ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.004×

43 examples

TechniqueUsed byProcedure example
T1071.004
DNS
MalwareBRICKSTORM

BRICKSTORM has used DNS over HTTPS to resolve C2 infrastructure and obscure DNS traffic from inspection.

T1071.004
DNS
MalwarePOWRUNER

POWRUNER can use DNS for C2 communications.

T1071.004
DNS
MalwarePOWERSOURCE

POWERSOURCE uses DNS TXT records for C2.

T1071.004
DNS
MalwareMatryoshka

Matryoshka uses DNS for C2.

T1071.004
DNS
MalwareSystemBC

SystemBC has used DNS servers to resolve .bit domains to C2 infrastructure.

T1071.004
DNS
MalwareWellMess

WellMess has the ability to use DNS tunneling for C2 communications.

T1071.004
DNS
MalwareSombRAT

SombRAT can communicate over DNS with the C2 server.

T1071.004
DNS
MalwareInvisiMole

InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies.

T1071.004
DNS
MalwareRDAT

RDAT has used DNS to communicate with the C2.

T1071.004
DNS
MalwareTEXTMATE

TEXTMATE uses DNS TXT records for C2.

T1071.004
DNS
MalwareGreen Lambert

Green Lambert can use DNS for C2 communications.

T1071.004
DNS
MalwareAnchor

Variants of Anchor can use DNS tunneling to communicate with C2.

T1071.004
DNS
MalwarePlugX

PlugX can be configured to use DNS for command and control.

T1071.004
DNS
MalwareRemsec

Remsec is capable of using DNS for C2.

T1071.004
DNS
MalwareDarkGate

DarkGate can cloak command and control traffic in DNS records from legitimate services to avoid reputation-based detection techniques.

T1071.004
DNS
MalwareNanHaiShu

NanHaiShu uses DNS for the C2 communications.

T1071.004
DNS
MalwareMori

Mori can use DNS tunneling to communicate with C2.

T1071.004
DNS
MalwareQUADAGENT

QUADAGENT uses DNS for C2 communications.

T1071.004
DNS
MalwareUroburos

Uroburos has encoded outbound C2 communications in DNS requests consisting of character strings made to resemble standard domain names. The actual information transmitted by Uroburos is contained in the part of the character string prior to the first ‘.’ character.

T1071.004
DNS
MalwareDnsSystem

DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records.

T1071.004
DNS
MalwareNightClub

NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request.

T1071.004
DNS
MalwareShark

Shark can use DNS in C2 communications.

T1071.004
DNS
MalwareSOUNDBITE

SOUNDBITE communicates via DNS for C2.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareSUNBURST

SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications.

T1071.004
DNS
MalwareCobian RAT

Cobian RAT uses DNS for C2.

T1071.004
DNS
MalwareMilan

Milan has the ability to use DNS for C2 communications.

T1071.004
DNS
MalwareDanBot

DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.

T1071.004
DNS
MalwarePisloader

Pisloader uses DNS as its C2 protocol.

T1071.004
DNS
MalwareSysUpdate

SysUpdate has used DNS TXT requests as for its C2 communication.

T1071.004
DNS
MalwareBONDUPDATER

BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.

T1071.004
DNS
MalwareEbury

Ebury has used DNS requests over UDP port 53 for C2.

T1071.004
DNS
MalwareHeyoka Backdoor

Heyoka Backdoor can use DNS tunneling for C2 communications.

T1071.004
DNS
MalwareHTTPBrowser

HTTPBrowser has used DNS for command and control.

T1071.004
DNS
MalwareKevin

Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information.

T1071.004
DNS
MalwareGoopy

Goopy has the ability to communicate with its C2 over DNS.

T1071.004
DNS
MalwareShadowPad

ShadowPad has used DNS tunneling for C2 communications.

T1071.004
DNS
MalwareGelsemium

Gelsemium has the ability to use DNS in communication with C2.

T1071.004
DNS
MalwareHelminth

Helminth can use DNS for C2.

T1071.004
DNS
MalwareDenis

Denis has used DNS tunneling for C2 communications.

T1071.004
DNS
ToolSliver

Sliver can support C2 communications over DNS.

T1071.004
DNS
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1071.004
DNS
ToolMythic

Mythic supports DNS-based C2 profiles.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.