ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.004×

11 examples

TechniqueUsed byProcedure example
T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1071.004
DNS
GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

T1071.004
DNS
GroupAPT18

APT18 uses DNS for C2 communications.

T1071.004
DNS
GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1071.004
DNS
GroupTropic Trooper

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

T1071.004
DNS
GroupKe3chang

Ke3chang malware RoyalDNS has used DNS for C2.

T1071.004
DNS
GroupChimera

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.

T1071.004
DNS
GroupEmber Bear

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.

T1071.004
DNS
GroupLazyScripter

LazyScripter has leveraged dynamic DNS providers for C2 communications.

T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.