Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwarePteranodon | Pteranodon can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkTortilla | DarkTortilla has used HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareBeaverTail | BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
| T1071.001 Web Protocols |
MalwareROKRAT | ROKRAT can use HTTP and HTTPS for command and control communication. |
| T1071.001 Web Protocols |
MalwareCORESHELL | CORESHELL can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDarkWatchman | DarkWatchman uses HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareDyre | Dyre uses HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBlackMould | BlackMould can send commands to C2 in the body of HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareBBSRAT | BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareReaver | Some Reaver variants use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareBisonal | Bisonal has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareS-Type | S-Type uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareSeaDuke | SeaDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareDustySky | DustySky has used both HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareExplosive | Explosive has used HTTP for communication. |
| T1071.001 Web Protocols |
MalwareXbash | Xbash uses HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareEpic | Epic uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwarePeppy | Peppy can use HTTP to communicate with C2. |
| T1071.001 Web Protocols |
MalwareKEYPLUG | KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2. |
| T1071.001 Web Protocols |
MalwareDEATHRANSOM | DEATHRANSOM can use HTTPS to download files. |
| T1071.001 Web Protocols |
MalwareClambling | Clambling has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareMongall | Mongall can use HTTP for C2 communication. |
| T1071.001 Web Protocols |
MalwareLockBit 3.0 | LockBit 3.0 can use HTTP to send victim host information to C2. |
| T1071.001 Web Protocols |
MalwareSVCReady | SVCReady can communicate with its C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareThiefQuest | ThiefQuest uploads files via unencrypted HTTP. |
| T1071.001 Web Protocols |
MalwareFoggyWeb | FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests. |
| T1071.001 Web Protocols |
MalwareNGLite | NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003. |
| T1071.001 Web Protocols |
MalwareCarbanak | The Carbanak malware communicates to its command server using HTTP with an encrypted payload. |
| T1071.001 Web Protocols |
MalwareCreepyDrive | CreepyDrive can use HTTPS for C2 using the Microsoft Graph API. |
| T1071.001 Web Protocols |
MalwareElise | Elise communicates over HTTP or HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareGazer | Gazer communicates with its C2 servers over HTTP. |
| T1071.001 Web Protocols |
MalwareTSCookie | TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1071.001 Web Protocols |
MalwareSaint Bot | Saint Bot has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareChaes | Chaes has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareCharmPower | CharmPower can use HTTP to communicate with C2. |
| T1071.001 Web Protocols |
MalwareMuddyViper | MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API. |
| T1071.001 Web Protocols |
Malware3PARA RAT | 3PARA RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareBundlore | Bundlore uses HTTP requests for C2. |
| T1071.001 Web Protocols |
MalwareSMOKEDHAM | SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareMori | Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set. |
| T1071.001 Web Protocols |
MalwareQUADAGENT | QUADAGENT uses HTTPS and HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareSagerunex | Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`. |
| T1071.001 Web Protocols |
MalwareSys10 | Sys10 uses HTTP for C2. |
| T1071.001 Web Protocols |
Malwarepngdowner | pngdowner uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareGlassWorm | GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers. |
| T1071.001 Web Protocols |
MalwareUroburos | Uroburos can use a custom HTTP-based protocol for large data communications that can blend with normal network traffic by riding on top of standard HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.