ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

T1041
Exfiltration Over C2 Channel
GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1041
Exfiltration Over C2 Channel
GroupGALLIUM

GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.

T1041
Exfiltration Over C2 Channel
GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKimsuky

Kimsuky has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupAPT32

APT32's backdoor has exfiltrated data using the already opened channel with its C&C server.

T1041
Exfiltration Over C2 Channel
GroupMuddyWater

MuddyWater has used C2 infrastructure to receive exfiltrated data.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1041
Exfiltration Over C2 Channel
GroupSandworm Team

Sandworm Team has sent system information to its C2 server using HTTP.

T1041
Exfiltration Over C2 Channel
GroupCURIUM

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1041
Exfiltration Over C2 Channel
GroupMustang Panda

Mustang Panda has exfiltrated stolen data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupZIRCONIUM

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1041
Exfiltration Over C2 Channel
GroupScattered Spider

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1041
Exfiltration Over C2 Channel
GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
GroupHigaisa

Higaisa exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKe3chang

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

T1041
Exfiltration Over C2 Channel
GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupLeviathan

Leviathan has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1041
Exfiltration Over C2 Channel
GroupStealth Falcon

After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1041
Exfiltration Over C2 Channel
GroupLuminousMoth

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1041
Exfiltration Over C2 Channel
GroupWizard Spider

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1041
Exfiltration Over C2 Channel
GroupVOID MANTICORE

VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.

T1041
Exfiltration Over C2 Channel
GroupWIRTE

WIRTE has exfiltrated collected victim data to C2 infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareTrickBot

TrickBot can send information about the compromised host and upload data to a hardcoded C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBLINDINGCAN

BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests.

T1041
Exfiltration Over C2 Channel
MalwarePikabot

During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4.

T1041
Exfiltration Over C2 Channel
MalwareSpark

Spark has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBumblebee

Bumblebee can send collected data in JSON format to C2.

T1041
Exfiltration Over C2 Channel
MalwareBRICKSTORM

BRICKSTORM has uploaded files from the victim system to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareAmadey

Amadey has sent victim data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareProxysvc

Proxysvc performs data exfiltration over the control server channel using a custom protocol.

T1041
Exfiltration Over C2 Channel
MalwareTorisma

Torisma can send victim data to an actor-controlled C2 server.

T1041
Exfiltration Over C2 Channel
MalwareStuxnet

Stuxnet sends compromised victim information via HTTP.

T1041
Exfiltration Over C2 Channel
MalwareRotaJakiro

RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP.

T1041
Exfiltration Over C2 Channel
MalwareKOPILUWAK

KOPILUWAK has exfiltrated collected data to its C2 via POST requests.

T1041
Exfiltration Over C2 Channel
MalwareMisdat

Misdat has uploaded files and data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareHAWKBALL

HAWKBALL has sent system information and files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareUrsnif

Ursnif has used HTTP POSTs to exfil gathered information.

T1041
Exfiltration Over C2 Channel
MalwareZLib

ZLib has sent data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareInvisibleFerret

InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareBankshot

Bankshot exfiltrates data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareSharpDisco

SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2.

T1041
Exfiltration Over C2 Channel
MalwareStrongPity

StrongPity can exfiltrate collected documents through C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareAppleSeed

AppleSeed can exfiltrate files via the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePowerExchange

PowerExchange can exfiltrate files via its email C2 channel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.