Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareCallMe | CallMe has the capability to download a file to the victim from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCloudDuke | CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account. |
| T1105 Ingress Tool Transfer |
MalwareEgregor | Egregor has the ability to download files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwarePoetRAT | PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote file transmission. |
| T1105 Ingress Tool Transfer |
MalwareFELIXROOT | FELIXROOT downloads and uploads files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareZxShell | ZxShell has a command to transfer files from a remote host. |
| T1105 Ingress Tool Transfer |
MalwareRIFLESPINE | RIFLESPINE can download and execute files. |
| T1105 Ingress Tool Transfer |
MalwareSLIGHTPULSE | RAPIDPULSE can transfer files to and from compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareNDiskMonitor | NDiskMonitor can download and execute a file from given URL. |
| T1105 Ingress Tool Transfer |
MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| T1105 Ingress Tool Transfer |
MalwareDDKONG | DDKONG downloads and uploads files on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwarePenquin | Penquin can execute the command code |
| T1105 Ingress Tool Transfer |
MalwareBabyShark | BabyShark has downloaded additional files from the C2. |
| T1105 Ingress Tool Transfer |
MalwareCannon | Cannon can download a payload for execution. |
| T1105 Ingress Tool Transfer |
Malwarebuild_downer | build_downer has the ability to download files from C2 to the infected host. |
| T1105 Ingress Tool Transfer |
MalwareMelcoz | Melcoz has the ability to download additional files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareWinnti for Windows | The Winnti for Windows dropper can place malicious payloads on targeted systems. |
| T1105 Ingress Tool Transfer |
MalwarePowerPunch | PowerPunch can download payloads from adversary infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareBONDUPDATER | BONDUPDATER can download or upload files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareKinsing | Kinsing has downloaded additional lateral movement scripts from C2. |
| T1105 Ingress Tool Transfer |
MalwareMeteor | Meteor has the ability to download additional files for execution on the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarenjRAT | njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies. |
| T1105 Ingress Tool Transfer |
MalwareZIPLINE | ZIPLINE can download files to be saved on the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareTURNEDUP | TURNEDUP is capable of downloading additional files. |
| T1105 Ingress Tool Transfer |
MalwareChChes | ChChes is capable of downloading files, including additional modules. |
| T1105 Ingress Tool Transfer |
MalwareANDROMEDA | ANDROMEDA can download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareShai-Hulud | Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data. |
| T1105 Ingress Tool Transfer |
MalwareJPIN | JPIN can download files and upgrade itself. |
| T1105 Ingress Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to upload and download files. |
| T1105 Ingress Tool Transfer |
MalwaremetaMain | metaMain can download files onto compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareSideTwist | SideTwist has the ability to download additional files. |
| T1105 Ingress Tool Transfer |
MalwareKOCTOPUS | KOCTOPUS has executed a PowerShell command to download a file to the system. |
| T1105 Ingress Tool Transfer |
MalwareMechaFlounder | MechaFlounder has the ability to upload and download files to and from a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePsylo | Psylo has a command to download a file to the system from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareHTTPBrowser | HTTPBrowser is capable of writing a file to the compromised system from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareMis-Type | Mis-Type has downloaded additional malware and files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareXCSSET | XCSSET downloads browser specific AppleScript modules using a constructed URL with the |
| T1105 Ingress Tool Transfer |
MalwareDisco | Disco can download files to targeted systems via SMB. |
| T1105 Ingress Tool Transfer |
MalwareDipsind | Dipsind can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareOctopus | Octopus can download additional files and tools onto the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareSoreFang | SoreFang can download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
MalwareIndustroyer | Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory. |
| T1105 Ingress Tool Transfer |
MalwareKevin | Kevin can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAgent Tesla | Agent Tesla can download additional files for execution on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwarePasam | Pasam creates a backdoor through which remote attackers can upload files. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSTATS | POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareBADNEWS | BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself. |
| T1105 Ingress Tool Transfer |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can download files onto compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareShadowPad | ShadowPad has downloaded code from a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.