Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupSalt Typhoon | Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT32 | APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN6 | FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupMustang Panda | Mustang Panda has used FTP to exfiltrate archive files. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview | Contagious Interview has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupOilRig | OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupLazarus Group | Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupThrip | Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT33 | APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN8 | FIN8 has used FTP to exfiltrate collected data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.