ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1105×

29 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
CampaignKV Botnet Activity

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.

T1105
Ingress Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware.

T1105
Ingress Tool Transfer
CampaignFrankenstein

During Frankenstein, the threat actors downloaded files and tools onto a victim machine.

T1105
Ingress Tool Transfer
CampaignRedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignOperation Sharpshooter

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.

T1105
Ingress Tool Transfer
CampaignOperation Honeybee

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1105
Ingress Tool Transfer
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1105
Ingress Tool Transfer
CampaignCutting Edge

During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1105
Ingress Tool Transfer
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory.

T1105
Ingress Tool Transfer
CampaignShadowRay

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.

T1105
Ingress Tool Transfer
CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

T1105
Ingress Tool Transfer
CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

T1105
Ingress Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.

T1105
Ingress Tool Transfer
CampaignFunnyDream

During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system.

T1105
Ingress Tool Transfer
CampaignOuter Space

During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure.

T1105
Ingress Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.

T1105
Ingress Tool Transfer
CampaignC0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

T1105
Ingress Tool Transfer
CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1105
Ingress Tool Transfer
CampaignNight Dragon

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.

T1105
Ingress Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors downloaded additional files to the infected system.

T1105
Ingress Tool Transfer
CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

T1105
Ingress Tool Transfer
CampaignC0026

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.

T1105
Ingress Tool Transfer
CampaignC0027

During C0027, Scattered Spider downloaded tools using victim organization systems.

T1105
Ingress Tool Transfer
CampaignQuad7 Activity

Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices.

T1105
Ingress Tool Transfer
CampaignCostaRicto

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.