ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1041×

27 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1041
Exfiltration Over C2 Channel
GroupGALLIUM

GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.

T1041
Exfiltration Over C2 Channel
GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKimsuky

Kimsuky has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupAPT32

APT32's backdoor has exfiltrated data using the already opened channel with its C&C server.

T1041
Exfiltration Over C2 Channel
GroupMuddyWater

MuddyWater has used C2 infrastructure to receive exfiltrated data.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1041
Exfiltration Over C2 Channel
GroupSandworm Team

Sandworm Team has sent system information to its C2 server using HTTP.

T1041
Exfiltration Over C2 Channel
GroupCURIUM

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1041
Exfiltration Over C2 Channel
GroupMustang Panda

Mustang Panda has exfiltrated stolen data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupZIRCONIUM

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1041
Exfiltration Over C2 Channel
GroupScattered Spider

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1041
Exfiltration Over C2 Channel
GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
GroupHigaisa

Higaisa exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKe3chang

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

T1041
Exfiltration Over C2 Channel
GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupLeviathan

Leviathan has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1041
Exfiltration Over C2 Channel
GroupStealth Falcon

After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1041
Exfiltration Over C2 Channel
GroupLuminousMoth

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1041
Exfiltration Over C2 Channel
GroupWizard Spider

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1041
Exfiltration Over C2 Channel
GroupVOID MANTICORE

VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.

T1041
Exfiltration Over C2 Channel
GroupWIRTE

WIRTE has exfiltrated collected victim data to C2 infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.