ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1567.002
Exfiltration to Cloud Storage
MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

T1567.002
Exfiltration to Cloud Storage
MalwarePcexter

Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`.

T1567.002
Exfiltration to Cloud Storage
ToolEmpire

Empire can use Dropbox for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
ToolRclone

Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.

T1567.004
Exfiltration Over Webhook
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data.

T1567.004
Exfiltration Over Webhook
MalwareShai-Hulud

Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`.

T1568
Dynamic Resolution
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322.

T1568
Dynamic Resolution
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1568
Dynamic Resolution
CampaignOperation Spalax

For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure.

T1568
Dynamic Resolution
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2.

T1568
Dynamic Resolution
CampaignNight Dragon

During Night Dragon, threat actors used dynamic DNS services for C2.

T1568
Dynamic Resolution
CampaignC0026

During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.

T1568
Dynamic Resolution
GroupKimsuky

Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea.

T1568
Dynamic Resolution
GroupRedEcho

RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1568
Dynamic Resolution
GroupGamaredon Group

Gamaredon Group has incorporated dynamic DNS domains in its infrastructure.

T1568
Dynamic Resolution
GroupTA2541

TA2541 has used dynamic DNS services for C2 infrastructure.

T1568
Dynamic Resolution
GroupBITTER

BITTER has used DDNS for C2 communications.

T1568
Dynamic Resolution
GroupAPT29

APT29 has used Dynamic DNS providers for their malware C2 infrastructure.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1568
Dynamic Resolution
GroupTransparent Tribe

Transparent Tribe has used dynamic DNS services to set up C2.

T1568
Dynamic Resolution
MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

T1568
Dynamic Resolution
MalwareTomiris

Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2.

T1568
Dynamic Resolution
MalwareNETEAGLE

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

T1568
Dynamic Resolution
MalwareBisonal

Bisonal has used a dynamic DNS service for C2.

T1568
Dynamic Resolution
MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

T1568
Dynamic Resolution
MalwareSUNBURST

SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain.

T1568
Dynamic Resolution
MalwareMaze

Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts.

T1568
Dynamic Resolution
MalwareGelsemium

Gelsemium can use dynamic DNS domain names in C2.

T1568
Dynamic Resolution
ToolAsyncRAT

AsyncRAT can be configured to use dynamic DNS.

T1568
Dynamic Resolution
ToolRemcos

Remcos has used dynamic DNS domains in C2 communications.

T1568.001
Fast Flux DNS
GroupmenuPass

menuPass has used dynamic DNS service providers to host malicious domains.

T1568.001
Fast Flux DNS
GroupGamaredon Group

Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method.

T1568.001
Fast Flux DNS
GroupTA505

TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs.

T1568.001
Fast Flux DNS
MalwareAmadey

Amadey has used fast flux DNS for its C2.

T1568.001
Fast Flux DNS
Malwaregh0st RAT

gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses.

T1568.001
Fast Flux DNS
MalwarenjRAT

njRAT has used a fast flux DNS for C2 IP resolution.

T1568.002
Domain Generation Algorithms
GroupAPT41

APT41 has used DGAs to change their C2 servers monthly.

T1568.002
Domain Generation Algorithms
GroupTA551

TA551 has used a DGA to generate URLs from executed macros.

T1568.002
Domain Generation Algorithms
MalwareUrsnif

Ursnif has used a DGA to generate domain names for C2.

T1568.002
Domain Generation Algorithms
MalwareAria-body

Aria-body has the ability to use a DGA for C2 communications.

T1568.002
Domain Generation Algorithms
MalwareSombRAT

SombRAT can use a custom DGA to generate a subdomain for C2.

T1568.002
Domain Generation Algorithms
MalwareDoki

Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains.

T1568.002
Domain Generation Algorithms
MalwareConficker

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

T1568.002
Domain Generation Algorithms
MalwarePOSHSPY

POSHSPY uses a DGA to derive command and control URLs from a word list.

T1568.002
Domain Generation Algorithms
MalwareMiniDuke

MiniDuke can use DGA to generate new Twitter URLs for C2.

T1568.002
Domain Generation Algorithms
MalwareDarkWatchman

DarkWatchman has used a DGA to generate a domain name for C2.

T1568.002
Domain Generation Algorithms
MalwareGrandoreiro

Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily.

T1568.002
Domain Generation Algorithms
MalwareShark

Shark can send DNS C2 communications using a unique domain generation algorithm.

T1568.002
Domain Generation Algorithms
MalwareBazar

Bazar can implement DGA using the current date as a seed variable.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.