ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1572×

15 examples

TechniqueUsed byProcedure example
T1572
Protocol Tunneling
GroupSalt Typhoon

Salt Typhoon has modified device configurations to create and use Generic Routing Encapsulation (GRE) tunnels.

T1572
Protocol Tunneling
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

T1572
Protocol Tunneling
GroupFIN7

FIN7 has tunneled C2 traffic via OpenSSH.

T1572
Protocol Tunneling
GroupMustang Panda

Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445.

T1572
Protocol Tunneling
GroupScattered Spider

Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport.

T1572
Protocol Tunneling
GroupOilRig

OilRig has used the Plink utility and other tools to create tunnels to C2 servers.

T1572
Protocol Tunneling
GroupLeviathan

Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure.

T1572
Protocol Tunneling
GroupCinnamon Tempest

Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel.

T1572
Protocol Tunneling
GroupChimera

Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS.

T1572
Protocol Tunneling
GroupEmber Bear

Ember Bear has used ProxyChains to tunnel protocols to internal networks.

T1572
Protocol Tunneling
GroupFox Kitten

Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.

T1572
Protocol Tunneling
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1572
Protocol Tunneling
GroupVOID MANTICORE

VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices.

T1572
Protocol Tunneling
GroupMagic Hound

Magic Hound has used Plink to tunnel RDP over SSH.

T1572
Protocol Tunneling
GroupFIN13

FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.