Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareSMOKEDHAM | SMOKEDHAM has exfiltrated data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSagerunex | Sagerunex encrypts collected system data then exfiltrates via existing command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareMetamorfo | Metamorfo can send the data it collects to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBandook | Bandook can upload files from a victim's machine over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMagicRAT | MagicRAT exfiltrates data via HTTP over existing command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareKONNI | KONNI has sent data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDnsSystem | DnsSystem can exfiltrate collected data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBLUELIGHT | BLUELIGHT has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareKGH_SPY | KGH_SPY can exfiltrate collected information from the host to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareRedLine Stealer | RedLine Stealer has sent victim data to its C2 server or RedLine panel server. |
| T1041 Exfiltration Over C2 Channel |
MalwareOopsIE | OopsIE can upload files from the victim's machine to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareAttor | Attor has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLitePower | LitePower can send collected data, including screenshots, over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBoxCaon | BoxCaon uploads files and data from a compromised host over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareNightClub | NightClub can use SMTP and DNS for file exfiltration and C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrutch | Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API). |
| T1041 Exfiltration Over C2 Channel |
MalwareSDBbot | SDBbot has sent collected data from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrandoreiro | Grandoreiro can send data it retrieves to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDrovorub | Drovorub can exfiltrate files over C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareShark | Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareSUGARDUMP | SUGARDUMP has sent stolen credentials and other data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareZebrocy | Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareLunarMail | LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareHotCroissant | HotCroissant has the ability to download files from the infected host to the command and control (C2) server. |
| T1041 Exfiltration Over C2 Channel |
MalwareREvil | REvil can exfiltrate host and malware information to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareValak | Valak has the ability to exfiltrate data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOilBooster | OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareCyclops Blink | Cyclops Blink has the ability to upload exfiltrated files to a C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTajMahal | TajMahal has the ability to send collected files over its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareRaccoon Stealer | Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareIPsec Helper | IPsec Helper exfiltrates specific files through its command and control framework. |
| T1041 Exfiltration Over C2 Channel |
MalwareSolar | Solar can send staged files to C2 for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldenSpy | GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006. |
| T1041 Exfiltration Over C2 Channel |
MalwareAshTag | AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareCarberp | Carberp has exfiltrated data via HTTP to already established C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareMacMa | MacMa exfiltrates data from a supplied path over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareFunnyDream | FunnyDream can execute commands, including gathering user information, and send the results to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareSysUpdate | SysUpdate has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOutSteel | OutSteel can upload files from a compromised host over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLAMEHUG | LAMEHUG can exfiltrate collected system information and documents to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareMango | Mango can use its HTTP C2 channel for exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareKessel | Kessel has exfiltrated information gathered from the infected system to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrimAgent | GrimAgent has sent data related to a compromise host over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePHASEJAM | PHASEJAM has the ability to exfiltrate data from the victim appliance. |
| T1041 Exfiltration Over C2 Channel |
MalwareLokibot | Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data. |
| T1041 Exfiltration Over C2 Channel |
MalwareCallMe | CallMe exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwarePoetRAT | PoetRAT has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePenquin | Penquin can execute the command code |
| T1041 Exfiltration Over C2 Channel |
MalwareCannon | Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.