ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1041×

166 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareSUGARDUMP

SUGARDUMP has sent stolen credentials and other data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1041
Exfiltration Over C2 Channel
MalwareLunarMail

LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareHotCroissant

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1041
Exfiltration Over C2 Channel
MalwareREvil

REvil can exfiltrate host and malware information to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOilBooster

OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareCyclops Blink

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTajMahal

TajMahal has the ability to send collected files over its C2.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareIPsec Helper

IPsec Helper exfiltrates specific files through its command and control framework.

T1041
Exfiltration Over C2 Channel
MalwareSolar

Solar can send staged files to C2 for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareGoldenSpy

GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006.

T1041
Exfiltration Over C2 Channel
MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareMacMa

MacMa exfiltrates data from a supplied path over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareFunnyDream

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1041
Exfiltration Over C2 Channel
MalwareSysUpdate

SysUpdate has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOutSteel

OutSteel can upload files from a compromised host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLAMEHUG

LAMEHUG can exfiltrate collected system information and documents to C2.

T1041
Exfiltration Over C2 Channel
MalwareMango

Mango can use its HTTP C2 channel for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareKessel

Kessel has exfiltrated information gathered from the infected system to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareGrimAgent

GrimAgent has sent data related to a compromise host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePHASEJAM

PHASEJAM has the ability to exfiltrate data from the victim appliance.

T1041
Exfiltration Over C2 Channel
MalwareLokibot

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1041
Exfiltration Over C2 Channel
MalwareCallMe

CallMe exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwarePoetRAT

PoetRAT has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePenquin

Penquin can execute the command code do_upload to send files to C2.

T1041
Exfiltration Over C2 Channel
MalwareCannon

Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareCreepySnail

CreepySnail can connect to C2 for data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareTroll Stealer

Troll Stealer exfiltrates collected information to its command and control infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareEbury

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1041
Exfiltration Over C2 Channel
MalwareManjusaka

Manjusaka data exfiltration takes place over HTTP channels.

T1041
Exfiltration Over C2 Channel
MalwareIceApple

IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2.

T1041
Exfiltration Over C2 Channel
MalwareShai-Hulud

Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL.

T1041
Exfiltration Over C2 Channel
MalwaremetaMain

metaMain can upload collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSideTwist

SideTwist has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMechaFlounder

MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2.

T1041
Exfiltration Over C2 Channel
MalwarePsylo

Psylo exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareMis-Type

Mis-Type has transmitted collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareXCSSET

XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOctopus

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSTARWHALE

STARWHALE can exfiltrate collected data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareIndustroyer

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1041
Exfiltration Over C2 Channel
MalwareKevin

Kevin can send data from the victim host through a DNS C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareGoopy

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareRemexi

Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.