Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.003 Mail Protocols |
MalwareUroburos | Uroburos can use custom communications protocols that ride over SMTP. |
| T1071.003 Mail Protocols |
MalwareNightClub | NightClub can use emails for C2 communications. |
| T1071.003 Mail Protocols |
MalwareBadPatch | BadPatch uses SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant used SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1071.003 Mail Protocols |
MalwareLunarMail | LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI). |
| T1071.003 Mail Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3. |
| T1071.003 Mail Protocols |
MalwareCannon | Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails. |
| T1071.003 Mail Protocols |
MalwareComRAT | ComRAT can use email attachments for command and control. |
| T1071.003 Mail Protocols |
MalwareJPIN | JPIN can send email over SMTP. |
| T1071.003 Mail Protocols |
MalwareAgent Tesla | Agent Tesla has used SMTP for C2 communications. |
| T1071.003 Mail Protocols |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1071.004 DNS |
MalwareBRICKSTORM | BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection. |
| T1071.004 DNS |
MalwarePOWRUNER | POWRUNER can use DNS for C2 communications. |
| T1071.004 DNS |
MalwarePOWERSOURCE | POWERSOURCE uses DNS TXT records for C2. |
| T1071.004 DNS |
MalwareMatryoshka | Matryoshka uses DNS for C2. |
| T1071.004 DNS |
MalwareSystemBC | SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure. |
| T1071.004 DNS |
MalwareWellMess | WellMess has the ability to use DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareSombRAT | SombRAT can communicate over DNS with the C2 server. |
| T1071.004 DNS |
MalwareInvisiMole | InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies. |
| T1071.004 DNS |
MalwareRDAT | RDAT has used DNS to communicate with the C2. |
| T1071.004 DNS |
MalwareTEXTMATE | TEXTMATE uses DNS TXT records for C2. |
| T1071.004 DNS |
MalwareGreen Lambert | Green Lambert can use DNS for C2 communications. |
| T1071.004 DNS |
MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1071.004 DNS |
MalwarePlugX | PlugX can be configured to use DNS for command and control. |
| T1071.004 DNS |
MalwareRemsec | Remsec is capable of using DNS for C2. |
| T1071.004 DNS |
MalwareDarkGate | DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques. |
| T1071.004 DNS |
MalwareNanHaiShu | NanHaiShu uses DNS for the C2 communications. |
| T1071.004 DNS |
MalwareMori | Mori can use DNS tunneling to communicate with C2. |
| T1071.004 DNS |
MalwareQUADAGENT | QUADAGENT uses DNS for C2 communications. |
| T1071.004 DNS |
MalwareUroburos | Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character. |
| T1071.004 DNS |
MalwareDnsSystem | DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records. |
| T1071.004 DNS |
MalwareNightClub | NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request. |
| T1071.004 DNS |
MalwareShark | Shark can use DNS in C2 communications. |
| T1071.004 DNS |
MalwareSOUNDBITE | SOUNDBITE communicates via DNS for C2. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareSUNBURST | SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications. |
| T1071.004 DNS |
MalwareCobian RAT | Cobian RAT uses DNS for C2. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1071.004 DNS |
MalwareDanBot | DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications. |
| T1071.004 DNS |
MalwarePisloader | Pisloader uses DNS as its C2 protocol. |
| T1071.004 DNS |
MalwareSysUpdate | SysUpdate has used DNS TXT requests as for its C2 communication. |
| T1071.004 DNS |
MalwareBONDUPDATER | BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control. |
| T1071.004 DNS |
MalwareEbury | Ebury has used DNS requests over UDP port 53 for C2. |
| T1071.004 DNS |
MalwareHeyoka Backdoor | Heyoka Backdoor can use DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareHTTPBrowser | HTTPBrowser has used DNS for command and control. |
| T1071.004 DNS |
MalwareKevin | Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information. |
| T1071.004 DNS |
MalwareGoopy | Goopy has the ability to communicate with its C2 over DNS. |
| T1071.004 DNS |
MalwareShadowPad | ShadowPad has used DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareGelsemium | Gelsemium has the ability to use DNS in communication with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.