Real-world descriptions of how a group, tool or campaign used a technique.
51 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareTrickBot | TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1008 Fallback Channels |
MalwareBumblebee | Bumblebee can use backup C2 servers if the primary server fails. |
| T1008 Fallback Channels |
MalwareStuxnet | Stuxnet has the ability to generate new C2 domains. |
| T1008 Fallback Channels |
MalwareExaramel for Linux | Exaramel for Linux can attempt to find a new C2 server if it receives an error. |
| T1008 Fallback Channels |
MalwareWinMM | WinMM is usually configured with primary and backup domains for C2 communications. |
| T1008 Fallback Channels |
MalwareRainyDay | RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working. |
| T1008 Fallback Channels |
MalwareAppleSeed | AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| T1008 Fallback Channels |
MalwareTinyTurla | TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds. |
| T1008 Fallback Channels |
MalwareSslMM | SslMM has a hard-coded primary and backup C2 string. |
| T1008 Fallback Channels |
MalwareMachete | Machete has sent data over HTTP if FTP failed, and has also used a fallback server. |
| T1008 Fallback Channels |
MalwareHOPLIGHT | HOPLIGHT has multiple C2 channels in place in case one fails. |
| T1008 Fallback Channels |
MalwareInvisiMole | InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1008 Fallback Channels |
MalwareQUIETEXIT | QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails. |
| T1008 Fallback Channels |
MalwareRDAT | RDAT has used HTTP if DNS C2 communications were not functioning. |
| T1008 Fallback Channels |
MalwareKazuar | Kazuar can accept multiple URLs for C2 servers. |
| T1008 Fallback Channels |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000. |
| T1008 Fallback Channels |
MalwareFatDuke | FatDuke has used several C2 servers per targeted organization. |
| T1008 Fallback Channels |
MalwareBlackEnergy | BlackEnergy has the capability to communicate over a backup channel via plus.google.com. |
| T1008 Fallback Channels |
MalwareShimRat | ShimRat has used a secondary C2 location if the first was unavailable. |
| T1008 Fallback Channels |
MalwareMiniDuke | MiniDuke uses Google Search to identify C2 servers if its primary C2 method via Twitter is not working. |
| T1008 Fallback Channels |
MalwareAnchor | Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1008 Fallback Channels |
MalwareS-Type | S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails. |
| T1008 Fallback Channels |
MalwareDustySky | DustySky has two hard-coded domains for C2 servers; if the first does not respond, it will try the second. |
| T1008 Fallback Channels |
MalwareXTunnel | The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port. |
| T1008 Fallback Channels |
MalwareCharmPower | CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket. |
| T1008 Fallback Channels |
MalwareQUADAGENT | QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful. |
| T1008 Fallback Channels |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can randomly pick one of five hard-coded IP addresses for C2 communication; if one of the IP fails, it will wait 60 seconds and then try another IP address. |
| T1008 Fallback Channels |
MalwareGlassWorm | GlassWorm has utilized Google Calendar as backup C2. |
| T1008 Fallback Channels |
MalwareUroburos | Uroburos can use up to 10 channels to communicate between implants. |
| T1008 Fallback Channels |
MalwarePipeMon | PipeMon can switch to an alternate C2 domain when a particular date has been reached. |
| T1008 Fallback Channels |
MalwareJHUHUGIT | JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails. |
| T1008 Fallback Channels |
MalwareCrutch | Crutch has used a hardcoded GitHub repository as a fallback channel. |
| T1008 Fallback Channels |
MalwareDerusbi | Derusbi uses a backup communication method with an HTTP beacon. |
| T1008 Fallback Channels |
MalwareShark | Shark can update its configuration to use a different C2 server. |
| T1008 Fallback Channels |
MalwareBazar | Bazar has the ability to use an alternative C2 server if the primary server fails. |
| T1008 Fallback Channels |
MalwareHiddenFace | HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands. |
| T1008 Fallback Channels |
MalwareValak | Valak can communicate over multiple C2 hosts. |
| T1008 Fallback Channels |
MalwareOilBooster | OilBooster can use a backup channel to request a new refresh token from its C2 server after 10 consecutive unsuccessful connections to the primary OneDrive C2 server. |
| T1008 Fallback Channels |
MalwareCardinal RAT | Cardinal RAT can communicate over multiple C2 host and port combinations. |
| T1008 Fallback Channels |
MalwareBISCUIT | BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server. |
| T1008 Fallback Channels |
MalwareKwampirs | Kwampirs uses a large list of C2 servers that it cycles through until a successful connection is established. |
| T1008 Fallback Channels |
MalwareCHOPSTICK | CHOPSTICK can switch to a new C2 channel if the current one is broken. |
| T1008 Fallback Channels |
MalwareEbury | Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days. |
| T1008 Fallback Channels |
MalwareSideTwist | SideTwist has primarily used port 443 for C2 but can use port 80 as a fallback. |
| T1008 Fallback Channels |
MalwareMis-Type | Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol to communicate to an alternate C2 server. |
| T1008 Fallback Channels |
MalwareKevin | Kevin can assign hard-coded fallback domains for C2. |
| T1008 Fallback Channels |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can change C2 servers. |
| T1008 Fallback Channels |
MalwareGelsemium | Gelsemium can use multiple domains and protocols in C2. |
| T1008 Fallback Channels |
ToolMythic | Mythic can use a list of C2 URLs as fallback mechanisms in case one IP or domain gets blocked. |
| T1008 Fallback Channels |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.