Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareStrongPity | StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1020 Automated Exfiltration |
MalwareHannotog | Hannotog can upload encyrpted data for exfiltration. |
| T1020 Automated Exfiltration |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files automatically over FTP to remote servers. |
| T1020 Automated Exfiltration |
MalwareMachete | Machete’s collected files are exfiltrated automatically to remote servers. |
| T1020 Automated Exfiltration |
MalwareDoki | Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| T1020 Automated Exfiltration |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe. |
| T1020 Automated Exfiltration |
MalwareLightNeuron | LightNeuron can be configured to automatically exfiltrate files under a specified directory. |
| T1020 Automated Exfiltration |
MalwarePeppy | Peppy has the ability to automatically exfiltrate files and keylogs. |
| T1020 Automated Exfiltration |
MalwareTINYTYPHON | When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server. |
| T1020 Automated Exfiltration |
MalwareAttor | Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| T1020 Automated Exfiltration |
MalwareCrutch | Crutch has automatically exfiltrated stolen files to Dropbox. |
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1020 Automated Exfiltration |
MalwareUSBStealer | USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine. |
| T1020 Automated Exfiltration |
MalwareTajMahal | TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1020 Automated Exfiltration |
MalwareSolar | Solar can automatically exfitrate files from compromised systems. |
| T1020 Automated Exfiltration |
MalwareOutSteel | OutSteel can automatically upload collected files to its C2 server. |
| T1020 Automated Exfiltration |
MalwareEbury | If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| T1020 Automated Exfiltration |
ToolShimRatReporter | ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2. |
| T1020 Automated Exfiltration |
ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1020 Automated Exfiltration |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.