Real-world descriptions of how a group, tool or campaign used a technique.
166 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareSUGARDUMP | SUGARDUMP has sent stolen credentials and other data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareZebrocy | Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareLunarMail | LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareHotCroissant | HotCroissant has the ability to download files from the infected host to the command and control (C2) server. |
| T1041 Exfiltration Over C2 Channel |
MalwareREvil | REvil can exfiltrate host and malware information to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareValak | Valak has the ability to exfiltrate data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOilBooster | OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareCyclops Blink | Cyclops Blink has the ability to upload exfiltrated files to a C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTajMahal | TajMahal has the ability to send collected files over its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareRaccoon Stealer | Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareIPsec Helper | IPsec Helper exfiltrates specific files through its command and control framework. |
| T1041 Exfiltration Over C2 Channel |
MalwareSolar | Solar can send staged files to C2 for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldenSpy | GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006. |
| T1041 Exfiltration Over C2 Channel |
MalwareAshTag | AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareCarberp | Carberp has exfiltrated data via HTTP to already established C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareMacMa | MacMa exfiltrates data from a supplied path over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareFunnyDream | FunnyDream can execute commands, including gathering user information, and send the results to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareSysUpdate | SysUpdate has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOutSteel | OutSteel can upload files from a compromised host over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLAMEHUG | LAMEHUG can exfiltrate collected system information and documents to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareMango | Mango can use its HTTP C2 channel for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareKessel | Kessel has exfiltrated information gathered from the infected system to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrimAgent | GrimAgent has sent data related to a compromise host over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePHASEJAM | PHASEJAM has the ability to exfiltrate data from the victim appliance. |
| T1041 Exfiltration Over C2 Channel |
MalwareLokibot | Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data. |
| T1041 Exfiltration Over C2 Channel |
MalwareCallMe | CallMe exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwarePoetRAT | PoetRAT has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePenquin | Penquin can execute the command code |
| T1041 Exfiltration Over C2 Channel |
MalwareCannon | Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareCreepySnail | CreepySnail can connect to C2 for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareTroll Stealer | Troll Stealer exfiltrates collected information to its command and control infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareEbury | Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwarenjRAT | njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information. |
| T1041 Exfiltration Over C2 Channel |
MalwareManjusaka | Manjusaka data exfiltration takes place over HTTP channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareIceApple | IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareShai-Hulud | Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1041 Exfiltration Over C2 Channel |
MalwaremetaMain | metaMain can upload collected files and data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSideTwist | SideTwist has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMechaFlounder | MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePsylo | Psylo exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareMis-Type | Mis-Type has transmitted collected files and data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareXCSSET | XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOctopus | Octopus has uploaded stolen files and data from a victim's machine over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleJeus | AppleJeus has exfiltrated collected host information to a C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSTARWHALE | STARWHALE can exfiltrate collected data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareIndustroyer | Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request. |
| T1041 Exfiltration Over C2 Channel |
MalwareKevin | Kevin can send data from the victim host through a DNS C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoopy | Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareRemexi | Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareAstaroth | Astaroth exfiltrates collected information from its r1.log file to the external C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.