Real-world descriptions of how a group, tool or campaign used a technique.
344 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareCozyCar | CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS. |
| T1071.001 Web Protocols |
MalwareKevin | Variants of Kevin can communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
Malwarehttpclient | httpclient uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwarePOWERTON | POWERTON has used HTTP/HTTPS for C2 traffic. |
| T1071.001 Web Protocols |
MalwareBADNEWS | BADNEWS establishes a backdoor over HTTP. |
| T1071.001 Web Protocols |
MalwareGoopy | Goopy has the ability to communicate with its C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareShadowPad | ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL. |
| T1071.001 Web Protocols |
MalwareRemexi | Remexi uses BITSAdmin to communicate with the C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareQakBot | QakBot has the ability to use HTTP and HTTPS in communication with C2 servers. |
| T1071.001 Web Protocols |
MalwareGelsemium | Gelsemium can use HTTP/S in C2 communications. |
| T1071.001 Web Protocols |
MalwareHelminth | Helminth can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDridex | Dridex has used POST requests and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBBK | BBK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareKomplex | The Komplex C2 channel uses HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareComnie | Comnie uses HTTP for C2 communication. |
| T1071.001 Web Protocols |
MalwareVasport | Vasport creates a backdoor by making a connection using a HTTP POST. |
| T1071.001 Web Protocols |
MalwareMacSpy | MacSpy uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareBACKSPACE | BACKSPACE uses HTTP as a transport to communicate with its command server. |
| T1071.001 Web Protocols |
MalwareUPPERCUT | UPPERCUT has used HTTP for C2, including sending error codes in cookie headers. |
| T1071.001 Web Protocols |
MalwareADVSTORESHELL | ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| T1071.001 Web Protocols |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareXORIndex Loader | XORIndex Loader has used HTTPS POST to communicate with C2. |
| T1071.001 Web Protocols |
MalwareSmall Sieve | Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS. |
| T1071.001 Web Protocols |
ToolCovenant | Covenant can establish command and control via HTTP. |
| T1071.001 Web Protocols |
ToolShimRatReporter | ShimRatReporter communicated over HTTP with preconfigured C2 servers. |
| T1071.001 Web Protocols |
ToolSliver | Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.001 Web Protocols |
Toolevilginx2 | evilginx2 can proxy HTTPS connections between victims and destination websites. |
| T1071.001 Web Protocols |
ToolEmpire | Empire can conduct command and control over protocols like HTTP and HTTPS. |
| T1071.001 Web Protocols |
ToolFRP | FRP has the ability to use HTTP and HTTPS to enable the forwarding of requests for internal services via domain name. |
| T1071.001 Web Protocols |
ToolPcShare | PcShare has used HTTP for C2 communication. |
| T1071.001 Web Protocols |
ToolPoshC2 | PoshC2 can use protocols like HTTP/HTTPS for command and control traffic. |
| T1071.001 Web Protocols |
ToolCSPY Downloader | CSPY Downloader can use GET requests to download additional payloads from C2. |
| T1071.001 Web Protocols |
ToolBrute Ratel C4 | Brute Ratel C4 can use HTTPS and HTTPS for C2 communication. |
| T1071.001 Web Protocols |
ToolOut1 | Out1 can use HTTP and HTTPS in communications with remote hosts. |
| T1071.001 Web Protocols |
ToolMCMD | MCMD can use HTTPS in communication with C2 web servers. |
| T1071.001 Web Protocols |
ToolDonut | Donut can use HTTP to download previously staged shellcode payloads. |
| T1071.001 Web Protocols |
ToolKoadic | Koadic has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
ToolPupy | Pupy can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
ToolMythic | Mythic supports HTTP-based C2 profiles. |
| T1071.001 Web Protocols |
ToolQuick Assist | Quick Assist communicates over TCP 443 via HTTPS to a remote session server, under which RDP traffic is transferred. |
| T1071.001 Web Protocols |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains. |
| T1071.001 Web Protocols |
MalwareMini Shai-Hulud | Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains. |
| T1071.001 Web Protocols |
MalwareKali365 | Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.