Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org
Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Protocols such as SMB, FTP, FTPS, and TFTP that transfer files may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the transferred files. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
Rules on DetectionCode tagged with T1071.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Outbound SMB Traffic | TTP | NULL | Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | |
| GroupDragonfly | Dragonfly has used SMB for C2. |
| GroupKimsuky | Kimsuky has used FTP to download additional malware to the target machine. |
| GroupMirrorFace | MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer. |
| GroupSilverTerrier | SilverTerrier uses FTP for C2 communications. |
| Used by | Procedure example |
|---|---|
| MalwareAttor | Attor has used FTP protocol for C2 communication. |
| MalwareBADHATCH | BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers. |
| ToolCARROTBALL | CARROTBALL has the ability to use FTP in C2 communications. |
| MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| MalwareDisco | Disco can use SMB to transfer files. |
| MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| MalwareJPIN | JPIN can communicate over FTP. |
| MalwareKazuar | Kazuar uses FTP and FTPS to communicate with the C2 server. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors had the ability to use FTP for C2. |
| CampaignQuad7 Activity | Quad7 Activity has used a File Transfer Protocol (FTP) server to download malicious binaries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.