Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareTrailBlazer | TrailBlazer has used HTTP requests for C2. |
| T1071.001 Web Protocols |
MalwareMOPSLED | MOPSLED can communicate to C2 nodes over HTTP. |
| T1071.001 Web Protocols |
MalwareMore_eggs | More_eggs uses HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareOutSteel | OutSteel has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareBackConfig | BackConfig has the ability to use HTTPS for C2 communiations. |
| T1071.001 Web Protocols |
MalwarePowGoop | PowGoop can send HTTP GET requests to malicious servers. |
| T1071.001 Web Protocols |
MalwareBoomBox | BoomBox has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
MalwareLAMEHUG | LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2. |
| T1071.001 Web Protocols |
MalwareMango | Mango can retrieve C2 commands sent in HTTP responses. |
| T1071.001 Web Protocols |
MalwareWIREFIRE | WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`. |
| T1071.001 Web Protocols |
MalwareGrimAgent | GrimAgent has the ability to use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareLookBack | LookBack’s C2 proxy tool sends data to a C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareSTEADYPULSE | STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution. |
| T1071.001 Web Protocols |
MalwareYAHOYAH | YAHOYAH uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareLokibot | Lokibot has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareCloudDuke | One variant of CloudDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareEgregor | Egregor has communicated with its C2 servers via HTTPS protocol. |
| T1071.001 Web Protocols |
MalwarePoetRAT | PoetRAT has used HTTP and HTTPs for C2 communications. |
| T1071.001 Web Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareStealBit | StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure. |
| T1071.001 Web Protocols |
MalwareFELIXROOT | FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1071.001 Web Protocols |
MalwareZxShell | ZxShell has used HTTP for C2 connections. |
| T1071.001 Web Protocols |
MalwareRIFLESPINE | RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files. |
| T1071.001 Web Protocols |
MalwareSLIGHTPULSE | SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareCreepySnail | CreepySnail can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareWinnti for Windows | Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications. |
| T1071.001 Web Protocols |
MalwareTroll Stealer | Troll Stealer uses HTTP to communicate to command and control infrastructure. |
| T1071.001 Web Protocols |
MalwareKinsing | Kinsing has communicated with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwarenjRAT | njRAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareMaze | Maze has communicated to hard-coded IP addresses via HTTP. |
| T1071.001 Web Protocols |
MalwareComRAT | ComRAT has used HTTP requests for command and control. |
| T1071.001 Web Protocols |
MalwareChChes | ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header. |
| T1071.001 Web Protocols |
MalwareANDROMEDA | ANDROMEDA has the ability to make GET requests to download files from C2. |
| T1071.001 Web Protocols |
MalwareManjusaka | Manjusaka has used HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareIceApple | IceApple can use HTTP GET to request and pull information from C2. |
| T1071.001 Web Protocols |
MalwareShai-Hulud | Shai-Hulud has utilized curl to install Bun over HTTPS. |
| T1071.001 Web Protocols |
MalwaremetaMain | metaMain can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareSideTwist | SideTwist has used HTTP GET and POST requests over port 443 for C2. |
| T1071.001 Web Protocols |
MalwareMechaFlounder | MechaFlounder has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
MalwarePsylo | Psylo uses HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareHTTPBrowser | HTTPBrowser has used HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareMis-Type | Mis-Type network traffic can communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareLunarWeb | LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands. |
| T1071.001 Web Protocols |
MalwareDipsind | Dipsind uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareOctopus | Octopus has used HTTP GET and POST requests for C2 communications. |
| T1071.001 Web Protocols |
MalwareAppleJeus | AppleJeus has sent data to its C2 server via |
| T1071.001 Web Protocols |
MalwareSoreFang | SoreFang can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareSTARWHALE | STARWHALE has the ability to contact actor-controlled C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareIndustroyer | Industroyer’s main backdoor connected to a remote C2 server using HTTPS. |
| T1071.001 Web Protocols |
MalwareDownPaper | DownPaper communicates to its C2 server over HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.