Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupFIN6 | FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration. |
| T1074.002 Remote Data Staging |
GroupSea Turtle | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1074.002 Remote Data Staging |
GroupLeviathan | Leviathan has staged data remotely prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share. |
| T1074.002 Remote Data Staging |
GroupChimera | Chimera has staged stolen data on designated servers in the target environment. |
| T1074.002 Remote Data Staging |
GroupMirrorFace | MirrorFace has gathered data and files of interest on a single victim machine. |
| T1074.002 Remote Data Staging |
GroupToddyCat | ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
| T1074.002 Remote Data Staging |
GroupAPT28 | APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server. |
| T1074.002 Remote Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupFIN8 | FIN8 aggregates staged data from a network into a single location. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.