Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareWoody RAT | Woody RAT can exfiltrate files from an infected machine to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareMafalda | Mafalda can send network system data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSquirrelwaffle | Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHexEval Loader | HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareAuTo Stealer | AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1041 Exfiltration Over C2 Channel |
MalwareSombRAT | SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlawedAmmyy | FlawedAmmyy has sent data collected from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHOPLIGHT | HOPLIGHT has used its C2 channel to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareCuckoo Stealer | Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username. |
| T1041 Exfiltration Over C2 Channel |
MalwareMobileOrder | MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareRDAT | RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOkrum | Data exfiltration is done by Okrum using the already opened channel with the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated collected credentials to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Dancer | Line Dancer exfiltrates collected data via command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareMispadu | Mispadu can sends the collected financial data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDoki | Doki has used Ngrok to establish C2 and exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareHTTPTroy | HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command. |
| T1041 Exfiltration Over C2 Channel |
MalwareMarkiRAT | MarkiRAT can exfiltrate locally stored data via its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerShower | PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days. |
| T1041 Exfiltration Over C2 Channel |
MalwareNETEAGLE | NETEAGLE is capable of reading files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1041 Exfiltration Over C2 Channel |
MalwareRising Sun | Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareChrommme | Chrommme can exfiltrate collected data via C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlagpro | Flagpro has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightSpy | To exfiltrate data, LightSpy configures each module to send an obfuscated JSON blob to hardcoded URL endpoints or paths aligned to the module name. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Runner | Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer. |
| T1041 Exfiltration Over C2 Channel |
MalwarePteranodon | Pteranodon exfiltrates screenshot files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareROKRAT | ROKRAT can send collected files back over same C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDyre | Dyre has the ability to send information staged on a compromised host externally to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePlugX | PlugX has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBisonal | Bisonal has added the exfiltrated data to the URL over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareS-Type | S-Type has uploaded data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareDustySky | DustySky has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightNeuron | LightNeuron exfiltrates data over its email C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDarkGate | DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials. |
| T1041 Exfiltration Over C2 Channel |
MalwareMongall | Mongall can upload files and information from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSVCReady | SVCReady can send collected data in JSON format to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareThiefQuest | ThiefQuest exfiltrates targeted file extensions in the |
| T1041 Exfiltration Over C2 Channel |
MalwareFoggyWeb | FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server. |
| T1041 Exfiltration Over C2 Channel |
MalwareCaterpillar WebShell | Caterpillar WebShell can upload files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLatrodectus | Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLODEINFO | LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareCharmPower | CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST. |
| T1041 Exfiltration Over C2 Channel |
MalwareMuddyViper | MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk. |
| T1041 Exfiltration Over C2 Channel |
MalwareEVILNUM | EVILNUM can upload files over the C2 channel from the infected host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.