ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1048.003×

11 examples

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupSalt Typhoon

Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT32

APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupThrip

Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupWizard Spider

Wizard Spider has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.