Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.002 Asymmetric Cryptography |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedEcho | RedEcho uses SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
GroupTA2541 | TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT. |
| T1573.002 Asymmetric Cryptography |
GroupOilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupTropic Trooper | Tropic Trooper has used SSL to connect to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedCurl | RedCurl has used HTTPS for C2 communication. |
| T1573.002 Asymmetric Cryptography |
GroupMedusa Group | Medusa Group has used HTTPS for command and control. |
| T1573.002 Asymmetric Cryptography |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1573.002 Asymmetric Cryptography |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1573.002 Asymmetric Cryptography |
GroupVelvet Ant | Velvet Ant has used a reverse SSH shell to securely communicate with victim devices. |
| T1573.002 Asymmetric Cryptography |
GroupFIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. |
| T1573.002 Asymmetric Cryptography |
GroupShinyHunters | ShinyHunters has established a connection between the staging host and the C2 using SSH. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.