Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupBITTER | BITTER has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
GroupRedCurl | RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications. |
| T1071.001 Web Protocols |
GroupStealth Falcon | Stealth Falcon malware communicates with its C2 server via HTTPS. |
| T1071.001 Web Protocols |
GroupDark Caracal | Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”. |
| T1071.001 Web Protocols |
GroupChimera | Chimera has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupMedusa Group | Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS). |
| T1071.001 Web Protocols |
GroupBRONZE BUTLER | BRONZE BUTLER malware has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupTA551 | TA551 has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupWindshift | Windshift has used tools that communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
GroupLuminousMoth | LuminousMoth has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.001 Web Protocols |
GroupMetador | Metador has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1071.001 Web Protocols |
GroupFIN4 | FIN4 has used HTTP POST requests to transmit data. |
| T1071.001 Web Protocols |
GroupCobalt Group | Cobalt Group has used HTTPS for C2. |
| T1071.001 Web Protocols |
GroupWizard Spider | Wizard Spider has used HTTP for network communications. |
| T1071.001 Web Protocols |
GroupMoonstone Sleet | Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1071.001 Web Protocols |
GroupInception | Inception has used HTTP, HTTPS, and WebDav in network communications. |
| T1071.001 Web Protocols |
GroupVOID MANTICORE | VOID MANTICORE has utilized HTTPS for communication to C2 domains. |
| T1071.001 Web Protocols |
GroupDaggerfly | Daggerfly uses HTTP for command and control communication. |
| T1071.001 Web Protocols |
GroupRancor | Rancor has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupWIRTE | WIRTE has used HTTP for network communication. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupThreat Group-3390 | Threat Group-3390 malware has used HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT33 | APT33 has used HTTP for command and control. |
| T1071.001 Web Protocols |
GroupFIN8 | FIN8 has used HTTPS for command and control. |
| T1071.001 Web Protocols |
GroupFIN13 | FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data. |
| T1071.001 Web Protocols |
GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1071.002 File Transfer Protocols |
GroupKimsuky | Kimsuky has used FTP to download additional malware to the target machine. |
| T1071.002 File Transfer Protocols |
GroupAPT41 | |
| T1071.002 File Transfer Protocols |
GroupDragonfly | Dragonfly has used SMB for C2. |
| T1071.002 File Transfer Protocols |
GroupSilverTerrier | SilverTerrier uses FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
GroupMirrorFace | MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer. |
| T1071.003 Mail Protocols |
GroupKimsuky | Kimsuky has used e-mail to send exfiltrated data to C2 servers. |
| T1071.003 Mail Protocols |
GroupAPT32 | APT32 has used email for C2 via an Office macro. |
| T1071.003 Mail Protocols |
GroupContagious Interview | Contagious Interview has utilized email notifications from malware distribution servers to track victim engagement. |
| T1071.003 Mail Protocols |
GroupSilverTerrier | SilverTerrier uses SMTP for C2 communications. |
| T1071.003 Mail Protocols |
GroupTurla | Turla has used multiple backdoors which communicate with a C2 server via email attachments. |
| T1071.003 Mail Protocols |
GroupAPT28 | APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims. |
| T1071.004 DNS |
GroupAPT41 | APT41 used DNS for C2 communications. |
| T1071.004 DNS |
GroupFIN7 | FIN7 has performed C2 using DNS via A, OPT, and TXT records. |
| T1071.004 DNS |
GroupAPT18 | APT18 uses DNS for C2 communications. |
| T1071.004 DNS |
GroupAPT39 | APT39 has used remote access tools that leverage DNS in communications with C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1071.004 DNS |
GroupTropic Trooper | Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol. |
| T1071.004 DNS |
GroupKe3chang | Ke3chang malware RoyalDNS has used DNS for C2. |
| T1071.004 DNS |
GroupChimera | Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic. |
| T1071.004 DNS |
GroupEmber Bear | Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes. |
| T1071.004 DNS |
GroupLazyScripter | LazyScripter has leveraged dynamic DNS providers for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.