Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
GroupBlackByte | BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1041 Exfiltration Over C2 Channel |
GroupGALLIUM | GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT3 | APT3 has a tool that exfiltrates data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKimsuky | Kimsuky has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT32 | APT32's backdoor has exfiltrated data using the already opened channel with its C&C server. |
| T1041 Exfiltration Over C2 Channel |
GroupMuddyWater | MuddyWater has used C2 infrastructure to receive exfiltrated data. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupSandworm Team | Sandworm Team has sent system information to its C2 server using HTTP. |
| T1041 Exfiltration Over C2 Channel |
GroupCURIUM | CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. |
| T1041 Exfiltration Over C2 Channel |
GroupMustang Panda | Mustang Panda has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1041 Exfiltration Over C2 Channel |
GroupScattered Spider | Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT39 | APT39 has exfiltrated stolen victim data through C2 communications. |
| T1041 Exfiltration Over C2 Channel |
GroupContagious Interview | Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1041 Exfiltration Over C2 Channel |
GroupHigaisa | Higaisa exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKe3chang | Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
| T1041 Exfiltration Over C2 Channel |
GroupConfucius | Confucius has exfiltrated stolen files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupLeviathan | Leviathan has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1041 Exfiltration Over C2 Channel |
GroupStealth Falcon | After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupChimera | Chimera has used Cobalt Strike C2 beacons for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
GroupLuminousMoth | LuminousMoth has used malware that exfiltrates stolen data to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupAgrius | Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. |
| T1041 Exfiltration Over C2 Channel |
GroupLazarus Group | Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware. |
| T1041 Exfiltration Over C2 Channel |
GroupWizard Spider | Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels. |
| T1041 Exfiltration Over C2 Channel |
GroupVOID MANTICORE | VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications. |
| T1041 Exfiltration Over C2 Channel |
GroupWIRTE | WIRTE has exfiltrated collected victim data to C2 infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.