Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignKV Botnet Activity | KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes. |
| T1105 Ingress Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware. |
| T1105 Ingress Tool Transfer |
CampaignFrankenstein | During Frankenstein, the threat actors downloaded files and tools onto a victim machine. |
| T1105 Ingress Tool Transfer |
CampaignRedPenguin | During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignOperation Sharpshooter | During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader. |
| T1105 Ingress Tool Transfer |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1105 Ingress Tool Transfer |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1105 Ingress Tool Transfer |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs. |
| T1105 Ingress Tool Transfer |
CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| T1105 Ingress Tool Transfer |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory. |
| T1105 Ingress Tool Transfer |
CampaignShadowRay | During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
| T1105 Ingress Tool Transfer |
CampaignC0015 | During C0015, the threat actors downloaded additional tools and files onto a compromised network. |
| T1105 Ingress Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access. |
| T1105 Ingress Tool Transfer |
CampaignFunnyDream | During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system. |
| T1105 Ingress Tool Transfer |
CampaignOuter Space | During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure. |
| T1105 Ingress Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server. |
| T1105 Ingress Tool Transfer |
CampaignC0010 | During C0010, UNC3890 actors downloaded tools and malware onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1105 Ingress Tool Transfer |
CampaignNight Dragon | During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems. |
| T1105 Ingress Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors downloaded additional files to the infected system. |
| T1105 Ingress Tool Transfer |
CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
| T1105 Ingress Tool Transfer |
CampaignC0026 | During C0026, the threat actors downloaded malicious payloads onto select compromised hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0027 | During C0027, Scattered Spider downloaded tools using victim organization systems. |
| T1105 Ingress Tool Transfer |
CampaignQuad7 Activity | Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices. |
| T1105 Ingress Tool Transfer |
CampaignCostaRicto | During CostaRicto, the threat actors downloaded malware and tools onto a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.