ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1570×

19 examples

TechniqueUsed byProcedure example
T1570
Lateral Tool Transfer
GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

T1570
Lateral Tool Transfer
GroupGALLIUM

GALLIUM has used PsExec to move laterally between hosts in the target network.

T1570
Lateral Tool Transfer
GroupVolt Typhoon

Volt Typhoon has copied web shells between servers in targeted environments.

T1570
Lateral Tool Transfer
GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

T1570
Lateral Tool Transfer
GroupAPT32

APT32 has deployed tools after moving laterally using administrative accounts.

T1570
Lateral Tool Transfer
GroupStorm-1811

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.

T1570
Lateral Tool Transfer
GroupSandworm Team

Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access.

T1570
Lateral Tool Transfer
GroupUNC3886

UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs.

T1570
Lateral Tool Transfer
GroupAoqin Dragon

Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices.

T1570
Lateral Tool Transfer
GroupTurla

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.

T1570
Lateral Tool Transfer
GroupChimera

Chimera has copied tools between compromised hosts using SMB.

T1570
Lateral Tool Transfer
GroupMedusa Group

Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.

T1570
Lateral Tool Transfer
GroupEmber Bear

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.

T1570
Lateral Tool Transfer
GroupAgrius

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.

T1570
Lateral Tool Transfer
GroupINC Ransom

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
GroupWizard Spider

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.

T1570
Lateral Tool Transfer
GroupVelvet Ant

Velvet Ant transferred files laterally within victim networks through the Impacket toolkit.

T1570
Lateral Tool Transfer
GroupMagic Hound

Magic Hound has copied tools within a compromised network using RDP.

T1570
Lateral Tool Transfer
GroupFIN10

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.