ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareWoody RAT

Woody RAT can exfiltrate files from an infected machine to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareMafalda

Mafalda can send network system data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSquirrelwaffle

Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHexEval Loader

HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareAuTo Stealer

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.

T1041
Exfiltration Over C2 Channel
MalwareShrinkLocker

ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST.

T1041
Exfiltration Over C2 Channel
MalwareSombRAT

SombRAT has uploaded collected data and files from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files.

T1041
Exfiltration Over C2 Channel
MalwareFlawedAmmyy

FlawedAmmyy has sent data collected from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHOPLIGHT

HOPLIGHT has used its C2 channel to exfiltrate data.

T1041
Exfiltration Over C2 Channel
MalwareCuckoo Stealer

Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username.

T1041
Exfiltration Over C2 Channel
MalwareMobileOrder

MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareRDAT

RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOkrum

Data exfiltration is done by Okrum using the already opened channel with the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected credentials to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLine Dancer

Line Dancer exfiltrates collected data via command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareMispadu

Mispadu can sends the collected financial data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDoki

Doki has used Ngrok to establish C2 and exfiltrate data.

T1041
Exfiltration Over C2 Channel
MalwareHTTPTroy

HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command.

T1041
Exfiltration Over C2 Channel
MalwareMarkiRAT

MarkiRAT can exfiltrate locally stored data via its C2.

T1041
Exfiltration Over C2 Channel
MalwarePowerShower

PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days.

T1041
Exfiltration Over C2 Channel
MalwareNETEAGLE

NETEAGLE is capable of reading files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can upload collected files to the command-and-control server.

T1041
Exfiltration Over C2 Channel
MalwareRising Sun

Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2.

T1041
Exfiltration Over C2 Channel
MalwareChrommme

Chrommme can exfiltrate collected data via C2.

T1041
Exfiltration Over C2 Channel
MalwareFlagpro

Flagpro has exfiltrated data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLightSpy

To exfiltrate data, LightSpy configures each module to send an obfuscated JSON blob to hardcoded URL endpoints or paths aligned to the module name.

T1041
Exfiltration Over C2 Channel
MalwareGoldMax

GoldMax can exfiltrate files over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLine Runner

Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer.

T1041
Exfiltration Over C2 Channel
MalwarePteranodon

Pteranodon exfiltrates screenshot files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBeaverTail

BeaverTail has exfiltrated data collected from victim devices to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareROKRAT

ROKRAT can send collected files back over same C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareDyre

Dyre has the ability to send information staged on a compromised host externally to C2.

T1041
Exfiltration Over C2 Channel
MalwarePlugX

PlugX has exfiltrated stolen data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBisonal

Bisonal has added the exfiltrated data to the URL over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareS-Type

S-Type has uploaded data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareLumma Stealer

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareDustySky

DustySky has exfiltrated data to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLightNeuron

LightNeuron exfiltrates data over its email C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareDarkGate

DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials.

T1041
Exfiltration Over C2 Channel
MalwareMongall

Mongall can upload files and information from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSVCReady

SVCReady can send collected data in JSON format to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareThiefQuest

ThiefQuest exfiltrates targeted file extensions in the /Users/ folder to the command and control server via unencrypted HTTP. Network packets contain a string with two pieces of information: a file path and the contents of the file in a base64 encoded string.

T1041
Exfiltration Over C2 Channel
MalwareFoggyWeb

FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server.

T1041
Exfiltration Over C2 Channel
MalwareCaterpillar WebShell

Caterpillar WebShell can upload files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLODEINFO

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareCharmPower

CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST.

T1041
Exfiltration Over C2 Channel
MalwareMuddyViper

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1041
Exfiltration Over C2 Channel
MalwareEVILNUM

EVILNUM can upload files over the C2 channel from the infected host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.