Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareEmotet | Emotet has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrimson | Crimson can exfiltrate stolen information over its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareTomiris | Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDUSTTRAP | DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareBADHATCH | BADHATCH can exfiltrate data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMachete | Machete's collected data is exfiltrated over the same channel used for C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePingPull | PingPull has the ability to exfiltrate stolen victim data through its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareWoody RAT | Woody RAT can exfiltrate files from an infected machine to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareMafalda | Mafalda can send network system data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSquirrelwaffle | Squirrelwaffle has exfiltrated victim data using HTTP POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHexEval Loader | HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareAuTo Stealer | AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1041 Exfiltration Over C2 Channel |
MalwareSombRAT | SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlawedAmmyy | FlawedAmmyy has sent data collected from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHOPLIGHT | HOPLIGHT has used its C2 channel to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareCuckoo Stealer | Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username. |
| T1041 Exfiltration Over C2 Channel |
MalwareMobileOrder | MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareRDAT | RDAT can exfiltrate data gathered from the infected system via the established Exchange Web Services API C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareOkrum | Data exfiltration is done by Okrum using the already opened channel with the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated collected credentials to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Dancer | Line Dancer exfiltrates collected data via command and control channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareMispadu | Mispadu can sends the collected financial data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDoki | Doki has used Ngrok to establish C2 and exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
MalwareHTTPTroy | HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command. |
| T1041 Exfiltration Over C2 Channel |
MalwareMarkiRAT | MarkiRAT can exfiltrate locally stored data via its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerShower | PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days. |
| T1041 Exfiltration Over C2 Channel |
MalwareNETEAGLE | NETEAGLE is capable of reading files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1041 Exfiltration Over C2 Channel |
MalwareRising Sun | Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareChrommme | Chrommme can exfiltrate collected data via C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlagpro | Flagpro has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightSpy | To exfiltrate data, LightSpy configures each module to send an obfuscated JSON blob to hardcoded URL endpoints or paths aligned to the module name. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareLine Runner | Line Runner utilizes HTTP to retrieve and exfiltrate information staged using Line Dancer. |
| T1041 Exfiltration Over C2 Channel |
MalwarePteranodon | Pteranodon exfiltrates screenshot files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareROKRAT | ROKRAT can send collected files back over same C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDyre | Dyre has the ability to send information staged on a compromised host externally to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePlugX | PlugX has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBisonal | Bisonal has added the exfiltrated data to the URL over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareS-Type | S-Type has uploaded data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareDustySky | DustySky has exfiltrated data to the C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareLightNeuron | LightNeuron exfiltrates data over its email C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareDarkGate | DarkGate uses existing command and control channels to retrieve captured cryptocurrency wallet credentials. |
| T1041 Exfiltration Over C2 Channel |
MalwareMongall | Mongall can upload files and information from a compromised host to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareSVCReady | SVCReady can send collected data in JSON format to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareThiefQuest | ThiefQuest exfiltrates targeted file extensions in the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.