Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1571 Non-Standard Port |
GroupLazarus Group | Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches. |
| T1571 Non-Standard Port |
GroupSilence | Silence has used port 444 when sending data about the system from the client to the server. |
| T1571 Non-Standard Port |
GroupVelvet Ant | Velvet Ant has used random high number ports for PlugX listeners on victim devices. |
| T1571 Non-Standard Port |
GroupWIRTE | WIRTE has used HTTPS over ports 2083 and 2087 for C2. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
| T1571 Non-Standard Port |
GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
| T1572 Protocol Tunneling |
GroupSalt Typhoon | Salt Typhoon has modified device configurations to create and use Generic Routing Encapsulation (GRE) tunnels. |
| T1572 Protocol Tunneling |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1572 Protocol Tunneling |
GroupFIN7 | FIN7 has tunneled C2 traffic via OpenSSH. |
| T1572 Protocol Tunneling |
GroupMustang Panda | Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445. |
| T1572 Protocol Tunneling |
GroupScattered Spider | Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
| T1572 Protocol Tunneling |
GroupLeviathan | Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure. |
| T1572 Protocol Tunneling |
GroupCinnamon Tempest | Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel. |
| T1572 Protocol Tunneling |
GroupChimera | Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS. |
| T1572 Protocol Tunneling |
GroupEmber Bear | Ember Bear has used ProxyChains to tunnel protocols to internal networks. |
| T1572 Protocol Tunneling |
GroupFox Kitten | Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion. |
| T1572 Protocol Tunneling |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1572 Protocol Tunneling |
GroupVOID MANTICORE | VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices. |
| T1572 Protocol Tunneling |
GroupMagic Hound | Magic Hound has used Plink to tunnel RDP over SSH. |
| T1572 Protocol Tunneling |
GroupFIN13 | FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets. |
| T1573 Encrypted Channel |
GroupTropic Trooper | Tropic Trooper has encrypted traffic with the C2 to prevent network detection. |
| T1573 Encrypted Channel |
GroupBITTER | BITTER has encrypted their C2 communications. |
| T1573 Encrypted Channel |
GroupAPT29 | APT29 has used multiple layers of encryption within malware to protect C2 communication. |
| T1573 Encrypted Channel |
GroupMagic Hound | Magic Hound has used an encrypted http proxy in C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupVolt Typhoon | Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupMuddyWater | MuddyWater has used AES to encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
GroupMustang Panda | Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1573.001 Symmetric Cryptography |
GroupZIRCONIUM | ZIRCONIUM has used AES encrypted communications in C2. |
| T1573.001 Symmetric Cryptography |
GroupContagious Interview | Contagious Interview has encrypted C2 traffic using RC4. |
| T1573.001 Symmetric Cryptography |
GroupHigaisa | Higaisa used AES-128 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
GroupRedCurl | RedCurl has used AES-128 CBC to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupStealth Falcon | Stealth Falcon malware encrypts C2 traffic using RC4 with a hard-coded key. |
| T1573.001 Symmetric Cryptography |
GroupBRONZE BUTLER | BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server. |
| T1573.001 Symmetric Cryptography |
GroupDarkhotel | Darkhotel has used AES-256 and 3DES for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupAPT28 | APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupLazarus Group | Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
GroupInception | Inception has encrypted network communications with AES. |
| T1573.001 Symmetric Cryptography |
GroupAPT33 | APT33 has used AES for encryption of command and control traffic. |
| T1573.002 Asymmetric Cryptography |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedEcho | RedEcho uses SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
GroupTA2541 | TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT. |
| T1573.002 Asymmetric Cryptography |
GroupOilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupTropic Trooper | Tropic Trooper has used SSL to connect to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedCurl | RedCurl has used HTTPS for C2 communication. |
| T1573.002 Asymmetric Cryptography |
GroupMedusa Group | Medusa Group has used HTTPS for command and control. |
| T1573.002 Asymmetric Cryptography |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1573.002 Asymmetric Cryptography |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1573.002 Asymmetric Cryptography |
GroupVelvet Ant | Velvet Ant has used a reverse SSH shell to securely communicate with victim devices. |
| T1573.002 Asymmetric Cryptography |
GroupFIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.