ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1102.002×

38 examples

TechniqueUsed byProcedure example
T1102.002
Bidirectional Communication
MalwareOrz

Orz has used Technet and Pastebin web pages for command and control.

T1102.002
Bidirectional Communication
Malwareyty

yty communicates to the C2 server by retrieving a Google Doc.

T1102.002
Bidirectional Communication
MalwareDOGCALL

DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2.

T1102.002
Bidirectional Communication
MalwareLOWBALL

LOWBALL uses the Dropbox cloud storage service for command and control.

T1102.002
Bidirectional Communication
MalwareKARAE

KARAE can use public cloud-based storage providers for command and control.

T1102.002
Bidirectional Communication
MalwareSLOWDRIFT

SLOWDRIFT uses cloud based services for C2.

T1102.002
Bidirectional Communication
MalwareODAgent

ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands.

T1102.002
Bidirectional Communication
MalwareRegDuke

RegDuke can use Dropbox as its C2 server.

T1102.002
Bidirectional Communication
MalwareTRANSLATEXT

TRANSLATEXT has used a Github repository for C2.

T1102.002
Bidirectional Communication
MalwareUBoatRAT

UBoatRAT has used GitHub and a public blog service in Hong Kong for C2 communications.

T1102.002
Bidirectional Communication
MalwareKazuar

Kazuar has used compromised WordPress blogs as C2 servers.

T1102.002
Bidirectional Communication
MalwarePOORAIM

POORAIM has used AOL Instant Messenger for C2.

T1102.002
Bidirectional Communication
MalwareCALENDAR

The CALENDAR malware communicates through the use of events in Google Calendar.

T1102.002
Bidirectional Communication
MalwareROKRAT

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

T1102.002
Bidirectional Communication
MalwareClambling

Clambling can use Dropbox to download malicious payloads, send commands, and receive information.

T1102.002
Bidirectional Communication
MalwareCreepyDrive

CreepyDrive can use OneDrive for C2.

T1102.002
Bidirectional Communication
MalwareSagerunex

Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants.

T1102.002
Bidirectional Communication
MalwareBLUELIGHT

BLUELIGHT can use different cloud providers for its C2.

T1102.002
Bidirectional Communication
MalwareRogueRobin

RogueRobin has used Google Drive as a Command and Control channel.

T1102.002
Bidirectional Communication
MalwareBoxCaon

BoxCaon has used DropBox for C2 communications.

T1102.002
Bidirectional Communication
MalwareCrutch

Crutch can use Dropbox to receive commands and upload stolen data.

T1102.002
Bidirectional Communication
MalwareGrandoreiro

Grandoreiro can utilize web services including Google sites to send and receive C2 data.

T1102.002
Bidirectional Communication
MalwareOilCheck

OilCheck can use a REST-based Microsoft Graph API to access draft messages in a shared Microsoft Office 365 Outlook email account used for C2 communication.

T1102.002
Bidirectional Communication
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.

T1102.002
Bidirectional Communication
MalwareOilBooster

OilBooster uses the Microsoft Graph API to connect to an actor-controlled OneDrive account to download and execute files and shell commands, and to create directories to share exfiltrated data.

T1102.002
Bidirectional Communication
MalwareRevenge RAT

Revenge RAT used blogpost.com as its primary command and control server during a campaign.

T1102.002
Bidirectional Communication
MalwareLAMEHUG

LAMEHUG has used the Hugging Face API to query the Qwen2.5-Coder-32B-Instruct LLM to generate one-line Windows commands for the collection of system information and documents in specific folders on compromised hosts. LAMEHUG subsequently executed the returned commands and exfiltrated the collected files and information to adversary-controlled C2 servers.

T1102.002
Bidirectional Communication
MalwareCloudDuke

One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.

T1102.002
Bidirectional Communication
MalwareRIFLESPINE

RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.

T1102.002
Bidirectional Communication
MalwareBLACKCOFFEE

BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github.

T1102.002
Bidirectional Communication
MalwareComRAT

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1102.002
Bidirectional Communication
MalwarePowerStallion

PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with net use.

T1102.002
Bidirectional Communication
MalwareCozyCar

CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file.

T1102.002
Bidirectional Communication
MalwareBADNEWS

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.

T1102.002
Bidirectional Communication
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.

T1102.002
Bidirectional Communication
MalwareComnie

Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server.

T1102.002
Bidirectional Communication
MalwareSmall Sieve

Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages.

T1102.002
Bidirectional Communication
ToolEmpire

Empire can use Dropbox and GitHub for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.