Real-world descriptions of how a group, tool or campaign used a technique.
166 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareQakBot | QakBot can send stolen information to C2 nodes including passwords, accounts, and emails. |
| T1041 Exfiltration Over C2 Channel |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to upload files to the C2 Server. |
| T1041 Exfiltration Over C2 Channel |
MalwareADVSTORESHELL | ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrifeWater | StrifeWater can send data and files from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareWarzoneRAT | WarzoneRAT can send collected victim data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareXORIndex Loader | XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
ToolShimRatReporter | ShimRatReporter sent generated reports to the C2 via HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
ToolSliver | Sliver can exfiltrate files from the victim using the |
| T1041 Exfiltration Over C2 Channel |
ToolSILENTTRINITY | SILENTTRINITY can transfer files from an infected host to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
ToolEmpire | Empire can send data gathered from a target through the command and control channel. |
| T1041 Exfiltration Over C2 Channel |
ToolPcShare | PcShare can upload files and information from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
ToolImminent Monitor | Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2. |
| T1041 Exfiltration Over C2 Channel |
ToolPupy | Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1041 Exfiltration Over C2 Channel |
MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.