ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1104×

10 examples

TechniqueUsed byProcedure example
T1104
Multi-Stage Channels
MalwareJumbledPath

JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1104
Multi-Stage Channels
MalwareChaos

After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system.

T1104
Multi-Stage Channels
MalwareLatrodectus

Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure.

T1104
Multi-Stage Channels
MalwareUroburos

Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation.

T1104
Multi-Stage Channels
MalwareBazar

The Bazar loader is used to download and execute the Bazar backdoor.

T1104
Multi-Stage Channels
MalwareValak

Valak can download additional modules and malware capable of using separate C2 channels.

T1104
Multi-Stage Channels
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines.

T1104
Multi-Stage Channels
MalwareLunarWeb

LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands.

T1104
Multi-Stage Channels
MalwareBACKSPACE

BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.