ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
MalwareSaint Bot

Saint Bot has been distributed through malicious links contained within spearphishing emails.

T1566.002
Spearphishing Link
MalwareKerrdown

Kerrdown has been distributed via e-mails containing a malicious link.

T1566.002
Spearphishing Link
MalwareGrandoreiro

Grandoreiro has been spread via malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareBazar

Bazar has been spread via emails with embedded malicious links.

T1566.002
Spearphishing Link
MalwareValak

Valak has been delivered via malicious links in e-mail.

T1566.002
Spearphishing Link
MalwareOutSteel

OutSteel has been distributed through malicious links contained within spearphishing emails.

T1566.002
Spearphishing Link
MalwareMelcoz

Melcoz has been spread through malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareKOCTOPUS

KOCTOPUS has been distributed as a malicious link within an email.

T1566.002
Spearphishing Link
MalwareQilin

Qilin has been delivered via malicious links in spearphishing emails.

T1566.002
Spearphishing Link
MalwareAppleJeus

AppleJeus has been distributed via spearphishing link.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1566.002
Spearphishing Link
MalwareHancitor

Hancitor has been delivered via phishing emails which contained malicious links.

T1566.002
Spearphishing Link
ToolAADInternals

AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens.

T1566.002
Spearphishing Link
MalwareKali365

Kali365 has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign.

T1566.003
Spearphishing via Service
MalwareNinja

Ninja has been distributed to victims via the messaging app Telegram.

T1567
Exfiltration Over Web Service
MalwareInvisibleFerret

InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token.

T1567
Exfiltration Over Web Service
MalwareAppleSeed

AppleSeed has exfiltrated files using web services.

T1567
Exfiltration Over Web Service
MalwareDropBook

DropBook has used legitimate web services to exfiltrate data.

T1567
Exfiltration Over Web Service
MalwareExbyte

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

T1567
Exfiltration Over Web Service
MalwareOilCheck

OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration.

T1567
Exfiltration Over Web Service
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

T1567
Exfiltration Over Web Service
Toolngrok

ngrok has been used by threat actors to configure servers for data exfiltration.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1567.001
Exfiltration to Code Repository
ToolEmpire

Empire can use GitHub for data exfiltration.

T1567.001
Exfiltration to Code Repository
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.

T1567.001
Exfiltration to Code Repository
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.

T1567.002
Exfiltration to Cloud Storage
MalwareTsundere Botnet

Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server.

T1567.002
Exfiltration to Cloud Storage
MalwareRainyDay

RainyDay can use a file exfiltration tool to upload specific files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareHAMMERTOSS

HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.

T1567.002
Exfiltration to Cloud Storage
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account for exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

T1567.002
Exfiltration to Cloud Storage
MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareCreepyDrive

CreepyDrive can use cloud services including OneDrive for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareBoxCaon

BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive.

T1567.002
Exfiltration to Cloud Storage
MalwareCrutch

Crutch has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareOilBooster

OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API.

T1567.002
Exfiltration to Cloud Storage
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareRIFLESPINE

RIFLESPINE can upload results from executed C2 commands to cloud storage.

T1567.002
Exfiltration to Cloud Storage
MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

T1567.002
Exfiltration to Cloud Storage
MalwarePcexter

Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`.

T1567.002
Exfiltration to Cloud Storage
ToolEmpire

Empire can use Dropbox for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
ToolRclone

Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.

T1567.004
Exfiltration Over Webhook
MalwareShai-Hulud

Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`.

T1568
Dynamic Resolution
MalwareBRICKSTORM

BRICKSTORM has utilized DNS services sslip.io and nip.io to resolve C2 IP addresses.

T1568
Dynamic Resolution
MalwareTomiris

Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2.

T1568
Dynamic Resolution
MalwareNETEAGLE

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

T1568
Dynamic Resolution
MalwareBisonal

Bisonal has used a dynamic DNS service for C2.

T1568
Dynamic Resolution
MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

T1568
Dynamic Resolution
MalwareSUNBURST

SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain.

T1568
Dynamic Resolution
MalwareMaze

Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.