ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1020×

21 examples

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareStrongPity

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1020
Automated Exfiltration
MalwareHannotog

Hannotog can upload encyrpted data for exfiltration.

T1020
Automated Exfiltration
MalwareCosmicDuke

CosmicDuke exfiltrates collected files automatically over FTP to remote servers.

T1020
Automated Exfiltration
MalwareMachete

Machete’s collected files are exfiltrated automatically to remote servers.

T1020
Automated Exfiltration
MalwareDoki

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

T1020
Automated Exfiltration
MalwareRover

Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe.

T1020
Automated Exfiltration
MalwareLightNeuron

LightNeuron can be configured to automatically exfiltrate files under a specified directory.

T1020
Automated Exfiltration
MalwarePeppy

Peppy has the ability to automatically exfiltrate files and keylogs.

T1020
Automated Exfiltration
MalwareTINYTYPHON

When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.

T1020
Automated Exfiltration
MalwareAttor

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

T1020
Automated Exfiltration
MalwareCrutch

Crutch has automatically exfiltrated stolen files to Dropbox.

T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1020
Automated Exfiltration
MalwareUSBStealer

USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine.

T1020
Automated Exfiltration
MalwareTajMahal

TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1020
Automated Exfiltration
MalwareSolar

Solar can automatically exfitrate files from compromised systems.

T1020
Automated Exfiltration
MalwareOutSteel

OutSteel can automatically upload collected files to its C2 server.

T1020
Automated Exfiltration
MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1020
Automated Exfiltration
ToolShimRatReporter

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1020
Automated Exfiltration
ToolEmpire

Empire has the ability to automatically send collected data back to the threat actors' C2.

T1020
Automated Exfiltration
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.