Real-world descriptions of how a group, tool or campaign used a technique.
403 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
MalwareTrickBot | TrickBot downloads several additional files and saves them to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarePowerDuke | PowerDuke has a command to download a file. |
| T1105 Ingress Tool Transfer |
MalwareBLINDINGCAN | BLINDINGCAN has downloaded files to a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can download files. |
| T1105 Ingress Tool Transfer |
MalwareRCSession | RCSession has the ability to drop additional files to an infected machine. |
| T1105 Ingress Tool Transfer |
MalwareQuietSieve | QuietSieve can download and execute payloads on a target host. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1105 Ingress Tool Transfer |
MalwareBRICKSTORM | BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareAmadey | Amadey can download and execute files to further infect a host machine with additional malware. |
| T1105 Ingress Tool Transfer |
MalwareNICECURL | NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`. |
| T1105 Ingress Tool Transfer |
MalwareOrz | Orz can download files onto the victim. |
| T1105 Ingress Tool Transfer |
MalwareNOKKI | NOKKI has downloaded a remote module for execution. |
| T1105 Ingress Tool Transfer |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can download additional modules from C2. |
| T1105 Ingress Tool Transfer |
MalwareDOGCALL | DOGCALL can download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDowndelph | After downloading its main config file, Downdelph downloads multiple payloads from C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareSEASHARPEE | SEASHARPEE can download remote files onto victims. |
| T1105 Ingress Tool Transfer |
MalwarePOWRUNER | POWRUNER can download or upload files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareTDTESS | TDTESS has a command to download and execute an additional file. |
| T1105 Ingress Tool Transfer |
MalwareSharpStage | SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1105 Ingress Tool Transfer |
MalwareSardonic | Sardonic has the ability to upload additional malicious files to a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareSmoke Loader | Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins. |
| T1105 Ingress Tool Transfer |
MalwareMisdat | Misdat is capable of downloading files from the C2. |
| T1105 Ingress Tool Transfer |
MalwarereGeorg | reGeorg has the ability to download files to targeted systems. |
| T1105 Ingress Tool Transfer |
MalwareEmissary | Emissary has the capability to download files from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareExaramel for Linux | Exaramel for Linux has a command to download a file from and to a remote C2 server. |
| T1105 Ingress Tool Transfer |
MalwareKEYMARBLE | KEYMARBLE can upload files to the victim’s machine and can download additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareTAMECAT | TAMECAT has used `wget` and `curl` to download additional content. |
| T1105 Ingress Tool Transfer |
MalwarePS1 | CostaBricks can download additional payloads onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareUrsnif | Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareCASTLETAP | CASTLETAP can transfer files to compromised network devices. |
| T1105 Ingress Tool Transfer |
MalwareThreatNeedle | ThreatNeedle can download additional tools to enable lateral movement. |
| T1105 Ingress Tool Transfer |
MalwareZLib | ZLib has the ability to download files. |
| T1105 Ingress Tool Transfer |
MalwareRedLeaves | RedLeaves is capable of downloading a file from a specified URL. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSOURCE | POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims. |
| T1105 Ingress Tool Transfer |
MalwareTsundere Botnet | Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool. |
| T1105 Ingress Tool Transfer |
MalwareFelismus | Felismus can download files from remote servers. |
| T1105 Ingress Tool Transfer |
MalwareZeus Panda | Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareHavoc | Havoc has the ability to upload files to infected systems. |
| T1105 Ingress Tool Transfer |
MalwareCARROTBAT | CARROTBAT has the ability to download and execute a remote file via certutil. |
| T1105 Ingress Tool Transfer |
MalwareWEBC2 | WEBC2 can download and execute a file. |
| T1105 Ingress Tool Transfer |
MalwareInvisibleFerret | InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI. |
| T1105 Ingress Tool Transfer |
MalwareBankshot | Bankshot uploads files and secondary payloads to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareSharpDisco | SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources. |
| T1105 Ingress Tool Transfer |
MalwareStrongPity | StrongPity can download files to specified targets. |
| T1105 Ingress Tool Transfer |
MalwareHAPPYWORK | can download and execute a second-stage payload. |
| T1105 Ingress Tool Transfer |
MalwarexCaon | xCaon has a command to download files to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwarePLAINTEE | PLAINTEE has downloaded and executed additional plugins. |
| T1105 Ingress Tool Transfer |
MalwarePony | Pony can download additional files onto the infected system. |
| T1105 Ingress Tool Transfer |
MalwareNebulae | Nebulae can download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareAuditCred | AuditCred can download files and additional malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.