Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2. |
| T1571 Non-Standard Port |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008. |
| T1571 Non-Standard Port |
CampaignOperation Wocao | During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000. |
| T1571 Non-Standard Port |
CampaignQuad7 Activity | Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2. |
| T1571 Non-Standard Port |
GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| T1571 Non-Standard Port |
GroupMuddyWater | MuddyWater has used ports 8043 and 8848 for botnet C2 communication. |
| T1571 Non-Standard Port |
GroupRedEcho | RedEcho has used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
| T1571 Non-Standard Port |
GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| T1571 Non-Standard Port |
GroupSandworm Team | Sandworm Team has used port 6789 to accept connections on the group's SSH server. |
| T1571 Non-Standard Port |
GroupRocke | Rocke's miner connects to a C2 server using port 51640. |
| T1571 Non-Standard Port |
GroupContagious Interview | Contagious Interview has used TCP port 1224 for C2. |
| T1571 Non-Standard Port |
GroupDarkVishnya | DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| T1571 Non-Standard Port |
GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| T1571 Non-Standard Port |
GroupAPT-C-36 | APT-C-36 has used port 4050 for C2 communications. |
| T1571 Non-Standard Port |
GroupLazarus Group | Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches. |
| T1571 Non-Standard Port |
GroupSilence | Silence has used port 444 when sending data about the system from the client to the server. |
| T1571 Non-Standard Port |
GroupVelvet Ant | Velvet Ant has used random high number ports for PlugX listeners on victim devices. |
| T1571 Non-Standard Port |
GroupWIRTE | WIRTE has used HTTPS over ports 2083 and 2087 for C2. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
| T1571 Non-Standard Port |
GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
| T1571 Non-Standard Port |
MalwareTrickBot | Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443. |
| T1571 Non-Standard Port |
MalwarePikabot | Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication. |
| T1571 Non-Standard Port |
MalwareRotaJakiro | RotaJakiro uses a custom binary protocol over TCP port 443. |
| T1571 Non-Standard Port |
MalwareSardonic | Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443. |
| T1571 Non-Standard Port |
MalwareRedLeaves | RedLeaves can use HTTP over non-standard ports, such as 995, for C2. |
| T1571 Non-Standard Port |
MalwareGravityRAT | GravityRAT has used HTTP over a non-standard port, such as TCP port 46769. |
| T1571 Non-Standard Port |
MalwareInvisibleFerret | InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637. |
| T1571 Non-Standard Port |
MalwareBankshot | Bankshot binds and listens on port 1058 for HTTP traffic while also utilizing a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareStrongPity | StrongPity has used HTTPS over port 1402 in C2 communication. |
| T1571 Non-Standard Port |
MalwareHannotog | Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes. |
| T1571 Non-Standard Port |
MalwareEmotet | Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S. |
| T1571 Non-Standard Port |
MalwareSystemBC | The server component of SystemBC has used various TCP ports for C2 communication. |
| T1571 Non-Standard Port |
MalwarePingPull | PingPull can use HTTPS over port 8080 for C2. |
| T1571 Non-Standard Port |
MalwareSUGARUSH | SUGARUSH has used port 4585 for a TCP connection to its C2. |
| T1571 Non-Standard Port |
MalwareHOPLIGHT | HOPLIGHT has connected outbound over TCP port 443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareRaspberry Robin | Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic. |
| T1571 Non-Standard Port |
MalwareBeaverTail | BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
| T1571 Non-Standard Port |
MalwarePlugX | PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities. |
| T1571 Non-Standard Port |
MalwareTYPEFRAME | TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareVIRTUALPIE | VIRTUALPIE has created listeners on hard coded TCP port 546. |
| T1571 Non-Standard Port |
MalwareBendyBear | BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2. |
| T1571 Non-Standard Port |
MalwareGlassWorm | GlassWorm has distributed C2 using BitTorrent’s Distributed Hash Table (DHT) network to harness a decentralized command capability. |
| T1571 Non-Standard Port |
MalwareMetamorfo | Metamorfo has communicated with hosts over raw TCP on port 9999. |
| T1571 Non-Standard Port |
MalwareRTM | RTM used Port 44443 for its VNC module. |
| T1571 Non-Standard Port |
MalwareDerusbi | Derusbi has used unencrypted HTTP on port 443 for C2. |
| T1571 Non-Standard Port |
MalwareWellMail | WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications. |
| T1571 Non-Standard Port |
MalwareBADCALL | BADCALL communicates on ports 443 and 8000 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareMoonWind | MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports. |
| T1571 Non-Standard Port |
MalwareHiddenFace | HiddenFace's passive mode listens on TCP 47000. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.