ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1041×

10 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure.

T1041
Exfiltration Over C2 Channel
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

T1041
Exfiltration Over C2 Channel
CampaignRedPenguin

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1041
Exfiltration Over C2 Channel
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1041
Exfiltration Over C2 Channel
CampaignOperation Wocao

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

T1041
Exfiltration Over C2 Channel
CampaignLeviathan Australian Intrusions

Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.

T1041
Exfiltration Over C2 Channel
CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.