Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2. |
| T1041 Exfiltration Over C2 Channel |
CampaignRedPenguin | During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Wocao | During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
CampaignLeviathan Australian Intrusions | Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions. |
| T1041 Exfiltration Over C2 Channel |
CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.