Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used a custom binary protocol over TCP port 443 for C2. |
| T1571 Non-Standard Port |
MalwareCyclops Blink | Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic. |
| T1571 Non-Standard Port |
MalwareGoldenSpy | GoldenSpy has used HTTP over ports 9005 and 9006 for network traffic, 9002 for C2 requests, 33666 as a WebSocket, and 8090 to download files. |
| T1571 Non-Standard Port |
MalwareHARDRAIN | HARDRAIN binds and listens on port 443 with a FakeTLS method. |
| T1571 Non-Standard Port |
MalwareMacMa | MacMa has used TCP port 5633 for C2 Communication. |
| T1571 Non-Standard Port |
MalwarePoetRAT | PoetRAT used TLS to encrypt communications over port 143 |
| T1571 Non-Standard Port |
MalwareZxShell | ZxShell can use ports 1985 and 1986 in HTTP/S communication. |
| T1571 Non-Standard Port |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has the ability to bind on a localhost and listen on port 8300. |
| T1571 Non-Standard Port |
MalwarenjRAT | njRAT has used port 1177 for HTTP C2 communications. |
| T1571 Non-Standard Port |
MalwareVIRTUALPITA | VIRTUALPITA has created listeners on hard coded TCP ports such as 2233, 7475, and 18098. |
| T1571 Non-Standard Port |
ToolCovenant | Covenant listeners and controllers can be configured to use non-standard ports. |
| T1571 Non-Standard Port |
ToolQuasarRAT | QuasarRAT can use port 4782 on the compromised host for TCP callbacks. |
| T1572 Protocol Tunneling |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads. |
| T1572 Protocol Tunneling |
CampaignCutting Edge | During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS. |
| T1572 Protocol Tunneling |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment. |
| T1572 Protocol Tunneling |
CampaignC0027 | During C0027, Scattered Spider used SSH tunneling in targeted environments. |
| T1572 Protocol Tunneling |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler software to establish a “Yamux” TLS-based C2 channel with an external server(s). |
| T1572 Protocol Tunneling |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain. |
| T1572 Protocol Tunneling |
GroupSalt Typhoon | Salt Typhoon has modified device configurations to create and use Generic Routing Encapsulation (GRE) tunnels. |
| T1572 Protocol Tunneling |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1572 Protocol Tunneling |
GroupFIN7 | FIN7 has tunneled C2 traffic via OpenSSH. |
| T1572 Protocol Tunneling |
GroupMustang Panda | Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445. |
| T1572 Protocol Tunneling |
GroupScattered Spider | Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
| T1572 Protocol Tunneling |
GroupLeviathan | Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure. |
| T1572 Protocol Tunneling |
GroupCinnamon Tempest | Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel. |
| T1572 Protocol Tunneling |
GroupChimera | Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS. |
| T1572 Protocol Tunneling |
GroupEmber Bear | Ember Bear has used ProxyChains to tunnel protocols to internal networks. |
| T1572 Protocol Tunneling |
GroupFox Kitten | Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion. |
| T1572 Protocol Tunneling |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1572 Protocol Tunneling |
GroupVOID MANTICORE | VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices. |
| T1572 Protocol Tunneling |
GroupMagic Hound | Magic Hound has used Plink to tunnel RDP over SSH. |
| T1572 Protocol Tunneling |
GroupFIN13 | FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets. |
| T1572 Protocol Tunneling |
MalwareBRICKSTORM | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1572 Protocol Tunneling |
MalwarereGeorg | reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
| T1572 Protocol Tunneling |
MalwareFLIPSIDE | FLIPSIDE uses RDP to tunnel traffic from a victim environment. |
| T1572 Protocol Tunneling |
MalwareUroburos | Uroburos has the ability to communicate over custom communications methodologies that ride over common network protocols including raw TCP and UDP sockets, HTTP, SMTP, and DNS. |
| T1572 Protocol Tunneling |
MalwareHiddenFace | HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2. |
| T1572 Protocol Tunneling |
MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1572 Protocol Tunneling |
MalwareMilan | Milan can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareCyclops Blink | Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes. |
| T1572 Protocol Tunneling |
MalwareNeo-reGeorg | Neo-reGeorg can tunnel data in and out of targeted networks. |
| T1572 Protocol Tunneling |
MalwareFunnyDream | FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1572 Protocol Tunneling |
MalwareHeyoka Backdoor | Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers. |
| T1572 Protocol Tunneling |
MalwareLunarWeb | LunarWeb can run a custom binary protocol under HTTPS for C2. |
| T1572 Protocol Tunneling |
MalwareIndustroyer | Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel. |
| T1572 Protocol Tunneling |
MalwareKevin | Kevin can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareQakBot | The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol. |
| T1572 Protocol Tunneling |
Toolngrok | ngrok can tunnel RDP and other services securely over internet connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.