ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareSMOKEDHAM

SMOKEDHAM has exfiltrated data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSagerunex

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareMetamorfo

Metamorfo can send the data it collects to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBandook

Bandook can upload files from a victim's machine over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMagicRAT

MagicRAT exfiltrates data via HTTP over existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareKONNI

KONNI has sent data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDnsSystem

DnsSystem can exfiltrate collected data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBLUELIGHT

BLUELIGHT has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareKGH_SPY

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareRedLine Stealer

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1041
Exfiltration Over C2 Channel
MalwareOopsIE

OopsIE can upload files from the victim's machine to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareAttor

Attor has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLitePower

LitePower can send collected data, including screenshots, over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBoxCaon

BoxCaon uploads files and data from a compromised host over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareNightClub

NightClub can use SMTP and DNS for file exfiltration and C2.

T1041
Exfiltration Over C2 Channel
MalwareCrutch

Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API).

T1041
Exfiltration Over C2 Channel
MalwareSDBbot

SDBbot has sent collected data from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1041
Exfiltration Over C2 Channel
MalwareGrandoreiro

Grandoreiro can send data it retrieves to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDrovorub

Drovorub can exfiltrate files over C2 infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareShark

Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareSUGARDUMP

SUGARDUMP has sent stolen credentials and other data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1041
Exfiltration Over C2 Channel
MalwareLunarMail

LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareHotCroissant

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1041
Exfiltration Over C2 Channel
MalwareREvil

REvil can exfiltrate host and malware information to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOilBooster

OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareCyclops Blink

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTajMahal

TajMahal has the ability to send collected files over its C2.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareIPsec Helper

IPsec Helper exfiltrates specific files through its command and control framework.

T1041
Exfiltration Over C2 Channel
MalwareSolar

Solar can send staged files to C2 for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareGoldenSpy

GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006.

T1041
Exfiltration Over C2 Channel
MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareMacMa

MacMa exfiltrates data from a supplied path over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareFunnyDream

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1041
Exfiltration Over C2 Channel
MalwareSysUpdate

SysUpdate has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOutSteel

OutSteel can upload files from a compromised host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLAMEHUG

LAMEHUG can exfiltrate collected system information and documents to C2.

T1041
Exfiltration Over C2 Channel
MalwareMango

Mango can use its HTTP C2 channel for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareKessel

Kessel has exfiltrated information gathered from the infected system to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareGrimAgent

GrimAgent has sent data related to a compromise host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePHASEJAM

PHASEJAM has the ability to exfiltrate data from the victim appliance.

T1041
Exfiltration Over C2 Channel
MalwareLokibot

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1041
Exfiltration Over C2 Channel
MalwareCallMe

CallMe exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwarePoetRAT

PoetRAT has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePenquin

Penquin can execute the command code do_upload to send files to C2.

T1041
Exfiltration Over C2 Channel
MalwareCannon

Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.