ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

57 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

T1071.001
Web Protocols
GroupBlackByte

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.

T1071.001
Web Protocols
GroupKimsuky

Kimsuky has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
GroupAPT41

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.

T1071.001
Web Protocols
GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

T1071.001
Web Protocols
GroupHAFNIUM

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupRedEcho

RedEcho network activity is associated with SSL traffic via TCP 443 and proxied HTTP traffic over non-standard ports.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1071.001
Web Protocols
GroupSandworm Team

Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP.

T1071.001
Web Protocols
GroupAPT18

APT18 uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1071.001
Web Protocols
GroupRocke

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1071.001
Web Protocols
GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.001
Web Protocols
GroupHigaisa

Higaisa used HTTP and HTTPS to send data back to its C2 server.

T1071.001
Web Protocols
GroupTropic Trooper

Tropic Trooper has used HTTP in communication with the C2.

T1071.001
Web Protocols
GroupOrangeworm

Orangeworm has used HTTP for C2.

T1071.001
Web Protocols
GroupSea Turtle

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.001
Web Protocols
GroupConfucius

Confucius has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWinter Vivern

Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.

T1071.001
Web Protocols
GroupSilverTerrier

SilverTerrier uses HTTP for C2 communications.

T1071.001
Web Protocols
GroupTurla

Turla has used HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
GroupTA505

TA505 has used HTTP to communicate with C2 nodes.

T1071.001
Web Protocols
GroupBITTER

BITTER has used HTTP POST requests for C2.

T1071.001
Web Protocols
GroupRedCurl

RedCurl has used HTTP, HTTPS and Webdav protocls for C2 communications.

T1071.001
Web Protocols
GroupStealth Falcon

Stealth Falcon malware communicates with its C2 server via HTTPS.

T1071.001
Web Protocols
GroupDark Caracal

Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.

T1071.001
Web Protocols
GroupChimera

Chimera has used HTTPS for C2 communications.

T1071.001
Web Protocols
GroupMedusa Group

Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).

T1071.001
Web Protocols
GroupBRONZE BUTLER

BRONZE BUTLER malware has used HTTP for C2.

T1071.001
Web Protocols
GroupTA551

TA551 has used HTTP for C2 communications.

T1071.001
Web Protocols
GroupWindshift

Windshift has used tools that communicate with C2 over HTTP.

T1071.001
Web Protocols
GroupLuminousMoth

LuminousMoth has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.001
Web Protocols
GroupMetador

Metador has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1071.001
Web Protocols
GroupFIN4

FIN4 has used HTTP POST requests to transmit data.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.001
Web Protocols
GroupWizard Spider

Wizard Spider has used HTTP for network communications.

T1071.001
Web Protocols
GroupMoonstone Sleet

Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1071.001
Web Protocols
GroupVOID MANTICORE

VOID MANTICORE has utilized HTTPS for communication to C2 domains.

T1071.001
Web Protocols
GroupDaggerfly

Daggerfly uses HTTP for command and control communication.

T1071.001
Web Protocols
GroupRancor

Rancor has used HTTP for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.