Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareRIFLESPINE | RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files. |
| T1071.001 Web Protocols |
MalwareSLIGHTPULSE | SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareCreepySnail | CreepySnail can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareWinnti for Windows | Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications. |
| T1071.001 Web Protocols |
MalwareTroll Stealer | Troll Stealer uses HTTP to communicate to command and control infrastructure. |
| T1071.001 Web Protocols |
MalwareKinsing | Kinsing has communicated with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwarenjRAT | njRAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareMaze | Maze has communicated to hard-coded IP addresses via HTTP. |
| T1071.001 Web Protocols |
MalwareComRAT | ComRAT has used HTTP requests for command and control. |
| T1071.001 Web Protocols |
MalwareChChes | ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header. |
| T1071.001 Web Protocols |
MalwareANDROMEDA | ANDROMEDA has the ability to make GET requests to download files from C2. |
| T1071.001 Web Protocols |
MalwareManjusaka | Manjusaka has used HTTP for command and control communication. |
| T1071.001 Web Protocols |
MalwareIceApple | IceApple can use HTTP GET to request and pull information from C2. |
| T1071.001 Web Protocols |
MalwareShai-Hulud | Shai-Hulud has utilized curl to install Bun over HTTPS. |
| T1071.001 Web Protocols |
MalwaremetaMain | metaMain can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareSideTwist | SideTwist has used HTTP GET and POST requests over port 443 for C2. |
| T1071.001 Web Protocols |
MalwareMechaFlounder | MechaFlounder has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
MalwarePsylo | Psylo uses HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareHTTPBrowser | HTTPBrowser has used HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareMis-Type | Mis-Type network traffic can communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareLunarWeb | LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands. |
| T1071.001 Web Protocols |
MalwareDipsind | Dipsind uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareOctopus | Octopus has used HTTP GET and POST requests for C2 communications. |
| T1071.001 Web Protocols |
MalwareAppleJeus | AppleJeus has sent data to its C2 server via |
| T1071.001 Web Protocols |
MalwareSoreFang | SoreFang can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareSTARWHALE | STARWHALE has the ability to contact actor-controlled C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareIndustroyer | Industroyer’s main backdoor connected to a remote C2 server using HTTPS. |
| T1071.001 Web Protocols |
MalwareDownPaper | DownPaper communicates to its C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareCozyCar | CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS. |
| T1071.001 Web Protocols |
MalwareKevin | Variants of Kevin can communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
Malwarehttpclient | httpclient uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwarePOWERTON | POWERTON has used HTTP/HTTPS for C2 traffic. |
| T1071.001 Web Protocols |
MalwareBADNEWS | BADNEWS establishes a backdoor over HTTP. |
| T1071.001 Web Protocols |
MalwareGoopy | Goopy has the ability to communicate with its C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareShadowPad | ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL. |
| T1071.001 Web Protocols |
MalwareRemexi | Remexi uses BITSAdmin to communicate with the C2 server over HTTP. |
| T1071.001 Web Protocols |
MalwareQakBot | QakBot has the ability to use HTTP and HTTPS in communication with C2 servers. |
| T1071.001 Web Protocols |
MalwareGelsemium | Gelsemium can use HTTP/S in C2 communications. |
| T1071.001 Web Protocols |
MalwareHelminth | Helminth can use HTTP for C2. |
| T1071.001 Web Protocols |
MalwareDridex | Dridex has used POST requests and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareBBK | BBK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareKomplex | The Komplex C2 channel uses HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareComnie | Comnie uses HTTP for C2 communication. |
| T1071.001 Web Protocols |
MalwareVasport | Vasport creates a backdoor by making a connection using a HTTP POST. |
| T1071.001 Web Protocols |
MalwareMacSpy | MacSpy uses HTTP for command and control. |
| T1071.001 Web Protocols |
MalwareBACKSPACE | BACKSPACE uses HTTP as a transport to communicate with its command server. |
| T1071.001 Web Protocols |
MalwareUPPERCUT | UPPERCUT has used HTTP for C2, including sending error codes in cookie headers. |
| T1071.001 Web Protocols |
MalwareADVSTORESHELL | ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| T1071.001 Web Protocols |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.