ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1570
Lateral Tool Transfer
GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

T1570
Lateral Tool Transfer
GroupGALLIUM

GALLIUM has used PsExec to move laterally between hosts in the target network.

T1570
Lateral Tool Transfer
GroupVolt Typhoon

Volt Typhoon has copied web shells between servers in targeted environments.

T1570
Lateral Tool Transfer
GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

T1570
Lateral Tool Transfer
GroupAPT32

APT32 has deployed tools after moving laterally using administrative accounts.

T1570
Lateral Tool Transfer
GroupStorm-1811

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.

T1570
Lateral Tool Transfer
GroupSandworm Team

Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access.

T1570
Lateral Tool Transfer
GroupUNC3886

UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs.

T1570
Lateral Tool Transfer
GroupAoqin Dragon

Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices.

T1570
Lateral Tool Transfer
GroupTurla

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.

T1570
Lateral Tool Transfer
GroupChimera

Chimera has copied tools between compromised hosts using SMB.

T1570
Lateral Tool Transfer
GroupMedusa Group

Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.

T1570
Lateral Tool Transfer
GroupEmber Bear

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.

T1570
Lateral Tool Transfer
GroupAgrius

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.

T1570
Lateral Tool Transfer
GroupINC Ransom

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
GroupWizard Spider

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.

T1570
Lateral Tool Transfer
GroupVelvet Ant

Velvet Ant transferred files laterally within victim networks through the Impacket toolkit.

T1570
Lateral Tool Transfer
GroupMagic Hound

Magic Hound has copied tools within a compromised network using RDP.

T1570
Lateral Tool Transfer
GroupFIN10

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

T1570
Lateral Tool Transfer
MalwareStuxnet

Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network.

T1570
Lateral Tool Transfer
MalwareHavoc

Havoc has the ability to copy files from one location to another.

T1570
Lateral Tool Transfer
MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

T1570
Lateral Tool Transfer
MalwareOlympic Destroyer

Olympic Destroyer attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareSameCoin

SameCoin can copy its wiper executable to remote machines within the same Active Directory.

T1570
Lateral Tool Transfer
MalwareBlackCat

BlackCat can replicate itself across connected servers via `psexec`.

T1570
Lateral Tool Transfer
MalwareLucifer

Lucifer can use certutil for propagation on Windows hosts within intranets.

T1570
Lateral Tool Transfer
MalwareLockerGoga

LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.

T1570
Lateral Tool Transfer
MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

T1570
Lateral Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.

T1570
Lateral Tool Transfer
MalwareWannaCry

WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.

T1570
Lateral Tool Transfer
MalwareVIRTUALPIE

VIRTUALPIE has file transfer capabilities.

T1570
Lateral Tool Transfer
MalwareShamoon

Shamoon attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareBlackByte Ransomware

BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders.

T1570
Lateral Tool Transfer
MalwareIPsec Helper

IPsec Helper can download additional payloads from command and control nodes and execute them.

T1570
Lateral Tool Transfer
MalwareOutSteel

OutSteel can download the Saint Bot malware for follow-on execution.

T1570
Lateral Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA is capable of file transfer and arbitrary command execution.

T1570
Lateral Tool Transfer
MalwareQilin

Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.

T1570
Lateral Tool Transfer
MalwareINC Ransomware

INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
MalwareHermeticWizard

HermeticWizard can copy files to other machines on a compromised network.

T1570
Lateral Tool Transfer
ToolImpacket

Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks.

T1570
Lateral Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers.

T1570
Lateral Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected internal system.

T1570
Lateral Tool Transfer
Toolesentutl

esentutl can be used to copy files to/from a remote share.

T1570
Lateral Tool Transfer
ToolExpand

Expand can be used to download or upload a file over a network share.

T1570
Lateral Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment.

T1570
Lateral Tool Transfer
ToolPsExec

PsExec can be used to download or upload a file over a network share.

T1571
Non-Standard Port
CampaignKV Botnet Activity

KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity.

T1571
Non-Standard Port
CampaignRedPenguin

During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.

T1571
Non-Standard Port
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication.

T1571
Non-Standard Port
CampaignC0018

During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.