Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1608.001 Upload Malware |
GroupBlackByte | BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites. |
| T1608.001 Upload Malware |
GroupSideCopy | SideCopy has used compromised domains to host its malicious payloads. |
| T1608.001 Upload Malware |
GroupMustard Tempest | Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months. |
| T1608.001 Upload Malware |
GroupKimsuky | Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupEXOTIC LILY | EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive. |
| T1608.001 Upload Malware |
GroupAPT32 | APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupTeamTNT | TeamTNT has uploaded backdoored Docker images to Docker Hub. |
| T1608.001 Upload Malware |
GroupFIN7 | FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip. |
| T1608.001 Upload Malware |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user. |
| T1608.001 Upload Malware |
GroupMustang Panda | Mustang Panda has hosted malicious payloads on DropBox including PlugX. |
| T1608.001 Upload Malware |
GroupContagious Interview | Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1608.001 Upload Malware |
GroupTA2541 | TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub. |
| T1608.001 Upload Malware |
GroupOilRig | OilRig has hosted malware on fake websites designed to target specific audiences. |
| T1608.001 Upload Malware |
GroupSaint Bear | Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails. |
| T1608.001 Upload Malware |
GroupTA505 | TA505 has staged malware on actor-controlled domains. |
| T1608.001 Upload Malware |
GroupBITTER | BITTER has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupStar Blizzard | Star Blizzard has uploaded malicious payloads to cloud storage sites. |
| T1608.001 Upload Malware |
GroupLazyScripter | LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub. |
| T1608.001 Upload Malware |
GroupLuminousMoth | LuminousMoth has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupAPT42 | APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application. |
| T1608.001 Upload Malware |
GroupAPT-C-36 | APT-C-36 has staged malware implants on group-owned repositories and sites. |
| T1608.001 Upload Malware |
GroupEarth Lusca | Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive. |
| T1608.001 Upload Malware |
GroupMoonstone Sleet | Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware. |
| T1608.001 Upload Malware |
GroupHEXANE | HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations. |
| T1608.001 Upload Malware |
GroupWIRTE | WIRTE has directed victims to malicious payloads staged on file sharing services. |
| T1608.001 Upload Malware |
GroupThreat Group-3390 | Threat Group-3390 has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupTeamPCP | TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.