Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareExaramel for Linux | Exaramel for Linux uses HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using HTTP or HTTPS. |
| T1071.001 Web Protocols |
MalwareHAWKBALL | HAWKBALL has used HTTP to communicate with a single hard-coded C2 server. |
| T1071.001 Web Protocols |
MalwareTAMECAT | TAMECAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareZLib | ZLib communicates over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareRedLeaves | RedLeaves can communicate to its C2 over HTTP and HTTPS if directed. |
| T1071.001 Web Protocols |
MalwareTsundere Botnet | Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes. |
| T1071.001 Web Protocols |
MalwareFelismus | Felismus uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareZeus Panda | Zeus Panda uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareGeminiDuke | GeminiDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.001 Web Protocols |
MalwareGravityRAT | GravityRAT uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareInvisibleFerret | InvisibleFerret has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareBankshot | Bankshot uses HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareStrongPity | StrongPity can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwarexCaon | xCaon has communicated with the C2 server by sending POST requests over HTTP. |
| T1071.001 Web Protocols |
MalwarePony | Pony has sent collected information to the C2 via HTTP POST request. |
| T1071.001 Web Protocols |
MalwareWinMM | WinMM uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareTONESHELL | TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareRainyDay | RainyDay can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareAppleSeed | AppleSeed has the ability to communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareLOWBALL | LOWBALL command and control occurs via HTTPS over port 443. |
| T1071.001 Web Protocols |
MalwareNETWIRE | NETWIRE has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareTinyTurla | TinyTurla can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareBOOKWORM | BOOKWORM has communicated with its C2 via HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareHAMMERTOSS | The "Uploader" variant of HAMMERTOSS visits a hard-coded server over HTTP/S to download the images HAMMERTOSS uses to receive commands. |
| T1071.001 Web Protocols |
MalwareOLDBAIT | OLDBAIT can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareCosmicDuke | CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers. |
| T1071.001 Web Protocols |
MalwareGreyEnergy | GreyEnergy uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareGomir | Gomir periodically communicates to its command and control infrastructure through HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareAria-body | Aria-body has used HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareEmotet | Emotet has used HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareSNUGRIDE | SNUGRIDE communicates with its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareBOLDMOVE | BOLDMOVE uses web services for command and control communication. |
| T1071.001 Web Protocols |
MalwareCrimson | Crimson can use a HTTP GET request to download its final payload. |
| T1071.001 Web Protocols |
MalwareTomiris | Tomiris can use HTTP to establish C2 communications. |
| T1071.001 Web Protocols |
MalwareTurian | Turian has the ability to use HTTP for its C2. |
| T1071.001 Web Protocols |
MalwareTHINCRUST | THINCRUST can use HTTP POST requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareBADHATCH | BADHATCH can use HTTP and HTTPS over port 443 to communicate with actor-controlled C2 servers. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.001 Web Protocols |
MalwareAction RAT | Action RAT can use HTTP to communicate with C2 servers. |
| T1071.001 Web Protocols |
MalwareAvenger | Avenger has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.001 Web Protocols |
MalwarePingPull | A PingPull variant can communicate with its C2 servers by using HTTPS. |
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareDacls | Dacls can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareWoody RAT | Woody RAT can communicate with its C2 server using HTTP requests. |
| T1071.001 Web Protocols |
MalwareMafalda | Mafalda can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareSquirrelwaffle | Squirrelwaffle has used HTTP POST requests for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.