Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareSampleCheck5000 | SampleCheck5000 can download additional payloads to compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareSUNBURST | SUNBURST delivered different payloads, including TEARDROP in at least one instance. |
| T1105 Ingress Tool Transfer |
MalwareEvilBunny | EvilBunny has downloaded additional Lua scripts from the C2. |
| T1105 Ingress Tool Transfer |
MalwareHotCroissant | HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareServHelper | ServHelper may download additional files to execute. |
| T1105 Ingress Tool Transfer |
MalwareUnknown Logger | Unknown Logger is capable of downloading remote files. |
| T1105 Ingress Tool Transfer |
MalwareREvil | REvil can download a copy of itself from an attacker controlled IP address to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareValak | Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware. |
| T1105 Ingress Tool Transfer |
MalwareSamurai | Samurai has been used to deploy other malware including Ninja. |
| T1105 Ingress Tool Transfer |
MalwareMilan | Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`. |
| T1105 Ingress Tool Transfer |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareOilBooster | OilBooster can download and execute files from an actor-controlled OneDrive account. |
| T1105 Ingress Tool Transfer |
MalwareTaidoor | Taidoor has downloaded additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKivars | Kivars has the ability to download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareCyclops Blink | Cyclops Blink has the ability to download files to target systems. |
| T1105 Ingress Tool Transfer |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can upload files. |
| T1105 Ingress Tool Transfer |
MalwareSeasalt | Seasalt has a command to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareNanoCore | NanoCore has the capability to download and activate additional modules for execution. |
| T1105 Ingress Tool Transfer |
MalwarePLEAD | PLEAD has the ability to upload and download files to and from an infected host. |
| T1105 Ingress Tool Transfer |
MalwareRaccoon Stealer | Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft. |
| T1105 Ingress Tool Transfer |
MalwareDaserf | Daserf can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareCardinal RAT | Cardinal RAT can download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDanBot | DanBot can download additional files to a targeted system. |
| T1105 Ingress Tool Transfer |
MalwareBISCUIT | BISCUIT has a command to download a file from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCalisto | Calisto has the capability to upload and download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareSolar | Solar has the ability to download and execute files. |
| T1105 Ingress Tool Transfer |
MalwarePisloader | Pisloader has a command to upload a file to the victim machine. |
| T1105 Ingress Tool Transfer |
MalwareGoldenSpy | GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system. |
| T1105 Ingress Tool Transfer |
MalwareGold Dragon | Gold Dragon can download additional components from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareRGDoor | RGDoor uploads and downloads files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareAshTag | The AshTag stager component can retrieve and execute the main payload. |
| T1105 Ingress Tool Transfer |
MalwareCarberp | Carberp can download and execute new plugins from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareRevenge RAT | Revenge RAT has the ability to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwareMacMa | MacMa has downloaded additional files, including an exploit for used privilege escalation. |
| T1105 Ingress Tool Transfer |
MalwareFunnyDream | FunnyDream can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareMore_eggs | More_eggs can download and launch additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareSysUpdate | SysUpdate has the ability to download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareOutSteel | OutSteel can download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareBackConfig | BackConfig can download and execute additional payloads on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKwampirs | Kwampirs downloads additional files from C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareNerex | Nerex creates a backdoor through which remote attackers can download files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareBoomBox | BoomBox has the ability to download next stage malware components to a compromised system. |
| T1105 Ingress Tool Transfer |
MalwareWIREFIRE | WIREFIRE has the ability to download files to compromised devices. |
| T1105 Ingress Tool Transfer |
MalwareKessel | Kessel can download additional modules from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareGrimAgent | GrimAgent has the ability to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareSTEADYPULSE | STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules. |
| T1105 Ingress Tool Transfer |
MalwarePHASEJAM | PHASEJAM has the ability to upload files onto the compromised appliance. |
| T1105 Ingress Tool Transfer |
MalwareYAHOYAH | YAHOYAH uses HTTP GET requests to download other files that are executed in memory. |
| T1105 Ingress Tool Transfer |
MalwareLokibot | Lokibot downloaded several staged items onto the victim's machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.