Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.008 Clear Mailbox Data |
MalwareLunarMail | LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration. |
| T1070.008 Clear Mailbox Data |
MalwareGoopy | Goopy has the ability to delete emails used for C2 once the content has been copied. |
| T1070.009 Clear Persistence |
MalwareMisdat | Misdat is capable of deleting Registry keys used for persistence. |
| T1070.009 Clear Persistence |
MalwareRaspberry Robin | Raspberry Robin uses a |
| T1070.009 Clear Persistence |
MalwareSplatDropper | SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices. |
| T1070.009 Clear Persistence |
MalwarePlugX | PlugX has deleted registry keys that store data and maintained persistence. |
| T1070.009 Clear Persistence |
MalwareS-Type | S-Type has deleted accounts it has created. |
| T1070.009 Clear Persistence |
MalwareRTM | RTM has the ability to remove Registry entries that it created for persistence. |
| T1070.009 Clear Persistence |
MalwareBazar | Bazar's loader can delete scheduled tasks created by a previous instance of the malware. |
| T1070.009 Clear Persistence |
MalwareKapeka | Kapeka will clear registry values used for persistent configuration storage when uninstalled. |
| T1070.009 Clear Persistence |
MalwareSUNBURST | SUNBURST removed IFEO registry values to clean up traces of persistence. |
| T1070.009 Clear Persistence |
MalwareIPsec Helper | IPsec Helper can delete various service traces related to persistent execution when commanded. |
| T1070.009 Clear Persistence |
MalwarePillowmint | Pillowmint can uninstall the malicious service from an infected machine. |
| T1070.009 Clear Persistence |
MalwareGrimAgent | GrimAgent can delete previously created tasks on a compromised host. |
| T1070.009 Clear Persistence |
MalwarenjRAT | njRAT is capable of manipulating and deleting registry keys, including those used for persistence. |
| T1070.009 Clear Persistence |
MalwareKOCTOPUS | KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
| T1070.009 Clear Persistence |
ToolMCMD | MCMD has the ability to remove set Registry Keys, including those used for persistence. |
| T1070.010 Relocate Malware |
MalwareBRICKSTORM | BRICKSTORM has copied itself to the `usr/sbin/` folder. |
| T1071 Application Layer Protocol |
MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| T1071 Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can use an inverse negotiated SSH connection as part of its C2. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071 Application Layer Protocol |
MalwareSiloscape | Siloscape connects to an IRC server for C2. |
| T1071 Application Layer Protocol |
MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1071 Application Layer Protocol |
MalwareNETEAGLE | Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519. |
| T1071 Application Layer Protocol |
MalwareLucifer | Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server. |
| T1071 Application Layer Protocol |
MalwareClambling | Clambling has the ability to use Telnet for communication. |
| T1071 Application Layer Protocol |
ToolSliver | Sliver can utilize the Wireguard VPN protocol for command and control. |
| T1071 Application Layer Protocol |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| T1071.001 Web Protocols |
MalwareTrickBot | TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files. |
| T1071.001 Web Protocols |
MalwareBLINDINGCAN | BLINDINGCAN has used HTTPS over port 443 for command and control. |
| T1071.001 Web Protocols |
MalwareNinja | Ninja can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareSpark | Spark has used HTTP POST requests to communicate with its C2 server to receive commands. |
| T1071.001 Web Protocols |
MalwareQuietSieve | QuietSieve can use HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareBRICKSTORM | BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls. |
| T1071.001 Web Protocols |
MalwareAmadey | Amadey has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareProxysvc | Proxysvc uses HTTP over SSL to communicate commands with the control server. |
| T1071.001 Web Protocols |
MalwareTorisma | Torisma can use HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareNOKKI | NOKKI has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareStuxnet | Stuxnet uses HTTP to communicate with a command and control server. |
| T1071.001 Web Protocols |
MalwareIronWind | IronWind can used HTTP to send information to C2 about the targeted system. |
| T1071.001 Web Protocols |
MalwareGet2 | Get2 has the ability to use HTTP to send information collected from an infected host to C2. |
| T1071.001 Web Protocols |
MalwarePOWRUNER | POWRUNER can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareKOPILUWAK | KOPILUWAK has used HTTP POST requests to send data to C2. |
| T1071.001 Web Protocols |
MalwareCOATHANGER | COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control. |
| T1071.001 Web Protocols |
MalwareSmoke Loader | Smoke Loader uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareWindTail | WindTail has the ability to use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwarereGeorg | reGeorg can use HTTP to tunnel connections in and out of targeted networks. |
| T1071.001 Web Protocols |
MalwareEmissary | Emissary uses HTTP or HTTPS for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.