ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1048.003×

22 examples

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWindTail

WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareInvisibleFerret

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareBrave Prince

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCosmicDuke

CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePUBLOAD

PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareSocGholish

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareRemsec

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCharmPower

CharmPower can send victim data via FTP with credentials hardcoded in the script.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKONNI

KONNI has used FTP to exfiltrate reconnaissance data out.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCORALDECK

CORALDECK has exfiltrated data in HTTP POST headers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Malwareccf32

ccf32 can upload collected data and files to an FTP server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWARPWIRE

WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCherry Picker

Cherry Picker exfiltrates files over FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCarbon

Carbon uses HTTP to send data to the C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKessel

Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePoetRAT

PoetRAT has used ftp for exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCookieMiner

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareDok

Dok exfiltrates logs of its execution stored in the /tmp folder over FTP using the curl command.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
ToolRclone

Rclone can exfiltrate data over FTP or HTTP, including HTTP via WebDAV.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload files from a compromised host.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Toolftp

ftp may be used to exfiltrate data separate from the main command and control protocol.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.