ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupBITTER

BITTER has used HTTP POST requests for C2.

T1071.001
Web Protocols
GroupRedCurl

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

T1071.001
Web Protocols
GroupStealth Falcon

Stealth Falcon malware communicates with its C2 server via HTTPS.

T1071.001
Web Protocols
GroupDark Caracal

Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.

T1071.001
Web Protocols
GroupChimera

Chimera has used HTTPS for C2 communications.

T1071.001
Web Protocols
GroupMedusa Group

Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).

T1071.001
Web Protocols
GroupBRONZE BUTLER

BRONZE BUTLER malware has used HTTP for C2.

T1071.001
Web Protocols
GroupTA551

TA551 has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWindshift

Windshift has used tools that communicate with C2 over HTTP.

T1071.001
Web Protocols
GroupLuminousMoth

LuminousMoth has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.001
Web Protocols
GroupMetador

Metador has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1071.001
Web Protocols
GroupFIN4

FIN4 has used HTTP POST requests to transmit data.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.001
Web Protocols
GroupWizard Spider

Wizard Spider has used HTTP for network communications.

T1071.001
Web Protocols
GroupMoonstone Sleet

Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1071.001
Web Protocols
GroupVOID MANTICORE

VOID MANTICORE has utilized HTTPS for communication to C2 domains.

T1071.001
Web Protocols
GroupDaggerfly

Daggerfly uses HTTP for command and control communication.

T1071.001
Web Protocols
GroupRancor

Rancor has used HTTP for C2.

T1071.001
Web Protocols
GroupWIRTE

WIRTE has used HTTP for network communication.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1071.001
Web Protocols
GroupThreat Group-3390

Threat Group-3390 malware has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT33

APT33 has used HTTP for command and control.

T1071.001
Web Protocols
GroupFIN8

FIN8 has used HTTPS for command and control.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1071.001
Web Protocols
GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

T1071.002
File Transfer Protocols
GroupKimsuky

Kimsuky has used FTP to download additional malware to the target machine.

T1071.002
File Transfer Protocols
GroupAPT41

APT41 used exploit payloads that initiate download via ftp.

T1071.002
File Transfer Protocols
GroupDragonfly

Dragonfly has used SMB for C2.

T1071.002
File Transfer Protocols
GroupSilverTerrier

SilverTerrier uses FTP for C2 communications.

T1071.002
File Transfer Protocols
GroupMirrorFace

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.

T1071.003
Mail Protocols
GroupKimsuky

Kimsuky has used e-mail to send exfiltrated data to C2 servers.

T1071.003
Mail Protocols
GroupAPT32

APT32 has used email for C2 via an Office macro.

T1071.003
Mail Protocols
GroupContagious Interview

Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement.

T1071.003
Mail Protocols
GroupSilverTerrier

SilverTerrier uses SMTP for C2 communications.

T1071.003
Mail Protocols
GroupTurla

Turla has used multiple backdoors which communicate with a C2 server via email attachments.

T1071.003
Mail Protocols
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1071.004
DNS
GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

T1071.004
DNS
GroupAPT18

APT18 uses DNS for C2 communications.

T1071.004
DNS
GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1071.004
DNS
GroupTropic Trooper

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

T1071.004
DNS
GroupKe3chang

Ke3chang malware RoyalDNS has used DNS for C2.

T1071.004
DNS
GroupChimera

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.

T1071.004
DNS
GroupEmber Bear

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.

T1071.004
DNS
GroupLazyScripter

LazyScripter has leveraged dynamic DNS providers for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.