ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1570×

27 examples

TechniqueUsed byProcedure example
T1570
Lateral Tool Transfer
MalwareStuxnet

Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network.

T1570
Lateral Tool Transfer
MalwareHavoc

Havoc has the ability to copy files from one location to another.

T1570
Lateral Tool Transfer
MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

T1570
Lateral Tool Transfer
MalwareOlympic Destroyer

Olympic Destroyer attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareSameCoin

SameCoin can copy its wiper executable to remote machines within the same Active Directory.

T1570
Lateral Tool Transfer
MalwareBlackCat

BlackCat can replicate itself across connected servers via `psexec`.

T1570
Lateral Tool Transfer
MalwareLucifer

Lucifer can use certutil for propagation on Windows hosts within intranets.

T1570
Lateral Tool Transfer
MalwareLockerGoga

LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.

T1570
Lateral Tool Transfer
MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

T1570
Lateral Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.

T1570
Lateral Tool Transfer
MalwareWannaCry

WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.

T1570
Lateral Tool Transfer
MalwareVIRTUALPIE

VIRTUALPIE has file transfer capabilities.

T1570
Lateral Tool Transfer
MalwareShamoon

Shamoon attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareBlackByte Ransomware

BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders.

T1570
Lateral Tool Transfer
MalwareIPsec Helper

IPsec Helper can download additional payloads from command and control nodes and execute them.

T1570
Lateral Tool Transfer
MalwareOutSteel

OutSteel can download the Saint Bot malware for follow-on execution.

T1570
Lateral Tool Transfer
MalwareVIRTUALPITA

VIRTUALPITA is capable of file transfer and arbitrary command execution.

T1570
Lateral Tool Transfer
MalwareQilin

Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment.

T1570
Lateral Tool Transfer
MalwareINC Ransomware

INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
MalwareHermeticWizard

HermeticWizard can copy files to other machines on a compromised network.

T1570
Lateral Tool Transfer
ToolImpacket

Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks.

T1570
Lateral Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers.

T1570
Lateral Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected internal system.

T1570
Lateral Tool Transfer
Toolesentutl

esentutl can be used to copy files to/from a remote share.

T1570
Lateral Tool Transfer
ToolExpand

Expand can be used to download or upload a file over a network share.

T1570
Lateral Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment.

T1570
Lateral Tool Transfer
ToolPsExec

PsExec can be used to download or upload a file over a network share.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.