to remotely trigger keyboard input and mouse clicks.

T1021
Remote Services
MalwareMacMa

MacMa can manage remote screen sessions.

T1021
Remote Services
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use RPC for lateral movement.

T1021.001
Remote Desktop Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

T1021.001
Remote Desktop Protocol
CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1021.001
Remote Desktop Protocol
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

T1021.001
Remote Desktop Protocol
CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.001
Remote Desktop Protocol
CampaignC0032

During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation.

T1021.001
Remote Desktop Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.001
Remote Desktop Protocol
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

T1021.001
Remote Desktop Protocol
GroupIndrik Spider

Indrik Spider has used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
GroupBlackByte

BlackByte has used RDP to access other hosts within victim networks.

T1021.001
Remote Desktop Protocol
GroupAPT3

APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions.

T1021.001
Remote Desktop Protocol
GroupKimsuky

Kimsuky has used RDP for direct remote point-and-click access.

T1021.001
Remote Desktop Protocol
GroupVolt Typhoon

Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.

T1021.001
Remote Desktop Protocol
GroupPatchwork

Patchwork attempted to use RDP to move laterally.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.