ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1608.001×

28 examples

TechniqueUsed byProcedure example
T1608.001
Upload Malware
GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

T1608.001
Upload Malware
GroupSideCopy

SideCopy has used compromised domains to host its malicious payloads.

T1608.001
Upload Malware
GroupMustard Tempest

Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months.

T1608.001
Upload Malware
GroupKimsuky

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupEXOTIC LILY

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

T1608.001
Upload Malware
GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

T1608.001
Upload Malware
GroupTeamTNT

TeamTNT has uploaded backdoored Docker images to Docker Hub.

T1608.001
Upload Malware
GroupFIN7

FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip.

T1608.001
Upload Malware
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user.

T1608.001
Upload Malware
GroupMustang Panda

Mustang Panda has hosted malicious payloads on DropBox including PlugX.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

T1608.001
Upload Malware
GroupOilRig

OilRig has hosted malware on fake websites designed to target specific audiences.

T1608.001
Upload Malware
GroupSaint Bear

Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails.

T1608.001
Upload Malware
GroupTA505

TA505 has staged malware on actor-controlled domains.

T1608.001
Upload Malware
GroupBITTER

BITTER has registered domains to stage payloads.

T1608.001
Upload Malware
GroupStar Blizzard

Star Blizzard has uploaded malicious payloads to cloud storage sites.

T1608.001
Upload Malware
GroupLazyScripter

LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub.

T1608.001
Upload Malware
GroupLuminousMoth

LuminousMoth has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupAPT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1608.001
Upload Malware
GroupEarth Lusca

Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.

T1608.001
Upload Malware
GroupMoonstone Sleet

Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware.

T1608.001
Upload Malware
GroupHEXANE

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.

T1608.001
Upload Malware
GroupWIRTE

WIRTE has directed victims to malicious payloads staged on file sharing services.

T1608.001
Upload Malware
GroupThreat Group-3390

Threat Group-3390 has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupTeamPCP

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.