Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1567.002 Exfiltration to Cloud Storage |
MalwareOctopus | Octopus has exfiltrated data to file sharing sites. |
| T1567.002 Exfiltration to Cloud Storage |
MalwarePcexter | Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`. |
| T1567.002 Exfiltration to Cloud Storage |
ToolEmpire | Empire can use Dropbox for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
ToolRclone | Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. |
| T1567.004 Exfiltration Over Webhook |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data. |
| T1567.004 Exfiltration Over Webhook |
MalwareShai-Hulud | Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`. |
| T1568 Dynamic Resolution |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322. |
| T1568 Dynamic Resolution |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1568 Dynamic Resolution |
CampaignOperation Spalax | For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure. |
| T1568 Dynamic Resolution |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2. |
| T1568 Dynamic Resolution |
CampaignNight Dragon | During Night Dragon, threat actors used dynamic DNS services for C2. |
| T1568 Dynamic Resolution |
CampaignC0026 | During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA. |
| T1568 Dynamic Resolution |
GroupKimsuky | Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea. |
| T1568 Dynamic Resolution |
GroupRedEcho | RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1568 Dynamic Resolution |
GroupGamaredon Group | Gamaredon Group has incorporated dynamic DNS domains in its infrastructure. |
| T1568 Dynamic Resolution |
GroupTA2541 | TA2541 has used dynamic DNS services for C2 infrastructure. |
| T1568 Dynamic Resolution |
GroupBITTER | BITTER has used DDNS for C2 communications. |
| T1568 Dynamic Resolution |
GroupAPT29 | APT29 has used Dynamic DNS providers for their malware C2 infrastructure. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1568 Dynamic Resolution |
GroupTransparent Tribe | Transparent Tribe has used dynamic DNS services to set up C2. |
| T1568 Dynamic Resolution |
MalwareBRICKSTORM | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses. |
| T1568 Dynamic Resolution |
MalwareTomiris | Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2. |
| T1568 Dynamic Resolution |
MalwareNETEAGLE | NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2. |
| T1568 Dynamic Resolution |
MalwareBisonal | Bisonal has used a dynamic DNS service for C2. |
| T1568 Dynamic Resolution |
MalwareRTM | RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain. |
| T1568 Dynamic Resolution |
MalwareSUNBURST | SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain. |
| T1568 Dynamic Resolution |
MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
| T1568 Dynamic Resolution |
MalwareGelsemium | Gelsemium can use dynamic DNS domain names in C2. |
| T1568 Dynamic Resolution |
ToolAsyncRAT | AsyncRAT can be configured to use dynamic DNS. |
| T1568 Dynamic Resolution |
ToolRemcos | Remcos has used dynamic DNS domains in C2 communications. |
| T1568.001 Fast Flux DNS |
GroupmenuPass | menuPass has used dynamic DNS service providers to host malicious domains. |
| T1568.001 Fast Flux DNS |
GroupGamaredon Group | Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method. |
| T1568.001 Fast Flux DNS |
GroupTA505 | TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs. |
| T1568.001 Fast Flux DNS |
MalwareAmadey | Amadey has used fast flux DNS for its C2. |
| T1568.001 Fast Flux DNS |
Malwaregh0st RAT | gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses. |
| T1568.001 Fast Flux DNS |
MalwarenjRAT | njRAT has used a fast flux DNS for C2 IP resolution. |
| T1568.002 Domain Generation Algorithms |
GroupAPT41 | APT41 has used DGAs to change their C2 servers monthly. |
| T1568.002 Domain Generation Algorithms |
GroupTA551 | TA551 has used a DGA to generate URLs from executed macros. |
| T1568.002 Domain Generation Algorithms |
MalwareUrsnif | Ursnif has used a DGA to generate domain names for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareAria-body | Aria-body has the ability to use a DGA for C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareSombRAT | SombRAT can use a custom DGA to generate a subdomain for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDoki | Doki has used the DynDNS service and a DGA based on the Dogecoin blockchain to generate C2 domains. |
| T1568.002 Domain Generation Algorithms |
MalwareConficker | Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
| T1568.002 Domain Generation Algorithms |
MalwarePOSHSPY | POSHSPY uses a DGA to derive command and control URLs from a word list. |
| T1568.002 Domain Generation Algorithms |
MalwareMiniDuke | MiniDuke can use DGA to generate new Twitter URLs for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareDarkWatchman | DarkWatchman has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareGrandoreiro | Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
| T1568.002 Domain Generation Algorithms |
MalwareBazar | Bazar can implement DGA using the current date as a seed variable. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.