ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1070.008
Clear Mailbox Data
MalwareLunarMail

LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration.

T1070.008
Clear Mailbox Data
MalwareGoopy

Goopy has the ability to delete emails used for C2 once the content has been copied.

T1070.009
Clear Persistence
MalwareMisdat

Misdat is capable of deleting Registry keys used for persistence.

T1070.009
Clear Persistence
MalwareRaspberry Robin

Raspberry Robin uses a RunOnce Registry key for persistence, where the key is removed after its use on reboot then re-added by the malware after it resumes execution.

T1070.009
Clear Persistence
MalwareSplatDropper

SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices.

T1070.009
Clear Persistence
MalwarePlugX

PlugX has deleted registry keys that store data and maintained persistence.

T1070.009
Clear Persistence
MalwareS-Type

S-Type has deleted accounts it has created.

T1070.009
Clear Persistence
MalwareRTM

RTM has the ability to remove Registry entries that it created for persistence.

T1070.009
Clear Persistence
MalwareBazar

Bazar's loader can delete scheduled tasks created by a previous instance of the malware.

T1070.009
Clear Persistence
MalwareKapeka

Kapeka will clear registry values used for persistent configuration storage when uninstalled.

T1070.009
Clear Persistence
MalwareSUNBURST

SUNBURST removed IFEO registry values to clean up traces of persistence.

T1070.009
Clear Persistence
MalwareIPsec Helper

IPsec Helper can delete various service traces related to persistent execution when commanded.

T1070.009
Clear Persistence
MalwarePillowmint

Pillowmint can uninstall the malicious service from an infected machine.

T1070.009
Clear Persistence
MalwareGrimAgent

GrimAgent can delete previously created tasks on a compromised host.

T1070.009
Clear Persistence
MalwarenjRAT

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

T1070.009
Clear Persistence
MalwareKOCTOPUS

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

T1070.009
Clear Persistence
ToolMCMD

MCMD has the ability to remove set Registry Keys, including those used for persistence.

T1070.010
Relocate Malware
MalwareBRICKSTORM

BRICKSTORM has copied itself to the `usr/sbin/` folder.

T1071
Application Layer Protocol
MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

T1071
Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

T1071
Application Layer Protocol
MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1071
Application Layer Protocol
MalwareSiloscape

Siloscape connects to an IRC server for C2.

T1071
Application Layer Protocol
MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

T1071
Application Layer Protocol
MalwareNETEAGLE

Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519.

T1071
Application Layer Protocol
MalwareLucifer

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

T1071
Application Layer Protocol
MalwareClambling

Clambling has the ability to use Telnet for communication.

T1071
Application Layer Protocol
ToolSliver

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071
Application Layer Protocol
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

T1071.001
Web Protocols
MalwareTrickBot

TrickBot uses HTTPS to communicate with its C2 servers, to get malware updates, modules that perform most of the malware logic and various configuration files.

T1071.001
Web Protocols
MalwareBLINDINGCAN

BLINDINGCAN has used HTTPS over port 443 for command and control.

T1071.001
Web Protocols
MalwareNinja

Ninja can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareSpark

Spark has used HTTP POST requests to communicate with its C2 server to receive commands.

T1071.001
Web Protocols
MalwareQuietSieve

QuietSieve can use HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareBRICKSTORM

BRICKSTORM has communicated to hardcoded C2 through WebSockets (WSS) to include domains associated with Cloudflare Workers. BRICKSTORM has also leveraged Gorilla mux library to serve its HTTP API calls.

T1071.001
Web Protocols
MalwareAmadey

Amadey has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareProxysvc

Proxysvc uses HTTP over SSL to communicate commands with the control server.

T1071.001
Web Protocols
MalwareTorisma

Torisma can use HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareNOKKI

NOKKI has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareStuxnet

Stuxnet uses HTTP to communicate with a command and control server.

T1071.001
Web Protocols
MalwareIronWind

IronWind can used HTTP to send information to C2 about the targeted system.

T1071.001
Web Protocols
MalwareGet2

Get2 has the ability to use HTTP to send information collected from an infected host to C2.

T1071.001
Web Protocols
MalwarePOWRUNER

POWRUNER can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareKOPILUWAK

KOPILUWAK has used HTTP POST requests to send data to C2.

T1071.001
Web Protocols
MalwareCOATHANGER

COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control.

T1071.001
Web Protocols
MalwareSmoke Loader

Smoke Loader uses HTTP for C2.

T1071.001
Web Protocols
MalwareWindTail

WindTail has the ability to use HTTP for C2 communications.

T1071.001
Web Protocols
MalwarereGeorg

reGeorg can use HTTP to tunnel connections in and out of targeted networks.

T1071.001
Web Protocols
MalwareEmissary

Emissary uses HTTP or HTTPS for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.