Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
GroupBlackByte | BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1041 Exfiltration Over C2 Channel |
GroupGALLIUM | GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT3 | APT3 has a tool that exfiltrates data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKimsuky | Kimsuky has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT32 | APT32's backdoor has exfiltrated data using the already opened channel with its C&C server. |
| T1041 Exfiltration Over C2 Channel |
GroupMuddyWater | MuddyWater has used C2 infrastructure to receive exfiltrated data. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupSandworm Team | Sandworm Team has sent system information to its C2 server using HTTP. |
| T1041 Exfiltration Over C2 Channel |
GroupCURIUM | CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. |
| T1041 Exfiltration Over C2 Channel |
GroupMustang Panda | Mustang Panda has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1041 Exfiltration Over C2 Channel |
GroupScattered Spider | Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT39 | APT39 has exfiltrated stolen victim data through C2 communications. |
| T1041 Exfiltration Over C2 Channel |
GroupContagious Interview | Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1041 Exfiltration Over C2 Channel |
GroupHigaisa | Higaisa exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKe3chang | Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
| T1041 Exfiltration Over C2 Channel |
GroupConfucius | Confucius has exfiltrated stolen files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupLeviathan | Leviathan has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1041 Exfiltration Over C2 Channel |
GroupStealth Falcon | After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupChimera | Chimera has used Cobalt Strike C2 beacons for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
GroupLuminousMoth | LuminousMoth has used malware that exfiltrates stolen data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupAgrius | Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. |
| T1041 Exfiltration Over C2 Channel |
GroupLazarus Group | Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware. |
| T1041 Exfiltration Over C2 Channel |
GroupWizard Spider | Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels. |
| T1041 Exfiltration Over C2 Channel |
GroupVOID MANTICORE | VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications. |
| T1041 Exfiltration Over C2 Channel |
GroupWIRTE | WIRTE has exfiltrated collected victim data to C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBLINDINGCAN | BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwarePikabot | During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4. |
| T1041 Exfiltration Over C2 Channel |
MalwareSpark | Spark has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBumblebee | Bumblebee can send collected data in JSON format to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareBRICKSTORM | BRICKSTORM has uploaded files from the victim system to C2 servers. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1041 Exfiltration Over C2 Channel |
MalwareAmadey | Amadey has sent victim data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareProxysvc | Proxysvc performs data exfiltration over the control server channel using a custom protocol. |
| T1041 Exfiltration Over C2 Channel |
MalwareTorisma | Torisma can send victim data to an actor-controlled C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareStuxnet | Stuxnet sends compromised victim information via HTTP. |
| T1041 Exfiltration Over C2 Channel |
MalwareRotaJakiro | RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareKOPILUWAK | KOPILUWAK has exfiltrated collected data to its C2 via POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareMisdat | Misdat has uploaded files and data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHAWKBALL | HAWKBALL has sent system information and files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1041 Exfiltration Over C2 Channel |
MalwareZLib | ZLib has sent data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareInvisibleFerret | InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareBankshot | Bankshot exfiltrates data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareSharpDisco | SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrongPity | StrongPity can exfiltrate collected documents through C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerExchange | PowerExchange can exfiltrate files via its email C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.