Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1570 Lateral Tool Transfer |
MalwareStuxnet | Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network. |
| T1570 Lateral Tool Transfer |
MalwareHavoc | Havoc has the ability to copy files from one location to another. |
| T1570 Lateral Tool Transfer |
MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| T1570 Lateral Tool Transfer |
MalwareOlympic Destroyer | Olympic Destroyer attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareSameCoin | SameCoin can copy its wiper executable to remote machines within the same Active Directory. |
| T1570 Lateral Tool Transfer |
MalwareBlackCat | BlackCat can replicate itself across connected servers via `psexec`. |
| T1570 Lateral Tool Transfer |
MalwareLucifer | Lucifer can use certutil for propagation on Windows hosts within intranets. |
| T1570 Lateral Tool Transfer |
MalwareLockerGoga | LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating. |
| T1570 Lateral Tool Transfer |
MalwareDustySky | DustySky searches for network drives and removable media and duplicates itself onto them. |
| T1570 Lateral Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems. |
| T1570 Lateral Tool Transfer |
MalwareWannaCry | WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPIE | VIRTUALPIE has file transfer capabilities. |
| T1570 Lateral Tool Transfer |
MalwareShamoon | Shamoon attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareBlackByte Ransomware | BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders. |
| T1570 Lateral Tool Transfer |
MalwareIPsec Helper | IPsec Helper can download additional payloads from command and control nodes and execute them. |
| T1570 Lateral Tool Transfer |
MalwareOutSteel | OutSteel can download the Saint Bot malware for follow-on execution. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPITA | VIRTUALPITA is capable of file transfer and arbitrary command execution. |
| T1570 Lateral Tool Transfer |
MalwareQilin | Qilin has used PsExec to distribute a second encryptor, named encryptor_1.exe, across the targeted environment. |
| T1570 Lateral Tool Transfer |
MalwareINC Ransomware | INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
MalwareHermeticWizard | HermeticWizard can copy files to other machines on a compromised network. |
| T1570 Lateral Tool Transfer |
ToolImpacket | Impacket has used its `wmiexec` command, leveraging Windows Management Instrumentation, to remotely stage and execute payloads in victim networks. |
| T1570 Lateral Tool Transfer |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers. |
| T1570 Lateral Tool Transfer |
Toolcmd | cmd can be used to copy files to/from a remotely connected internal system. |
| T1570 Lateral Tool Transfer |
Toolesentutl | esentutl can be used to copy files to/from a remote share. |
| T1570 Lateral Tool Transfer |
ToolExpand | Expand can be used to download or upload a file over a network share. |
| T1570 Lateral Tool Transfer |
Toolftp | ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment. |
| T1570 Lateral Tool Transfer |
ToolPsExec | PsExec can be used to download or upload a file over a network share. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.