ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1029×

17 examples

TechniqueUsed byProcedure example
T1029
Scheduled Transfer
MalwareNinja

Ninja can configure its agent to work only in specific time frames.

T1029
Scheduled Transfer
MalwareTinyTurla

TinyTurla contacts its C2 based on a scheduled timing set in its configuration.

T1029
Scheduled Transfer
MalwareMachete

Machete sends stolen data to the C2 server every 10 minutes.

T1029
Scheduled Transfer
MalwareKazuar

Kazuar can sleep for a specific time and be set to communicate at specific intervals.

T1029
Scheduled Transfer
MalwareShimRat

ShimRat can sleep when instructed to do so by the C2.

T1029
Scheduled Transfer
MalwareChrommme

Chrommme can set itself to sleep before requesting a new command from C2.

T1029
Scheduled Transfer
MalwareFlagpro

Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2.

T1029
Scheduled Transfer
MalwareLightNeuron

LightNeuron can be configured to exfiltrate data during nighttime or working hours.

T1029
Scheduled Transfer
MalwareShark

Shark can pause C2 communications for a specified time.

T1029
Scheduled Transfer
MalwareCobalt Strike

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.

T1029
Scheduled Transfer
MalwareComRAT

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1029
Scheduled Transfer
MalwareDipsind

Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic.

T1029
Scheduled Transfer
MalwarePOWERSTATS

POWERSTATS can sleep for a given number of seconds.

T1029
Scheduled Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure.

T1029
Scheduled Transfer
MalwareShadowPad

ShadowPad has sent data back to C2 every 8 hours.

T1029
Scheduled Transfer
MalwarejRAT

jRAT can be configured to reconnect at certain intervals.

T1029
Scheduled Transfer
MalwareADVSTORESHELL

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.