Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1029 Scheduled Transfer |
MalwareNinja | Ninja can configure its agent to work only in specific time frames. |
| T1029 Scheduled Transfer |
MalwareTinyTurla | TinyTurla contacts its C2 based on a scheduled timing set in its configuration. |
| T1029 Scheduled Transfer |
MalwareMachete | Machete sends stolen data to the C2 server every 10 minutes. |
| T1029 Scheduled Transfer |
MalwareKazuar | Kazuar can sleep for a specific time and be set to communicate at specific intervals. |
| T1029 Scheduled Transfer |
MalwareShimRat | ShimRat can sleep when instructed to do so by the C2. |
| T1029 Scheduled Transfer |
MalwareChrommme | Chrommme can set itself to sleep before requesting a new command from C2. |
| T1029 Scheduled Transfer |
MalwareFlagpro | Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2. |
| T1029 Scheduled Transfer |
MalwareLightNeuron | LightNeuron can be configured to exfiltrate data during nighttime or working hours. |
| T1029 Scheduled Transfer |
MalwareShark | Shark can pause C2 communications for a specified time. |
| T1029 Scheduled Transfer |
MalwareCobalt Strike | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval. |
| T1029 Scheduled Transfer |
MalwareComRAT | ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday). |
| T1029 Scheduled Transfer |
MalwareDipsind | Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic. |
| T1029 Scheduled Transfer |
MalwarePOWERSTATS | POWERSTATS can sleep for a given number of seconds. |
| T1029 Scheduled Transfer |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure. |
| T1029 Scheduled Transfer |
MalwareShadowPad | ShadowPad has sent data back to C2 every 8 hours. |
| T1029 Scheduled Transfer |
MalwarejRAT | jRAT can be configured to reconnect at certain intervals. |
| T1029 Scheduled Transfer |
MalwareADVSTORESHELL | ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.