ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareRIPTIDE

APT12 has used RIPTIDE, a RAT that uses HTTP to communicate.

T1071.001
Web Protocols
MalwareValak

Valak has used HTTP in communications with C2.

T1071.001
Web Protocols
MalwareSamurai

Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests.

T1071.001
Web Protocols
MalwarePinchDuke

PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server.

T1071.001
Web Protocols
MalwareMilan

Milan can use HTTPS for communication with C2.

T1071.001
Web Protocols
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can also use use HTTP POST and GET requests to send and receive C2 information.

T1071.001
Web Protocols
MalwareOilBooster

OilBooster can send HTTP `GET`, `POST`, `PUT`, and `DELETE` requests to the Microsoft Graph API over port 443 for C2 communication.

T1071.001
Web Protocols
MalwareOnionDuke

OnionDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareTaidoor

Taidoor has used HTTP GET and POST requests for C2.

T1071.001
Web Protocols
MalwareSUPERNOVA

SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute.

T1071.001
Web Protocols
MalwareCyclops Blink

Cyclops Blink can download files via HTTP and HTTPS.

T1071.001
Web Protocols
MalwareSeasalt

Seasalt uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwarePLEAD

PLEAD has used HTTP for communications with command and control (C2) servers.

T1071.001
Web Protocols
MalwareRaccoon Stealer

Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.

T1071.001
Web Protocols
MalwareIPsec Helper

IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.

T1071.001
Web Protocols
MalwareDaserf

Daserf uses HTTP for C2.

T1071.001
Web Protocols
MalwareGoldFinder

GoldFinder has used HTTP for C2.

T1071.001
Web Protocols
MalwareCarbon

Carbon can use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareCardinal RAT

Cardinal RAT is downloaded using HTTP over port 443.

T1071.001
Web Protocols
MalwareDanBot

DanBot can use HTTP in C2 communication.

T1071.001
Web Protocols
MalwareGoldenSpy

GoldenSpy has used the Ryeol HTTP Client to facilitate HTTP internet communication.

T1071.001
Web Protocols
MalwareGold Dragon

Gold Dragon uses HTTP for communication to the control servers.

T1071.001
Web Protocols
MalwareRGDoor

RGDoor uses HTTP for C2 communications.

T1071.001
Web Protocols
MalwareRamsay

Ramsay has used HTTP for C2.

T1071.001
Web Protocols
MalwareNeo-reGeorg

Neo-reGeorg can use customized HTTP headers.

T1071.001
Web Protocols
MalwareAshTag

AshTag can use HTTP to send and receive data from C2.

T1071.001
Web Protocols
MalwareCarberp

Carberp has connected to C2 servers via HTTP.

T1071.001
Web Protocols
MalwareFRAMESTING

FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data.

T1071.001
Web Protocols
MalwareTrailBlazer

TrailBlazer has used HTTP requests for C2.

T1071.001
Web Protocols
MalwareMOPSLED

MOPSLED can communicate to C2 nodes over HTTP.

T1071.001
Web Protocols
MalwareMore_eggs

More_eggs uses HTTPS for C2.

T1071.001
Web Protocols
MalwareOutSteel

OutSteel has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareBackConfig

BackConfig has the ability to use HTTPS for C2 communiations.

T1071.001
Web Protocols
MalwarePowGoop

PowGoop can send HTTP GET requests to malicious servers.

T1071.001
Web Protocols
MalwareBoomBox

BoomBox has used HTTP POST requests for C2.

T1071.001
Web Protocols
MalwareLAMEHUG

LAMEHUG can use HTTP POST requests to exfiltrate data from compromised hosts to C2.

T1071.001
Web Protocols
MalwareMango

Mango can retrieve C2 commands sent in HTTP responses.

T1071.001
Web Protocols
MalwareWIREFIRE

WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`.

T1071.001
Web Protocols
MalwareGrimAgent

GrimAgent has the ability to use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareLookBack

LookBack’s C2 proxy tool sends data to a C2 server over HTTP.

T1071.001
Web Protocols
MalwareSTEADYPULSE

STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution.

T1071.001
Web Protocols
MalwareYAHOYAH

YAHOYAH uses HTTP for C2.

T1071.001
Web Protocols
MalwareLokibot

Lokibot has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareCloudDuke

One variant of CloudDuke uses HTTP and HTTPS for C2.

T1071.001
Web Protocols
MalwareEgregor

Egregor has communicated with its C2 servers via HTTPS protocol.

T1071.001
Web Protocols
MalwarePoetRAT

PoetRAT has used HTTP and HTTPs for C2 communications.

T1071.001
Web Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareStealBit

StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure.

T1071.001
Web Protocols
MalwareFELIXROOT

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1071.001
Web Protocols
MalwareZxShell

ZxShell has used HTTP for C2 connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.