Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1570 Lateral Tool Transfer |
GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| T1570 Lateral Tool Transfer |
GroupGALLIUM | GALLIUM has used PsExec to move laterally between hosts in the target network. |
| T1570 Lateral Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has copied web shells between servers in targeted environments. |
| T1570 Lateral Tool Transfer |
GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| T1570 Lateral Tool Transfer |
GroupAPT32 | APT32 has deployed tools after moving laterally using administrative accounts. |
| T1570 Lateral Tool Transfer |
GroupStorm-1811 | Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1570 Lateral Tool Transfer |
GroupUNC3886 | UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs. |
| T1570 Lateral Tool Transfer |
GroupAoqin Dragon | Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1570 Lateral Tool Transfer |
GroupChimera | Chimera has copied tools between compromised hosts using SMB. |
| T1570 Lateral Tool Transfer |
GroupMedusa Group | Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment. |
| T1570 Lateral Tool Transfer |
GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| T1570 Lateral Tool Transfer |
GroupAgrius | Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as |
| T1570 Lateral Tool Transfer |
GroupINC Ransom | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
GroupWizard Spider | Wizard Spider has used stolen credentials to copy tools into the |
| T1570 Lateral Tool Transfer |
GroupVelvet Ant | Velvet Ant transferred files laterally within victim networks through the Impacket toolkit. |
| T1570 Lateral Tool Transfer |
GroupMagic Hound | Magic Hound has copied tools within a compromised network using RDP. |
| T1570 Lateral Tool Transfer |
GroupFIN10 | FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.