ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1102×

31 examples

TechniqueUsed byProcedure example
T1102
Web Service
MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

T1102
Web Service
MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

T1102
Web Service
MalwareSharpStage

SharpStage has used a legitimate web service for evading detection.

T1102
Web Service
MalwareNETWIRE

NETWIRE has used web services including Paste.ee to host payloads.

T1102
Web Service
MalwareBADHATCH

BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels.

T1102
Web Service
MalwareDropBook

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1102
Web Service
MalwareShrinkLocker

ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems.

T1102
Web Service
MalwareHildegard

Hildegard has downloaded scripts from GitHub.

T1102
Web Service
MalwareSnip3

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1102
Web Service
MalwareGuLoader

GuLoader has the ability to download malware from Google Drive.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1102
Web Service
MalwareRaspberry Robin

Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers.

T1102
Web Service
MalwareDoki

Doki has used the dogechain.info API to generate a C2 address.

T1102
Web Service
MalwareNightdoor

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1102
Web Service
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell.

T1102
Web Service
MalwareSocGholish

SocGholish has used Amazon Web Services to host second-stage servers.

T1102
Web Service
MalwareDarkTortilla

DarkTortilla can retrieve its primary payload from public sites such as Pastebin and Textbin.

T1102
Web Service
MalwarePureCrypter

PureCrypter can use Telegram or Discord to send infection status messages.

T1102
Web Service
MalwareLatrodectus

Latrodectus has used Google Firebase to download malicious installation scripts.

T1102
Web Service
MalwareCharmPower

CharmPower can download additional modules from actor-controlled Amazon S3 buckets.

T1102
Web Service
MalwareSMOKEDHAM

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1102
Web Service
MalwareRedLine Stealer

RedLine Stealer has leveraged legitimate file sharing web services to host malicious payloads.

T1102
Web Service
MalwareSibot

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1102
Web Service
MalwareBazar

Bazar downloads have been hosted on Google Docs.

T1102
Web Service
MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

T1102
Web Service
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

T1102
Web Service
MalwareMOPSLED

MOPSLED can use third-party web services such as GitHub and Google Drive for C2.

T1102
Web Service
MalwareBoomBox

BoomBox can download files from Dropbox using a hardcoded access token.

T1102
Web Service
Toolngrok

ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains.

T1102
Web Service
ToolBrute Ratel C4

Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams.

T1102
Web Service
MalwareKali365

Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.