Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
GroupKimsuky | Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames. |
| T1020 Automated Exfiltration |
GroupGamaredon Group | Gamaredon Group has used modules that automatically upload gathered documents to the C2 server. |
| T1020 Automated Exfiltration |
GroupSidewinder | Sidewinder has configured tools to automatically send collected files to attacker controlled servers. |
| T1020 Automated Exfiltration |
GroupTropic Trooper | Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage. |
| T1020 Automated Exfiltration |
GroupKe3chang | Ke3chang has performed frequent and scheduled data exfiltration from compromised networks. |
| T1020 Automated Exfiltration |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1020 Automated Exfiltration |
GroupRedCurl | RedCurl has used batch scripts to exfiltrate data. |
| T1020 Automated Exfiltration |
MalwareStrongPity | StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1020 Automated Exfiltration |
MalwareHannotog | Hannotog can upload encyrpted data for exfiltration. |
| T1020 Automated Exfiltration |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files automatically over FTP to remote servers. |
| T1020 Automated Exfiltration |
MalwareMachete | Machete’s collected files are exfiltrated automatically to remote servers. |
| T1020 Automated Exfiltration |
MalwareDoki | Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| T1020 Automated Exfiltration |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe. |
| T1020 Automated Exfiltration |
MalwareLightNeuron | LightNeuron can be configured to automatically exfiltrate files under a specified directory. |
| T1020 Automated Exfiltration |
MalwarePeppy | Peppy has the ability to automatically exfiltrate files and keylogs. |
| T1020 Automated Exfiltration |
MalwareTINYTYPHON | When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server. |
| T1020 Automated Exfiltration |
MalwareAttor | Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| T1020 Automated Exfiltration |
MalwareCrutch | Crutch has automatically exfiltrated stolen files to Dropbox. |
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1020 Automated Exfiltration |
MalwareUSBStealer | USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine. |
| T1020 Automated Exfiltration |
MalwareTajMahal | TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1020 Automated Exfiltration |
MalwareSolar | Solar can automatically exfitrate files from compromised systems. |
| T1020 Automated Exfiltration |
MalwareOutSteel | OutSteel can automatically upload collected files to its C2 server. |
| T1020 Automated Exfiltration |
MalwareEbury | If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| T1020 Automated Exfiltration |
ToolShimRatReporter | ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2. |
| T1020 Automated Exfiltration |
ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1020 Automated Exfiltration |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there. |
| T1021 Remote Services |
GroupAquatic Panda | Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions. |
| T1021 Remote Services |
GroupEmber Bear | Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so. |
| T1021 Remote Services |
GroupWizard Spider | Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares. |
| T1021 Remote Services |
MalwareStuxnet | Stuxnet can propagate via peer-to-peer communication and updates using RPC. |
| T1021 Remote Services |
MalwareKivars | Kivars has the ability to remotely trigger keyboard input and mouse clicks. |
| T1021 Remote Services |
MalwareMacMa | MacMa can manage remote screen sessions. |
| T1021 Remote Services |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use RPC for lateral movement. |
| T1021.001 Remote Desktop Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement. |
| T1021.001 Remote Desktop Protocol |
CampaignC0018 | During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892. |
| T1021.001 Remote Desktop Protocol |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1021.001 Remote Desktop Protocol |
CampaignC0015 | During C0015, the threat actors used RDP to access specific network hosts of interest. |
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.001 Remote Desktop Protocol |
CampaignC0032 | During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| T1021.001 Remote Desktop Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.001 Remote Desktop Protocol |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller. |
| T1021.001 Remote Desktop Protocol |
GroupIndrik Spider | Indrik Spider has used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
GroupBlackByte | BlackByte has used RDP to access other hosts within victim networks. |
| T1021.001 Remote Desktop Protocol |
GroupAPT3 | APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions. |
| T1021.001 Remote Desktop Protocol |
GroupKimsuky | Kimsuky has used RDP for direct remote point-and-click access. |
| T1021.001 Remote Desktop Protocol |
GroupVolt Typhoon | Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges. |
| T1021.001 Remote Desktop Protocol |
GroupPatchwork | Patchwork attempted to use RDP to move laterally. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.