ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareRIFLESPINE

RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files.

T1071.001
Web Protocols
MalwareSLIGHTPULSE

SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests.

T1071.001
Web Protocols
MalwareCreepySnail

CreepySnail can use HTTP for C2.

T1071.001
Web Protocols
MalwareWinnti for Windows

Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications.

T1071.001
Web Protocols
MalwareTroll Stealer

Troll Stealer uses HTTP to communicate to command and control infrastructure.

T1071.001
Web Protocols
MalwareKinsing

Kinsing has communicated with C2 over HTTP.

T1071.001
Web Protocols
MalwarenjRAT

njRAT has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareMaze

Maze has communicated to hard-coded IP addresses via HTTP.

T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1071.001
Web Protocols
MalwareChChes

ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header.

T1071.001
Web Protocols
MalwareANDROMEDA

ANDROMEDA has the ability to make GET requests to download files from C2.

T1071.001
Web Protocols
MalwareManjusaka

Manjusaka has used HTTP for command and control communication.

T1071.001
Web Protocols
MalwareIceApple

IceApple can use HTTP GET to request and pull information from C2.

T1071.001
Web Protocols
MalwareShai-Hulud

Shai-Hulud has utilized curl to install Bun over HTTPS.

T1071.001
Web Protocols
MalwaremetaMain

metaMain can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareSideTwist

SideTwist has used HTTP GET and POST requests over port 443 for C2.

T1071.001
Web Protocols
MalwareMechaFlounder

MechaFlounder has the ability to use HTTP in communication with C2.

T1071.001
Web Protocols
MalwarePsylo

Psylo uses HTTPS for C2.

T1071.001
Web Protocols
MalwareHTTPBrowser

HTTPBrowser has used HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareMis-Type

Mis-Type network traffic can communicate over HTTP.

T1071.001
Web Protocols
MalwareLunarWeb

LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands.

T1071.001
Web Protocols
MalwareDipsind

Dipsind uses HTTP for C2.

T1071.001
Web Protocols
MalwareOctopus

Octopus has used HTTP GET and POST requests for C2 communications.

T1071.001
Web Protocols
MalwareAppleJeus

AppleJeus has sent data to its C2 server via POST requests.

T1071.001
Web Protocols
MalwareSoreFang

SoreFang can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareSTARWHALE

STARWHALE has the ability to contact actor-controlled C2 servers via HTTP.

T1071.001
Web Protocols
MalwareIndustroyer

Industroyer’s main backdoor connected to a remote C2 server using HTTPS.

T1071.001
Web Protocols
MalwareDownPaper

DownPaper communicates to its C2 server over HTTP.

T1071.001
Web Protocols
MalwareCozyCar

CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS.

T1071.001
Web Protocols
MalwareKevin

Variants of Kevin can communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareAgent Tesla

Agent Tesla has used HTTP for C2 communications.

T1071.001
Web Protocols
Malwarehttpclient

httpclient uses HTTP for command and control.

T1071.001
Web Protocols
MalwarePOWERTON

POWERTON has used HTTP/HTTPS for C2 traffic.

T1071.001
Web Protocols
MalwareBADNEWS

BADNEWS establishes a backdoor over HTTP.

T1071.001
Web Protocols
MalwareGoopy

Goopy has the ability to communicate with its C2 over HTTP.

T1071.001
Web Protocols
MalwareShadowPad

ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL.

T1071.001
Web Protocols
MalwareRemexi

Remexi uses BITSAdmin to communicate with the C2 server over HTTP.

T1071.001
Web Protocols
MalwareQakBot

QakBot has the ability to use HTTP and HTTPS in communication with C2 servers.

T1071.001
Web Protocols
MalwareGelsemium

Gelsemium can use HTTP/S in C2 communications.

T1071.001
Web Protocols
MalwareHelminth

Helminth can use HTTP for C2.

T1071.001
Web Protocols
MalwareDridex

Dridex has used POST requests and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareBBK

BBK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareKomplex

The Komplex C2 channel uses HTTP POST requests.

T1071.001
Web Protocols
MalwareComnie

Comnie uses HTTP for C2 communication.

T1071.001
Web Protocols
MalwareVasport

Vasport creates a backdoor by making a connection using a HTTP POST.

T1071.001
Web Protocols
MalwareMacSpy

MacSpy uses HTTP for command and control.

T1071.001
Web Protocols
MalwareBACKSPACE

BACKSPACE uses HTTP as a transport to communicate with its command server.

T1071.001
Web Protocols
MalwareUPPERCUT

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1071.001
Web Protocols
MalwareADVSTORESHELL

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

T1071.001
Web Protocols
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.