Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
MalwareSaint Bot | Saint Bot has been distributed through malicious links contained within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareKerrdown | Kerrdown has been distributed via e-mails containing a malicious link. |
| T1566.002 Spearphishing Link |
MalwareGrandoreiro | Grandoreiro has been spread via malicious links embedded in e-mails. |
| T1566.002 Spearphishing Link |
MalwareBazar | Bazar has been spread via emails with embedded malicious links. |
| T1566.002 Spearphishing Link |
MalwareValak | Valak has been delivered via malicious links in e-mail. |
| T1566.002 Spearphishing Link |
MalwareOutSteel | OutSteel has been distributed through malicious links contained within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareMelcoz | Melcoz has been spread through malicious links embedded in e-mails. |
| T1566.002 Spearphishing Link |
MalwareKOCTOPUS | KOCTOPUS has been distributed as a malicious link within an email. |
| T1566.002 Spearphishing Link |
MalwareQilin | Qilin has been delivered via malicious links in spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareAppleJeus | AppleJeus has been distributed via spearphishing link. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1566.002 Spearphishing Link |
MalwareHancitor | Hancitor has been delivered via phishing emails which contained malicious links. |
| T1566.002 Spearphishing Link |
ToolAADInternals | AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens. |
| T1566.002 Spearphishing Link |
MalwareKali365 | Kali365 has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign. |
| T1566.003 Spearphishing via Service |
MalwareNinja | Ninja has been distributed to victims via the messaging app Telegram. |
| T1567 Exfiltration Over Web Service |
MalwareInvisibleFerret | InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token. |
| T1567 Exfiltration Over Web Service |
MalwareAppleSeed | AppleSeed has exfiltrated files using web services. |
| T1567 Exfiltration Over Web Service |
MalwareDropBook | DropBook has used legitimate web services to exfiltrate data. |
| T1567 Exfiltration Over Web Service |
MalwareExbyte | Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
| T1567 Exfiltration Over Web Service |
MalwareOilCheck | OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration. |
| T1567 Exfiltration Over Web Service |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| T1567 Exfiltration Over Web Service |
Toolngrok | ngrok has been used by threat actors to configure servers for data exfiltration. |
| T1567.001 Exfiltration to Code Repository |
MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| T1567.001 Exfiltration to Code Repository |
ToolEmpire | Empire can use GitHub for data exfiltration. |
| T1567.001 Exfiltration to Code Repository |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
| T1567.001 Exfiltration to Code Repository |
MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareTsundere Botnet | Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRainyDay | RainyDay can use a file exfiltration tool to upload specific files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareHAMMERTOSS | HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareROKRAT | ROKRAT can send collected data to cloud storage services such as PCloud. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCreepyDrive | CreepyDrive can use cloud services including OneDrive for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoxCaon | BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCrutch | Crutch has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOilBooster | OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoomBox | BoomBox can upload data to dedicated per-victim folders in Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRIFLESPINE | RIFLESPINE can upload results from executed C2 commands to cloud storage. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOctopus | Octopus has exfiltrated data to file sharing sites. |
| T1567.002 Exfiltration to Cloud Storage |
MalwarePcexter | Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`. |
| T1567.002 Exfiltration to Cloud Storage |
ToolEmpire | Empire can use Dropbox for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
ToolRclone | Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. |
| T1567.004 Exfiltration Over Webhook |
MalwareShai-Hulud | Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`. |
| T1568 Dynamic Resolution |
MalwareBRICKSTORM | BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses. |
| T1568 Dynamic Resolution |
MalwareTomiris | Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2. |
| T1568 Dynamic Resolution |
MalwareNETEAGLE | NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2. |
| T1568 Dynamic Resolution |
MalwareBisonal | Bisonal has used a dynamic DNS service for C2. |
| T1568 Dynamic Resolution |
MalwareRTM | RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain. |
| T1568 Dynamic Resolution |
MalwareSUNBURST | SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain. |
| T1568 Dynamic Resolution |
MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.