Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareP.A.S. Webshell | P.A.S. Webshell can upload and download files to and from compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareVolgmer | Volgmer can download remote files and additional payloads to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareWhisperGate | WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1105 Ingress Tool Transfer |
MalwareZeroT | ZeroT can download additional payloads onto the victim. |
| T1105 Ingress Tool Transfer |
MalwareRDAT | RDAT can download files via DNS. |
| T1105 Ingress Tool Transfer |
MalwareSkidmap | Skidmap has the ability to download files on an infected host. |
| T1105 Ingress Tool Transfer |
MalwareOkrum | Okrum has built-in commands for uploading, downloading, and executing files to the system. |
| T1105 Ingress Tool Transfer |
MalwareBonadan | Bonadan can download additional modules from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareNeoichor | Neoichor can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareRaspberry Robin | Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's |
| T1105 Ingress Tool Transfer |
MalwareRemoteCMD | RemoteCMD copies a file over to the remote system before execution. |
| T1105 Ingress Tool Transfer |
MalwareDiavol | Diavol can receive configuration updates and additional payloads including wscpy.exe from C2. |
| T1105 Ingress Tool Transfer |
MalwareDoki | Doki has downloaded scripts from C2. |
| T1105 Ingress Tool Transfer |
MalwareIcedID | IcedID has the ability to download additional modules and a configuration file from C2. |
| T1105 Ingress Tool Transfer |
MalwareVERMIN | VERMIN can download and upload files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareUBoatRAT | UBoatRAT can upload and download files to the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareHTTPTroy | HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command. |
| T1105 Ingress Tool Transfer |
MalwareMarkiRAT | MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin. |
| T1105 Ingress Tool Transfer |
MalwareKazuar | Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary. |
| T1105 Ingress Tool Transfer |
MalwareNavRAT | NavRAT can download files remotely. |
| T1105 Ingress Tool Transfer |
MalwareDarkComet | DarkComet can load any files onto the infected machine to execute. |
| T1105 Ingress Tool Transfer |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can download additional files from C2. |
| T1105 Ingress Tool Transfer |
MalwareLucifer | Lucifer can download and execute a replica of itself using certutil. |
| T1105 Ingress Tool Transfer |
MalwareDRATzarus | DRATzarus can deploy additional tools onto an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareShimRat | ShimRat can download additional files. |
| T1105 Ingress Tool Transfer |
MalwareChrommme | Chrommme can download its code from C2. |
| T1105 Ingress Tool Transfer |
MalwareConficker | Conficker downloads an HTTP server to the infected machine. |
| T1105 Ingress Tool Transfer |
MalwareSocGholish | SocGholish can download additional malware to infected hosts. |
| T1105 Ingress Tool Transfer |
MalwareFlagpro | Flagpro can download additional malware from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHi-Zor | Hi-Zor has the ability to upload and download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareSpicyOmelette | SpicyOmelette can download malicious files from threat actor controlled AWS URL's. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareLightSpy | On macOS, LightSpy downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections. |
| T1105 Ingress Tool Transfer |
MalwarePUNCHBUGGY | PUNCHBUGGY can download additional files and payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareGoldMax | GoldMax can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareCostaBricks | CostaBricks has been used to load SombRAT onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKeyBoy | KeyBoy has a download and upload functionality. |
| T1105 Ingress Tool Transfer |
MalwarePOSHSPY | POSHSPY downloads and executes additional PowerShell code and Windows binaries. |
| T1105 Ingress Tool Transfer |
MalwareMiniDuke | MiniDuke can download additional encrypted backdoors onto the victim via GIF files. |
| T1105 Ingress Tool Transfer |
MalwareHyperBro | HyperBro has the ability to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareAnchor | Anchor can download additional payloads. |
| T1105 Ingress Tool Transfer |
MalwarePteranodon | Pteranodon can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareDarkTortilla | DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit. |
| T1105 Ingress Tool Transfer |
MalwareBeaverTail | BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1105 Ingress Tool Transfer |
MalwareROKRAT | ROKRAT can retrieve additional malicious payloads from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCORESHELL | CORESHELL downloads another dropper from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareDyre | Dyre has a command to download and executes additional files. |
| T1105 Ingress Tool Transfer |
MalwareBlackMould | BlackMould has the ability to download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareJavali | Javali can download payloads from remote C2 servers. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.