Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102 Web Service |
MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| T1102 Web Service |
MalwareBRICKSTORM | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications. |
| T1102 Web Service |
MalwareSharpStage | SharpStage has used a legitimate web service for evading detection. |
| T1102 Web Service |
MalwareNETWIRE | NETWIRE has used web services including Paste.ee to host payloads. |
| T1102 Web Service |
MalwareBADHATCH | BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels. |
| T1102 Web Service |
MalwareDropBook | DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions. |
| T1102 Web Service |
MalwareShrinkLocker | ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1102 Web Service |
MalwareHildegard | Hildegard has downloaded scripts from GitHub. |
| T1102 Web Service |
MalwareSnip3 | Snip3 can download additional payloads from web services including Pastebin and top4top. |
| T1102 Web Service |
MalwareGuLoader | GuLoader has the ability to download malware from Google Drive. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1102 Web Service |
MalwareRaspberry Robin | Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers. |
| T1102 Web Service |
MalwareDoki | Doki has used the dogechain.info API to generate a C2 address. |
| T1102 Web Service |
MalwareNightdoor | Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1102 Web Service |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell. |
| T1102 Web Service |
MalwareSocGholish | SocGholish has used Amazon Web Services to host second-stage servers. |
| T1102 Web Service |
MalwareDarkTortilla | DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin. |
| T1102 Web Service |
MalwarePureCrypter | PureCrypter can use Telegram or Discord to send infection status messages. |
| T1102 Web Service |
MalwareLatrodectus | Latrodectus has used Google Firebase to download malicious installation scripts. |
| T1102 Web Service |
MalwareCharmPower | CharmPower can download additional modules from actor-controlled Amazon S3 buckets. |
| T1102 Web Service |
MalwareSMOKEDHAM | SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1102 Web Service |
MalwareRedLine Stealer | RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads. |
| T1102 Web Service |
MalwareSibot | Sibot has used a legitimate compromised website to download DLLs to the victim's machine. |
| T1102 Web Service |
MalwareBazar | Bazar downloads have been hosted on Google Docs. |
| T1102 Web Service |
MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| T1102 Web Service |
MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| T1102 Web Service |
MalwareMOPSLED | MOPSLED can use third-party web services such as GitHub and Google Drive for C2. |
| T1102 Web Service |
MalwareBoomBox | BoomBox can download files from Dropbox using a hardcoded access token. |
| T1102 Web Service |
Toolngrok | ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains. |
| T1102 Web Service |
ToolBrute Ratel C4 | Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams. |
| T1102 Web Service |
MalwareKali365 | Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.