ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

344 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareTrailBlazer

TrailBlazer has used HTTP requests for C2.

T1071.001
Web Protocols
MalwareMOPSLED

MOPSLED can communicate to C2 nodes over HTTP.

T1071.001
Web Protocols
MalwareMore_eggs

More_eggs uses HTTPS for C2.

T1071.001
Web Protocols
MalwareOutSteel

OutSteel has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareBackConfig

BackConfig has the ability to use HTTPS for C2 communiations.

T1071.001
Web Protocols
MalwarePowGoop

PowGoop can send HTTP GET requests to malicious servers.

T1071.001
Web Protocols
MalwareBoomBox

BoomBox has used HTTP POST requests for C2.

T1071.001
Web Protocols
MalwareLAMEHUG

LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2.

T1071.001
Web Protocols
MalwareMango

Mango can retrieve C2 commands sent in HTTP responses.

T1071.001
Web Protocols
MalwareWIREFIRE

WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`.

T1071.001
Web Protocols
MalwareGrimAgent

GrimAgent has the ability to use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareLookBack

LookBack’s C2 proxy tool sends data to a C2 server over HTTP.

T1071.001
Web Protocols
MalwareSTEADYPULSE

STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution.

T1071.001
Web Protocols
MalwareYAHOYAH

YAHOYAH uses HTTP for C2.

T1071.001
Web Protocols
MalwareLokibot

Lokibot has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareCloudDuke

One variant of CloudDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareEgregor

Egregor has communicated with its C2 servers via HTTPS protocol.

T1071.001
Web Protocols
MalwarePoetRAT

PoetRAT has used HTTP and HTTPs for C2 communications.

T1071.001
Web Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareStealBit

StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure.

T1071.001
Web Protocols
MalwareFELIXROOT

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1071.001
Web Protocols
MalwareZxShell

ZxShell has used HTTP for C2 connections.

T1071.001
Web Protocols
MalwareRIFLESPINE

RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files.

T1071.001
Web Protocols
MalwareSLIGHTPULSE

SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests.

T1071.001
Web Protocols
MalwareCreepySnail

CreepySnail can use HTTP for C2.

T1071.001
Web Protocols
MalwareWinnti for Windows

Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications.

T1071.001
Web Protocols
MalwareTroll Stealer

Troll Stealer uses HTTP to communicate to command and control infrastructure.

T1071.001
Web Protocols
MalwareKinsing

Kinsing has communicated with C2 over HTTP.

T1071.001
Web Protocols
MalwarenjRAT

njRAT has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareMaze

Maze has communicated to hard-coded IP addresses via HTTP.

T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1071.001
Web Protocols
MalwareChChes

ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header.

T1071.001
Web Protocols
MalwareANDROMEDA

ANDROMEDA has the ability to make GET requests to download files from C2.

T1071.001
Web Protocols
MalwareManjusaka

Manjusaka has used HTTP for command and control communication.

T1071.001
Web Protocols
MalwareIceApple

IceApple can use HTTP GET to request and pull information from C2.

T1071.001
Web Protocols
MalwareShai-Hulud

Shai-Hulud has utilized curl to install Bun over HTTPS.

T1071.001
Web Protocols
MalwaremetaMain

metaMain can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareSideTwist

SideTwist has used HTTP GET and POST requests over port 443 for C2.

T1071.001
Web Protocols
MalwareMechaFlounder

MechaFlounder has the ability to use HTTP in communication with C2.

T1071.001
Web Protocols
MalwarePsylo

Psylo uses HTTPS for C2.

T1071.001
Web Protocols
MalwareHTTPBrowser

HTTPBrowser has used HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareMis-Type

Mis-Type network traffic can communicate over HTTP.

T1071.001
Web Protocols
MalwareLunarWeb

LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands.

T1071.001
Web Protocols
MalwareDipsind

Dipsind uses HTTP for C2.

T1071.001
Web Protocols
MalwareOctopus

Octopus has used HTTP GET and POST requests for C2 communications.

T1071.001
Web Protocols
MalwareAppleJeus

AppleJeus has sent data to its C2 server via POST requests.

T1071.001
Web Protocols
MalwareSoreFang

SoreFang can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareSTARWHALE

STARWHALE has the ability to contact actor-controlled C2 servers via HTTP.

T1071.001
Web Protocols
MalwareIndustroyer

Industroyer’s main backdoor connected to a remote C2 server using HTTPS.

T1071.001
Web Protocols
MalwareDownPaper

DownPaper communicates to its C2 server over HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.