ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.003×

20 examples

TechniqueUsed byProcedure example
T1071.003
Mail Protocols
MalwarePowerExchange

PowerExchange can receive and send back the results of executed C2 commands through email.

T1071.003
Mail Protocols
MalwareOLDBAIT

OLDBAIT can use SMTP for C2.

T1071.003
Mail Protocols
MalwareIMAPLoader

IMAPLoader uses the IMAP email protocol for command and control purposes.

T1071.003
Mail Protocols
MalwareRDAT

RDAT can use email attachments for C2 communications.

T1071.003
Mail Protocols
MalwareNavRAT

NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP.

T1071.003
Mail Protocols
MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.003
Mail Protocols
MalwareLightNeuron

LightNeuron uses SMTP for C2.

T1071.003
Mail Protocols
MalwareUroburos

Uroburos can use custom communications protocols that ride over SMTP.

T1071.003
Mail Protocols
MalwareNightClub

NightClub can use emails for C2 communications.

T1071.003
Mail Protocols
MalwareBadPatch

BadPatch uses SMTP for C2.

T1071.003
Mail Protocols
MalwareSUGARDUMP

A SUGARDUMP variant used SMTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareLunarMail

LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI).

T1071.003
Mail Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

T1071.003
Mail Protocols
MalwareCannon

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

T1071.003
Mail Protocols
MalwareComRAT

ComRAT can use email attachments for command and control.

T1071.003
Mail Protocols
MalwareJPIN

JPIN can send email over SMTP.

T1071.003
Mail Protocols
MalwareAgent Tesla

Agent Tesla has used SMTP for C2 communications.

T1071.003
Mail Protocols
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.