Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareCreepySnail | CreepySnail can connect to C2 for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareTroll Stealer | Troll Stealer exfiltrates collected information to its command and control infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareEbury | Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwarenjRAT | njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information. |
| T1041 Exfiltration Over C2 Channel |
MalwareManjusaka | Manjusaka data exfiltration takes place over HTTP channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareIceApple | IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareShai-Hulud | Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1041 Exfiltration Over C2 Channel |
MalwaremetaMain | metaMain can upload collected files and data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSideTwist | SideTwist has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMechaFlounder | MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePsylo | Psylo exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareMis-Type | Mis-Type has transmitted collected files and data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareXCSSET | XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOctopus | Octopus has uploaded stolen files and data from a victim's machine over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleJeus | AppleJeus has exfiltrated collected host information to a C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSTARWHALE | STARWHALE can exfiltrate collected data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareIndustroyer | Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request. |
| T1041 Exfiltration Over C2 Channel |
MalwareKevin | Kevin can send data from the victim host through a DNS C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoopy | Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareRemexi | Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareAstaroth | Astaroth exfiltrates collected information from its r1.log file to the external C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareQakBot | QakBot can send stolen information to C2 nodes including passwords, accounts, and emails. |
| T1041 Exfiltration Over C2 Channel |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to upload files to the C2 Server. |
| T1041 Exfiltration Over C2 Channel |
MalwareADVSTORESHELL | ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrifeWater | StrifeWater can send data and files from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareWarzoneRAT | WarzoneRAT can send collected victim data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareXORIndex Loader | XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
ToolShimRatReporter | ShimRatReporter sent generated reports to the C2 via HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
ToolSliver | Sliver can exfiltrate files from the victim using the |
| T1041 Exfiltration Over C2 Channel |
ToolSILENTTRINITY | SILENTTRINITY can transfer files from an infected host to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
ToolEmpire | Empire can send data gathered from a target through the command and control channel. |
| T1041 Exfiltration Over C2 Channel |
ToolPcShare | PcShare can upload files and information from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
ToolImminent Monitor | Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2. |
| T1041 Exfiltration Over C2 Channel |
ToolPupy | Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1041 Exfiltration Over C2 Channel |
MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains. |
| T1046 Network Service Discovery |
MalwareHDoor | HDoor scans to identify open ports on the victim. |
| T1046 Network Service Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to scan for open ports on hosts in a connected network. |
| T1046 Network Service Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1046 Network Service Discovery |
MalwareBADHATCH | BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| T1046 Network Service Discovery |
MalwareHildegard | Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1046 Network Service Discovery |
MalwareInvisiMole | InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1046 Network Service Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can scan networks for open ports and listening services. |
| T1046 Network Service Discovery |
MalwareLucifer | Lucifer can scan for open ports including TCP ports 135 and 1433. |
| T1046 Network Service Discovery |
MalwareBlackEnergy | BlackEnergy has conducted port scans on a host. |
| T1046 Network Service Discovery |
MalwareConficker | Conficker scans for other machines to infect. |
| T1046 Network Service Discovery |
MalwareChina Chopper | China Chopper's server component can spider authentication portals. |
| T1046 Network Service Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist file`.It also utilizes Apple's CWWiFiClient API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1046 Network Service Discovery |
MalwareRemsec | Remsec has a plugin that can perform ARP scanning as well as port scanning. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.