ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1074.002×

11 examples

TechniqueUsed byProcedure example
T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1074.002
Remote Data Staging
GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

T1074.002
Remote Data Staging
GroupSea Turtle

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1074.002
Remote Data Staging
GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

T1074.002
Remote Data Staging
GroupMoustachedBouncer

MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share.

T1074.002
Remote Data Staging
GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

T1074.002
Remote Data Staging
GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

T1074.002
Remote Data Staging
GroupToddyCat

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

T1074.002
Remote Data Staging
GroupAPT28

APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server.

T1074.002
Remote Data Staging
GroupThreat Group-3390

Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration.

T1074.002
Remote Data Staging
GroupFIN8

FIN8 aggregates staged data from a network into a single location.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.