ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1572×

21 examples

TechniqueUsed byProcedure example
T1572
Protocol Tunneling
MalwareBRICKSTORM

BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket.

T1572
Protocol Tunneling
MalwarereGeorg

reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP.

T1572
Protocol Tunneling
MalwareFLIPSIDE

FLIPSIDE uses RDP to tunnel traffic from a victim environment.

T1572
Protocol Tunneling
MalwareUroburos

Uroburos has the ability to communicate over custom communications methodologies that ride over common network protocols including raw TCP and UDP sockets, HTTP, SMTP, and DNS.

T1572
Protocol Tunneling
MalwareHiddenFace

HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2.

T1572
Protocol Tunneling
MalwareCobalt Strike

Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1572
Protocol Tunneling
MalwareMilan

Milan can use a custom protocol tunneled through DNS or HTTP.

T1572
Protocol Tunneling
MalwareCyclops Blink

Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes.

T1572
Protocol Tunneling
MalwareNeo-reGeorg

Neo-reGeorg can tunnel data in and out of targeted networks.

T1572
Protocol Tunneling
MalwareFunnyDream

FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2.

T1572
Protocol Tunneling
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications.

T1572
Protocol Tunneling
MalwareHeyoka Backdoor

Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers.

T1572
Protocol Tunneling
MalwareLunarWeb

LunarWeb can run a custom binary protocol under HTTPS for C2.

T1572
Protocol Tunneling
MalwareIndustroyer

Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel.

T1572
Protocol Tunneling
MalwareKevin

Kevin can use a custom protocol tunneled through DNS or HTTP.

T1572
Protocol Tunneling
MalwareQakBot

The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol.

T1572
Protocol Tunneling
Toolngrok

ngrok can tunnel RDP and other services securely over internet connections.

T1572
Protocol Tunneling
ToolFRP

FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT.

T1572
Protocol Tunneling
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1572
Protocol Tunneling
ToolMythic

Mythic can use SOCKS proxies to tunnel traffic through another protocol.

T1572
Protocol Tunneling
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.