ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareFoggyWeb

FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server.

T1041
Exfiltration Over C2 Channel
MalwareCaterpillar WebShell

Caterpillar WebShell can upload files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareLODEINFO

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareCharmPower

CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST.

T1041
Exfiltration Over C2 Channel
MalwareMuddyViper

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1041
Exfiltration Over C2 Channel
MalwareEVILNUM

EVILNUM can upload files over the C2 channel from the infected host.

T1041
Exfiltration Over C2 Channel
MalwareSMOKEDHAM

SMOKEDHAM has exfiltrated data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSagerunex

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareMetamorfo

Metamorfo can send the data it collects to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBandook

Bandook can upload files from a victim's machine over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMagicRAT

MagicRAT exfiltrates data via HTTP over existing command and control channels.

T1041
Exfiltration Over C2 Channel
MalwareKONNI

KONNI has sent data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDnsSystem

DnsSystem can exfiltrate collected data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareBLUELIGHT

BLUELIGHT has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareKGH_SPY

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareRedLine Stealer

RedLine Stealer has sent victim data to its C2 server or RedLine panel server.

T1041
Exfiltration Over C2 Channel
MalwareOopsIE

OopsIE can upload files from the victim's machine to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareAttor

Attor has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLitePower

LitePower can send collected data, including screenshots, over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBoxCaon

BoxCaon uploads files and data from a compromised host over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareNightClub

NightClub can use SMTP and DNS for file exfiltration and C2.

T1041
Exfiltration Over C2 Channel
MalwareCrutch

Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API).

T1041
Exfiltration Over C2 Channel
MalwareSDBbot

SDBbot has sent collected data from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1041
Exfiltration Over C2 Channel
MalwareGrandoreiro

Grandoreiro can send data it retrieves to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareDrovorub

Drovorub can exfiltrate files over C2 infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareShark

Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareSUGARDUMP

SUGARDUMP has sent stolen credentials and other data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1041
Exfiltration Over C2 Channel
MalwareLunarMail

LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareHotCroissant

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1041
Exfiltration Over C2 Channel
MalwareREvil

REvil can exfiltrate host and malware information to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOilBooster

OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareCyclops Blink

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTajMahal

TajMahal has the ability to send collected files over its C2.

T1041
Exfiltration Over C2 Channel
MalwareRaccoon Stealer

Raccoon Stealer uses existing HTTP-based command and control channels for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareIPsec Helper

IPsec Helper exfiltrates specific files through its command and control framework.

T1041
Exfiltration Over C2 Channel
MalwareSolar

Solar can send staged files to C2 for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareGoldenSpy

GoldenSpy has exfiltrated host environment information to an external C2 domain via port 9006.

T1041
Exfiltration Over C2 Channel
MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareMacMa

MacMa exfiltrates data from a supplied path over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareFunnyDream

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1041
Exfiltration Over C2 Channel
MalwareSysUpdate

SysUpdate has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOutSteel

OutSteel can upload files from a compromised host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareLAMEHUG

LAMEHUG can exfiltrate collected system information and documents to C2.

T1041
Exfiltration Over C2 Channel
MalwareMango

Mango can use its HTTP C2 channel for exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareKessel

Kessel has exfiltrated information gathered from the infected system to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.