File Transfer Protocols

T1071.002

Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org

About this technique

Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as SMB, FTP, FTPS, and TFTP that transfer files may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the transferred files. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Detection rules1

Rules on DetectionCode tagged with T1071.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Detect Outbound SMB TrafficTTPNULLCisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall

Groups5

Software20

Campaigns2

Procedure examples27

Groups5

Used byProcedure example
GroupAPT41

APT41 used exploit payloads that initiate download via ftp.

GroupDragonfly

Dragonfly has used SMB for C2.

GroupKimsuky

Kimsuky has used FTP to download additional malware to the target machine.

GroupMirrorFace

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.

GroupSilverTerrier

SilverTerrier uses FTP for C2 communications.

Software20

Used byProcedure example
MalwareAttor

Attor has used FTP protocol for C2 communication.

MalwareBADHATCH

BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers.

ToolCARROTBALL

CARROTBALL has the ability to use FTP in C2 communications.

MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

MalwareDisco

Disco can use SMB to transfer files.

MalwareHavoc

Havoc can use an SMB listener for C2 communication.

MalwareJPIN

JPIN can communicate over FTP.

MalwareKazuar

Kazuar uses FTP and FTPS to communicate with the C2 server.

View all 20 software examples

Campaigns2

Used byProcedure example
CampaignOperation Honeybee

During Operation Honeybee, the threat actors had the ability to use FTP for C2.

CampaignQuad7 Activity

Quad7 Activity has used a File Transfer Protocol (FTP) server to download malicious binaries.

References2

  1. ESET Machete July 2019 Open source
    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.
  2. US-CERT TA18-074A Open source
    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.