Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1090.002 External Proxy |
GroupAPT39 | APT39 has used various tools to proxy C2 communications. |
| T1090.002 External Proxy |
GroupFIN5 | FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel. |
| T1090.002 External Proxy |
GroupAPT29 | APT29 uses compromised residential endpoints as proxies for defense evasion and network access. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1090.002 External Proxy |
GroupTonto Team | Tonto Team has routed their traffic through an external server in order to obfuscate their location. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1090.002 External Proxy |
GroupSilence | Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5. |
| T1090.003 Multi-hop Proxy |
GroupVolt Typhoon | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure. |
| T1090.003 Multi-hop Proxy |
GroupGamaredon Group | Gamaredon Group has used Tor for C2 traffic. |
| T1090.003 Multi-hop Proxy |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1090.003 Multi-hop Proxy |
GroupLeviathan | Leviathan has used multi-hop proxies to disguise the source of their malicious traffic. |
| T1090.003 Multi-hop Proxy |
GroupLotus Blossom | Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT29 | A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1090.003 Multi-hop Proxy |
GroupEmber Bear | Ember Bear has configured multi-hop proxies via ProxyChains within victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT28 | APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. |
| T1090.003 Multi-hop Proxy |
GroupFIN4 | |
| T1090.003 Multi-hop Proxy |
GroupInception | Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers. |
| T1090.003 Multi-hop Proxy |
GroupShinyHunters | ShinyHunters has used Tor to host their DLS. |
| T1090.004 Domain Fronting |
GroupAPT29 | APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic. |
| T1091 Replication Through Removable Media |
GroupGamaredon Group | Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host. |
| T1091 Replication Through Removable Media |
GroupFIN7 | FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands. |
| T1091 Replication Through Removable Media |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could spread through USB connections. |
| T1091 Replication Through Removable Media |
GroupTropic Trooper | Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine. |
| T1091 Replication Through Removable Media |
GroupAoqin Dragon | Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment. |
| T1091 Replication Through Removable Media |
GroupDarkhotel | Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| T1091 Replication Through Removable Media |
GroupLuminousMoth | LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| T1091 Replication Through Removable Media |
GroupAPT28 | APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted. |
| T1092 Communication Through Removable Media |
GroupAPT28 | APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted. |
| T1095 Non-Application Layer Protocol |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1095 Non-Application Layer Protocol |
GroupHAFNIUM | HAFNIUM has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
GroupFIN6 | FIN6 has used Metasploit Bind and Reverse TCP stagers. |
| T1095 Non-Application Layer Protocol |
GroupGamaredon Group | Gamaredon Group has used SOCKS5 over port 9050 for C2 communication. |
| T1095 Non-Application Layer Protocol |
GroupMustang Panda | Mustang Panda has utilized TCP-based reverse shells using cmd.exe. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1095 Non-Application Layer Protocol |
GroupBITTER | BITTER has used TCP for C2 communications. |
| T1095 Non-Application Layer Protocol |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities. |
| T1095 Non-Application Layer Protocol |
GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| T1095 Non-Application Layer Protocol |
GroupToddyCat | ToddyCat has used a passive backdoor that receives commands with UDP packets. |
| T1095 Non-Application Layer Protocol |
GroupMetador | Metador has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
GroupPLATINUM | PLATINUM has used the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel for command and control. |
| T1098 Account Manipulation |
GroupHAFNIUM | HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. |
| T1098 Account Manipulation |
GroupScattered Spider | Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere. |
| T1098 Account Manipulation |
GroupLazarus Group | Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account. |
| T1098 Account Manipulation |
GroupVOID MANTICORE | VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access. |
| T1098 Account Manipulation |
GroupTeamPCP | TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public. |
| T1098.001 Additional Cloud Credentials |
GroupStorm-0501 | Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT29 | APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT28 | APT28 has used a Powershell cmdlet to grant the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.