ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.003
Mail Protocols
MalwareUroburos

Uroburos can use custom communications protocols that ride over SMTP.

T1071.003
Mail Protocols
MalwareNightClub

NightClub can use emails for C2 communications.

T1071.003
Mail Protocols
MalwareBadPatch

BadPatch uses SMTP for C2.

T1071.003
Mail Protocols
MalwareSUGARDUMP

A SUGARDUMP variant used SMTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareLunarMail

LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI).

T1071.003
Mail Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

T1071.003
Mail Protocols
MalwareCannon

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

T1071.003
Mail Protocols
MalwareComRAT

ComRAT can use email attachments for command and control.

T1071.003
Mail Protocols
MalwareJPIN

JPIN can send email over SMTP.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1071.003
Mail Protocols
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1071.004
DNS
MalwareBRICKSTORM

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

T1071.004
DNS
MalwarePOWRUNER

POWRUNER can use DNS for C2 communications.

T1071.004
DNS
MalwarePOWERSOURCE

POWERSOURCE uses DNS TXT records for C2.

T1071.004
DNS
MalwareMatryoshka

Matryoshka uses DNS for C2.

T1071.004
DNS
MalwareSystemBC

SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.

T1071.004
DNS
MalwareWellMess

WellMess has the ability to use DNS tunneling for C2 communications.

T1071.004
DNS
MalwareSombRAT

SombRAT can communicate over DNS with the C2 server.

T1071.004
DNS
MalwareInvisiMole

InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies.

T1071.004
DNS
MalwareRDAT

RDAT has used DNS to communicate with the C2.

T1071.004
DNS
MalwareTEXTMATE

TEXTMATE uses DNS TXT records for C2.

T1071.004
DNS
MalwareGreen Lambert

Green Lambert can use DNS for C2 communications.

T1071.004
DNS
MalwareAnchor

Variants of Anchor can use DNS tunneling to communicate with C2.

T1071.004
DNS
MalwarePlugX

PlugX can be configured to use DNS for command and control.

T1071.004
DNS
MalwareRemsec

Remsec is capable of using DNS for C2.

T1071.004
DNS
MalwareDarkGate

DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques.

T1071.004
DNS
MalwareNanHaiShu

NanHaiShu uses DNS for the C2 communications.

T1071.004
DNS
MalwareMori

Mori can use DNS tunneling to communicate with C2.

T1071.004
DNS
MalwareQUADAGENT

QUADAGENT uses DNS for C2 communications.

T1071.004
DNS
MalwareUroburos

Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character.

T1071.004
DNS
MalwareDnsSystem

DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records.

T1071.004
DNS
MalwareNightClub

NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request.

T1071.004
DNS
MalwareShark

Shark can use DNS in C2 communications.

T1071.004
DNS
MalwareSOUNDBITE

SOUNDBITE communicates via DNS for C2.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareSUNBURST

SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications.

T1071.004
DNS
MalwareCobian RAT

Cobian RAT uses DNS for C2.

T1071.004
DNS
MalwareMilan

Milan has the ability to use DNS for C2 communications.

T1071.004
DNS
MalwareDanBot

DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.

T1071.004
DNS
MalwarePisloader

Pisloader uses DNS as its C2 protocol.

T1071.004
DNS
MalwareSysUpdate

SysUpdate has used DNS TXT requests as for its C2 communication.

T1071.004
DNS
MalwareBONDUPDATER

BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.

T1071.004
DNS
MalwareEbury

Ebury has used DNS requests over UDP port 53 for C2.

T1071.004
DNS
MalwareHeyoka Backdoor

Heyoka Backdoor can use DNS tunneling for C2 communications.

T1071.004
DNS
MalwareHTTPBrowser

HTTPBrowser has used DNS for command and control.

T1071.004
DNS
MalwareKevin

Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information.

T1071.004
DNS
MalwareGoopy

Goopy has the ability to communicate with its C2 over DNS.

T1071.004
DNS
MalwareShadowPad

ShadowPad has used DNS tunneling for C2 communications.

T1071.004
DNS
MalwareGelsemium

Gelsemium has the ability to use DNS in communication with C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.