Real-world descriptions of how a group, tool or campaign used a technique.
88 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
GroupAPT38 | APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine. |
| T1105 Ingress Tool Transfer |
GroupIndrik Spider | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupBlackByte | BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites. |
| T1105 Ingress Tool Transfer |
GroupElderwood | The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location. |
| T1105 Ingress Tool Transfer |
GroupSideCopy | SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads. |
| T1105 Ingress Tool Transfer |
GroupGALLIUM | GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN. |
| T1105 Ingress Tool Transfer |
GroupAPT3 | APT3 has a tool that can copy files to remote machines. |
| T1105 Ingress Tool Transfer |
GroupMustard Tempest | Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupKimsuky | Kimsuky has downloaded additional scripts, tools, and malware onto victim systems. |
| T1105 Ingress Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder. |
| T1105 Ingress Tool Transfer |
GroupPatchwork | Patchwork payloads download additional files from the C2 server. |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1105 Ingress Tool Transfer |
GroupDragonfly | Dragonfly has copied and installed tools for operations once in the victim environment. |
| T1105 Ingress Tool Transfer |
GroupEvilnum | Evilnum can deploy additional components or tools as needed. |
| T1105 Ingress Tool Transfer |
GroupGorgon Group | Gorgon Group malware can download additional files from C2 servers. |
| T1105 Ingress Tool Transfer |
GroupmenuPass | menuPass has installed updates and new malware on victims. |
| T1105 Ingress Tool Transfer |
GroupAPT32 | APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors. |
| T1105 Ingress Tool Transfer |
GroupHAFNIUM | HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1105 Ingress Tool Transfer |
GroupStorm-1811 | Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices. |
| T1105 Ingress Tool Transfer |
GroupTeamTNT | TeamTNT has the |
| T1105 Ingress Tool Transfer |
GroupFIN7 | FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload. |
| T1105 Ingress Tool Transfer |
GroupSandworm Team | Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1105 Ingress Tool Transfer |
GroupAPT18 | APT18 can upload a file to the victim’s machine. |
| T1105 Ingress Tool Transfer |
GroupAndariel | Andariel has downloaded additional tools and malware onto compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupSidewinder | Sidewinder has used LNK files to download remote files to the victim's network. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1105 Ingress Tool Transfer |
GroupZIRCONIUM | ZIRCONIUM has used tools to download malicious files to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupRocke | Rocke used malware to download additional malicious files to the target system. |
| T1105 Ingress Tool Transfer |
GroupScattered Spider | Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers. |
| T1105 Ingress Tool Transfer |
GroupAPT39 | APT39 has downloaded tools to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupTA2541 | TA2541 has used malicious scripts and macros with the ability to download additional payloads. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1105 Ingress Tool Transfer |
GroupMoses Staff | Moses Staff has downloaded and installed web shells to following path |
| T1105 Ingress Tool Transfer |
GroupOilRig | OilRig had downloaded remote files onto victim infrastructure. |
| T1105 Ingress Tool Transfer |
GroupTropic Trooper | Tropic Trooper has used a delivered trojan to download additional files. |
| T1105 Ingress Tool Transfer |
GroupAquatic Panda | Aquatic Panda has downloaded additional malware onto compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupKe3chang | Ke3chang has used tools to download files to compromised machines. |
| T1105 Ingress Tool Transfer |
GroupConfucius | Confucius has downloaded additional files and payloads onto a compromised host following initial access. |
| T1105 Ingress Tool Transfer |
GroupLeviathan | Leviathan has downloaded additional scripts and files from adversary-controlled servers. |
| T1105 Ingress Tool Transfer |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads. |
| T1105 Ingress Tool Transfer |
GroupTurla | Turla has used shellcode to download Meterpreter after compromising a victim. |
| T1105 Ingress Tool Transfer |
GroupTA505 | TA505 has downloaded additional malware to execute on victim systems. |
| T1105 Ingress Tool Transfer |
GroupBITTER | BITTER has downloaded additional malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1105 Ingress Tool Transfer |
GroupCinnamon Tempest | Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts. |
| T1105 Ingress Tool Transfer |
GroupChimera | Chimera has remotely copied tools and malware onto targeted systems. |
| T1105 Ingress Tool Transfer |
GroupMedusa Group | Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools. |
| T1105 Ingress Tool Transfer |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.