ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1102.001×

19 examples

TechniqueUsed byProcedure example
T1102.001
Dead Drop Resolver
MalwareTsundere Botnet

Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes.

T1102.001
Dead Drop Resolver
MalwarePolyglotDuke

PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL.

T1102.001
Dead Drop Resolver
MalwareTRANSLATEXT

TRANSLATEXT has used a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.001
Dead Drop Resolver
MalwareMiniDuke

Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds.

T1102.001
Dead Drop Resolver
MalwareJavali

Javali can read C2 information from Google Documents and YouTube.

T1102.001
Dead Drop Resolver
MalwarePlugX

PlugX uses Pastebin to store C2 addresses.

T1102.001
Dead Drop Resolver
MalwareXbash

Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list.

T1102.001
Dead Drop Resolver
MalwareKEYPLUG

The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums.

T1102.001
Dead Drop Resolver
MalwareCharmPower

CharmPower can retrieve C2 domain information from actor-controlled S3 buckets.

T1102.001
Dead Drop Resolver
MalwareGlassWorm

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1102.001
Dead Drop Resolver
MalwareMetamorfo

Metamorfo has used YouTube to store and hide C&C server domains.

T1102.001
Dead Drop Resolver
MalwareRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain.

T1102.001
Dead Drop Resolver
MalwareGrandoreiro

Grandoreiro can obtain C2 information from Google Docs.

T1102.001
Dead Drop Resolver
MalwareMOPSLED

MOPSLED has the ability to retrieve a C2 address from a dead drop URL.

T1102.001
Dead Drop Resolver
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server.

T1102.001
Dead Drop Resolver
MalwareBADNEWS

BADNEWS collects C2 information via a dead drop resolver.

T1102.001
Dead Drop Resolver
MalwareAstaroth

Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook.

T1102.001
Dead Drop Resolver
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories.

T1102.001
Dead Drop Resolver
MalwareCanisterWorm

CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.