Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWindTail | WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareInvisibleFerret | InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareBrave Prince | Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePUBLOAD | PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareSocGholish | SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareRemsec | Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCharmPower | CharmPower can send victim data via FTP with credentials hardcoded in the script. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKONNI | KONNI has used FTP to exfiltrate reconnaissance data out. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCORALDECK | CORALDECK has exfiltrated data in HTTP POST headers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Malwareccf32 | ccf32 can upload collected data and files to an FTP server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWARPWIRE | WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCherry Picker | Cherry Picker exfiltrates files over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCarbon | Carbon uses HTTP to send data to the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKessel | Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePoetRAT | |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCookieMiner | CookieMiner has used the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareDok | Dok exfiltrates logs of its execution stored in the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolRclone | Rclone can exfiltrate data over FTP or HTTP, including HTTP via WebDAV. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload files from a compromised host. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Toolftp | ftp may be used to exfiltrate data separate from the main command and control protocol. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.