Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1570 Lateral Tool Transfer |
GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| T1570 Lateral Tool Transfer |
GroupGALLIUM | GALLIUM has used PsExec to move laterally between hosts in the target network. |
| T1570 Lateral Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has copied web shells between servers in targeted environments. |
| T1570 Lateral Tool Transfer |
GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| T1570 Lateral Tool Transfer |
GroupAPT32 | APT32 has deployed tools after moving laterally using administrative accounts. |
| T1570 Lateral Tool Transfer |
GroupStorm-1811 | Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1570 Lateral Tool Transfer |
GroupUNC3886 | UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs. |
| T1570 Lateral Tool Transfer |
GroupAoqin Dragon | Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1570 Lateral Tool Transfer |
GroupChimera | Chimera has copied tools between compromised hosts using SMB. |
| T1570 Lateral Tool Transfer |
GroupMedusa Group | Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment. |
| T1570 Lateral Tool Transfer |
GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| T1570 Lateral Tool Transfer |
GroupAgrius | Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as |
| T1570 Lateral Tool Transfer |
GroupINC Ransom | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
GroupWizard Spider | Wizard Spider has used stolen credentials to copy tools into the |
| T1570 Lateral Tool Transfer |
GroupVelvet Ant | Velvet Ant transferred files laterally within victim networks through the Impacket toolkit. |
| T1570 Lateral Tool Transfer |
GroupMagic Hound | Magic Hound has copied tools within a compromised network using RDP. |
| T1570 Lateral Tool Transfer |
GroupFIN10 | FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally. |
| T1570 Lateral Tool Transfer |
MalwareStuxnet | Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network. |
| T1570 Lateral Tool Transfer |
MalwareHavoc | Havoc has the ability to copy files from one location to another. |
| T1570 Lateral Tool Transfer |
MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| T1570 Lateral Tool Transfer |
MalwareOlympic Destroyer | Olympic Destroyer attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareSameCoin | SameCoin can copy its wiper executable to remote machines within the same Active Directory. |
| T1570 Lateral Tool Transfer |
MalwareBlackCat | BlackCat can replicate itself across connected servers via `psexec`. |
| T1570 Lateral Tool Transfer |
MalwareLucifer | Lucifer can use certutil for propagation on Windows hosts within intranets. |
| T1570 Lateral Tool Transfer |
MalwareLockerGoga | LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating. |
| T1570 Lateral Tool Transfer |
MalwareDustySky | DustySky searches for network drives and removable media and duplicates itself onto them. |
| T1570 Lateral Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems. |
| T1570 Lateral Tool Transfer |
MalwareWannaCry | WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPIE | VIRTUALPIE has file transfer capabilities. |
| T1570 Lateral Tool Transfer |
MalwareShamoon | Shamoon attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareBlackByte Ransomware | BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders. |
| T1570 Lateral Tool Transfer |
MalwareIPsec Helper | IPsec Helper can download additional payloads from command and control nodes and execute them. |
| T1570 Lateral Tool Transfer |
MalwareOutSteel | OutSteel can download the Saint Bot malware for follow-on execution. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA is capable of file transfer and arbitrary command execution. |
| T1570 Lateral Tool Transfer |
MalwareQilin | Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment. |
| T1570 Lateral Tool Transfer |
MalwareINC Ransomware | INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
MalwareHermeticWizard | HermeticWizard can copy files to other machines on a compromised network. |
| T1570 Lateral Tool Transfer |
ToolImpacket | Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks. |
| T1570 Lateral Tool Transfer |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers. |
| T1570 Lateral Tool Transfer |
Toolcmd | cmd can be used to copy files to/from a remotely connected internal system. |
| T1570 Lateral Tool Transfer |
Toolesentutl | esentutl can be used to copy files to/from a remote share. |
| T1570 Lateral Tool Transfer |
ToolExpand | Expand can be used to download or upload a file over a network share. |
| T1570 Lateral Tool Transfer |
Toolftp | ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment. |
| T1570 Lateral Tool Transfer |
ToolPsExec | PsExec can be used to download or upload a file over a network share. |
| T1571 Non-Standard Port |
CampaignKV Botnet Activity | KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity. |
| T1571 Non-Standard Port |
CampaignRedPenguin | During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default. |
| T1571 Non-Standard Port |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
CampaignC0018 | During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.