ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1095×

88 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
Malwarecd00r

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareRotaJakiro

RotaJakiro uses a custom binary protocol using a type, length, value format over TCP.

T1095
Non-Application Layer Protocol
MalwareCOATHANGER

COATHANGER uses ICMP for transmitting configuration information to and from its command and control server.

T1095
Non-Application Layer Protocol
MalwareSardonic

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1095
Non-Application Layer Protocol
MalwareMisdat

Misdat network traffic communicates over a raw socket.

T1095
Non-Application Layer Protocol
MalwarereGeorg

reGeorg can tunnel TCP sessions into targeted networks.

T1095
Non-Application Layer Protocol
MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using SOCKS.

T1095
Non-Application Layer Protocol
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket.

T1095
Non-Application Layer Protocol
MalwareInvisibleFerret

InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000.

T1095
Non-Application Layer Protocol
MalwareNebulae

Nebulae can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareTONESHELL

TONESHELL has utilized TCP-based reverse shells.

T1095
Non-Application Layer Protocol
MalwareRainyDay

RainyDay can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareJ-magic

J-magic can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
MalwareAria-body

Aria-body has used TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareCrimson

Crimson uses a custom TCP protocol for C2.

T1095
Non-Application Layer Protocol
MalwareSystemBC

SystemBC has used raw TCP on non-standard ports, such as 4044, for C2 communications and for HTTP communications, which include downloading binaries.

T1095
Non-Application Layer Protocol
MalwarePingPull

PingPull variants have the ability to communicate with C2 servers using ICMP or TCP.

T1095
Non-Application Layer Protocol
MalwareMafalda

Mafalda can use raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareUmbreon

Umbreon provides access to the system via SSH or any other protocol that uses PAM to authenticate.

T1095
Non-Application Layer Protocol
MalwareAuTo Stealer

AuTo Stealer can use TCP to communicate with command and control servers.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1095
Non-Application Layer Protocol
MalwareSUGARUSH

SUGARUSH has used TCP for C2.

T1095
Non-Application Layer Protocol
MalwareCuckoo Stealer

Cuckoo Stealer can use sockets for communications to its C2 server.

T1095
Non-Application Layer Protocol
MalwareInvisiMole

InvisiMole has used TCP to download additional modules.

T1095
Non-Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can establish a TCP connection as part of its initial connection to the C2.

T1095
Non-Application Layer Protocol
MalwareRegin

The Regin malware platform can use ICMP to communicate between infected computers.

T1095
Non-Application Layer Protocol
MalwareREPTILE

REPTILE can communicate using TLS over raw TCP.

T1095
Non-Application Layer Protocol
MalwareNETEAGLE

If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs.

T1095
Non-Application Layer Protocol
MalwareSnappyTCP

SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation.

T1095
Non-Application Layer Protocol
MalwareAnchor

Anchor has used ICMP in C2 communications.

T1095
Non-Application Layer Protocol
MalwarePlugX

PlugX can be configured to use raw TCP or UDP for command and control.

T1095
Non-Application Layer Protocol
MalwareReaver

Some Reaver variants use raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareBisonal

Bisonal has used raw sockets for network communication.

T1095
Non-Application Layer Protocol
MalwareRemsec

Remsec is capable of using ICMP, TCP, and UDP for C2.

T1095
Non-Application Layer Protocol
MalwareKEYPLUG

KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication.

T1095
Non-Application Layer Protocol
MalwareClambling

Clambling has the ability to use TCP and UDP for communication.

T1095
Non-Application Layer Protocol
MalwareTSCookie

TSCookie can use ICMP to receive information on the destination server.

T1095
Non-Application Layer Protocol
MalwarePay2Key

Pay2Key has sent its public key to the C2 server over TCP.

T1095
Non-Application Layer Protocol
MalwareRoyal

Royal establishes a TCP socket for C2 communication using the API `WSASocketW`.

T1095
Non-Application Layer Protocol
MalwareUroburos

Uroburos can communicate through custom methodologies for UDP, ICMP, and TCP that use distinct sessions to ride over the legitimate protocols.

T1095
Non-Application Layer Protocol
MalwareMetamorfo

Metamorfo has used raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareSpica

Spica can use JSON over WebSockets for C2 communications.

T1095
Non-Application Layer Protocol
MalwareBandook

Bandook has a command built in to use a raw TCP socket.

T1095
Non-Application Layer Protocol
MalwarePipeMon

The PipeMon communication module can use a custom protocol based on TLS over TCP.

T1095
Non-Application Layer Protocol
MalwareWinnti for Linux

Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications.

T1095
Non-Application Layer Protocol
Malwaregh0st RAT

gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2.

T1095
Non-Application Layer Protocol
MalwareRARSTONE

RARSTONE uses SSL to encrypt its communication with its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.