Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102.002 Bidirectional Communication |
GroupKimsuky | Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information. |
| T1102.002 Bidirectional Communication |
GroupMuddyWater | MuddyWater has used web services including OneHub to distribute remote access tools. |
| T1102.002 Bidirectional Communication |
GroupGamaredon Group | Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain. |
| T1102.002 Bidirectional Communication |
GroupFIN7 | FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2. |
| T1102.002 Bidirectional Communication |
GroupSandworm Team | Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1102.002 Bidirectional Communication |
GroupAPT39 | APT39 has communicated with C2 through files uploaded to and downloaded from DropBox. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1102.002 Bidirectional Communication |
GroupCarbanak | Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2. |
| T1102.002 Bidirectional Communication |
GroupPOLONIUM | POLONIUM has used OneDrive and DropBox for C2. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1102.002 Bidirectional Communication |
GroupAPT28 | APT28 has used Google Drive for C2. |
| T1102.002 Bidirectional Communication |
GroupAPT12 | APT12 has used blogs and WordPress for C2 infrastructure. |
| T1102.002 Bidirectional Communication |
GroupLazarus Group | Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories. |
| T1102.002 Bidirectional Communication |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for C2. |
| T1102.002 Bidirectional Communication |
GroupMagic Hound | Magic Hound malware can use a SOAP Web service to communicate with its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.