Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1104 Multi-Stage Channels |
MalwareJumbledPath | JumbledPath can communicate over a unique series of connections to send and retrieve data from exploited devices. |
| T1104 Multi-Stage Channels |
MalwareSnip3 | Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1104 Multi-Stage Channels |
MalwareChaos | After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system. |
| T1104 Multi-Stage Channels |
MalwareLatrodectus | Latrodectus has used a two-tiered C2 configuration with tier one nodes connecting to the victim and tier two nodes connecting to backend infrastructure. |
| T1104 Multi-Stage Channels |
MalwareUroburos | Individual Uroburos implants can use multiple communication channels based on one of four available modes of operation. |
| T1104 Multi-Stage Channels |
MalwareBazar | The Bazar loader is used to download and execute the Bazar backdoor. |
| T1104 Multi-Stage Channels |
MalwareValak | Valak can download additional modules and malware capable of using separate C2 channels. |
| T1104 Multi-Stage Channels |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines. |
| T1104 Multi-Stage Channels |
MalwareLunarWeb | LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands. |
| T1104 Multi-Stage Channels |
MalwareBACKSPACE | BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.