Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1102.001 Dead Drop Resolver |
MalwareTsundere Botnet | Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1102.001 Dead Drop Resolver |
MalwarePolyglotDuke | PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL. |
| T1102.001 Dead Drop Resolver |
MalwareTRANSLATEXT | TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.001 Dead Drop Resolver |
MalwareMiniDuke | Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1102.001 Dead Drop Resolver |
MalwareJavali | Javali can read C2 information from Google Documents and YouTube. |
| T1102.001 Dead Drop Resolver |
MalwarePlugX | PlugX uses Pastebin to store C2 addresses. |
| T1102.001 Dead Drop Resolver |
MalwareXbash | Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list. |
| T1102.001 Dead Drop Resolver |
MalwareKEYPLUG | The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums. |
| T1102.001 Dead Drop Resolver |
MalwareCharmPower | CharmPower can retrieve C2 domain information from actor-controlled S3 buckets. |
| T1102.001 Dead Drop Resolver |
MalwareGlassWorm | GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1102.001 Dead Drop Resolver |
MalwareMetamorfo | Metamorfo has used YouTube to store and hide C&C server domains. |
| T1102.001 Dead Drop Resolver |
MalwareRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
| T1102.001 Dead Drop Resolver |
MalwareGrandoreiro | Grandoreiro can obtain C2 information from Google Docs. |
| T1102.001 Dead Drop Resolver |
MalwareMOPSLED | MOPSLED has the ability to retrieve a C2 address from a dead drop URL. |
| T1102.001 Dead Drop Resolver |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server. |
| T1102.001 Dead Drop Resolver |
MalwareBADNEWS | BADNEWS collects C2 information via a dead drop resolver. |
| T1102.001 Dead Drop Resolver |
MalwareAstaroth | Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook. |
| T1102.001 Dead Drop Resolver |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.