Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.002 File Transfer Protocols |
MalwareNOKKI | NOKKI has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1071.002 File Transfer Protocols |
MalwareSharpDisco | SharpDisco has the ability to transfer data between SMB shares. |
| T1071.002 File Transfer Protocols |
MalwareBADHATCH | BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwarePUBLOAD | PUBLOAD has used `curl` for data exfiltration over FTP. |
| T1071.002 File Transfer Protocols |
MalwareRegin | The Regin malware platform supports many standard protocols, including SMB. |
| T1071.002 File Transfer Protocols |
MalwareKazuar | Kazuar uses FTP and FTPS to communicate with the C2 server. |
| T1071.002 File Transfer Protocols |
MalwareXAgentOSX | XAgentOSX contains the ftpUpload function to use the FTPManager:uploadFile method to upload files from the target system. |
| T1071.002 File Transfer Protocols |
MalwareAttor | Attor has used FTP protocol for C2 communication. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwarePoetRAT | PoetRAT has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareZxShell | ZxShell has used FTP for C2 connections. |
| T1071.002 File Transfer Protocols |
MalwareJPIN | JPIN can communicate over FTP. |
| T1071.002 File Transfer Protocols |
MalwareDisco | Disco can use SMB to transfer files. |
| T1071.002 File Transfer Protocols |
MalwareQilin | Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system. |
| T1071.002 File Transfer Protocols |
MalwareShadowPad | ShadowPad has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareSYSCON | SYSCON has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolCARROTBALL | CARROTBALL has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolMythic | Mythic supports SMB-based peer-to-peer C2 profiles. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.