{"schema_version":1,"key":"enterprise/T1105","id":"T1105","name":"Ingress Tool Transfer","domain":"enterprise","reviewed_on":"2026-09-28","source_url":"https://attack.mitre.org/techniques/T1105","source_file":{"file":"enterprise.json","url":"https://raw.githubusercontent.com/mitre-attack/attack-stix-data/6cda5ad8462c79e14fbb872f4e09059b18e0cfc4/enterprise-attack/enterprise-attack-19.2.json","sha256":"dc1639caa5501d720e280cf1cbd8fbe009884a0c9b3e6e9ed9d0c25166c3d8f4","bytes":53835637},"source_object_sha256":"ff2c8b1119c643983ecd11cf048a9a23257a069197586c0ed8aa2a353b0ce099","description":"Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). \n\nOn Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas)  A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023)\n\nAdversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms)\n\nFiles can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)","references":[{"source_name":"mitre-attack","url":"https://attack.mitre.org/techniques/T1105","external_id":"T1105"},{"source_name":"T1105: Trellix_search-ms","description":" Mathanraj Thangaraju, Sijo Jacob. (2023, July 26). Beyond File Search: A Novel Method for Exploiting the \"search-ms\" URI Protocol Handler. Retrieved March 15, 2024.","url":"https://www.trellix.com/blogs/research/beyond-file-search-a-novel-method/"},{"source_name":"Google Cloud Threat Intelligence COSCMICENERGY 2023","description":"COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises. (2023, May 25). Ken Proska, Daniel Kapellmann Zafra, Keith Lunden, Corey Hildebrandt, Rushikesh Nandedkar, Nathan Brubaker. Retrieved March 18, 2025.","url":"https://cloud.google.com/blog/topics/threat-intelligence/cosmicenergy-ot-malware-russian-response/"},{"source_name":"Dropbox Malware Sync","description":"David Talbot. (2013, August 21). Dropbox and Similar Services Can Sync Malware. Retrieved May 31, 2023.","url":"https://www.technologyreview.com/2013/08/21/83143/dropbox-and-similar-services-can-sync-malware/"},{"source_name":"University of Birmingham C2","description":"Gardiner, J.,  Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.","url":"https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf"},{"source_name":"t1105_lolbas","description":"LOLBAS. (n.d.). LOLBAS Mapped to T1105. Retrieved March 11, 2022.","url":"https://lolbas-project.github.io/#t1105"},{"source_name":"PTSecurity Cobalt Dec 2016","description":"Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.","url":"https://www.ptsecurity.com/upload/corporate/ww-en/analytics/Cobalt-Snatch-eng.pdf"}],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"environments":["cloud-hosted-endpoint","network-infrastructure","onprem","virtualization"],"visibility":"source_mapped","visibility_note":null,"parent":null,"children":[],"telemetry":[{"id":"DC0064","name":"Command Execution","page":"telemetry/DC0064/","kind":"attack_component","category":"Script and command execution","description":"Execution of a command and its interpreter or parent context.","collection_focus":"Collect process command lines and relevant shell/interpreter audit; shell history alone is neither complete nor tamper-resistant.","providers":[{"name":"PowerShell Script Block Logging","scope":"Script content via event 4104 when configured; channel depends on PowerShell edition.","source_id":"powershell"},{"name":"Sysmon process events","scope":"Interpreter launch and parent context, not full script content.","source_id":"sysmon"},{"name":"Linux Audit","scope":"execve-family execution context; shell built-ins need additional instrumentation.","source_id":"linux"}],"configuration":["Enable Script Block Logging through the policy/configuration for the installed edition. Forward Microsoft-Windows-PowerShell/Operational for Windows PowerShell, or PowerShellCore/Operational for PowerShell 7.","Retain script-block ID and fragment ordering alongside process creation. Protect access to collected script text; secrets may be included.","On Linux, use narrowly scoped Audit execution rules for the lab account and supported architectures, and retain joined SYSCALL/EXECVE/PATH records."],"configuration_example":null,"required_fields":["interpreter","command_line","actor_uid","session_id"],"example":{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0064","collector":"illustrative-lab-collector","observation":{"interpreter":"/bin/sh","command_line":"printf LAB_TELEMETRY_CHECK","actor_uid":1000,"session_id":"lab-session-1"}},"example_note":"Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.","limitations":"Script content and process command lines are different signals. Logging may be partial, fragmented, filtered or disabled; never assume a command line reveals everything executed.","sources":[{"id":"powershell","title":"Microsoft PowerShell logging on Windows","url":"https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.5"},{"id":"sysmon","title":"Microsoft Sysmon events and configuration","url":"https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon"},{"id":"linux","title":"Linux Audit rule configuration","url":"https://www.man7.org/linux/man-pages/man8/auditctl.8.html"}],"association":"attack_component","anomaly_design":"Per host role and principal: rare interpreters, command argument patterns and parent-child sequences. Normalize scripts carefully; obfuscation, administrative automation and missing command lines change visibility."},{"id":"DC0039","name":"File Creation","page":"telemetry/DC0039/","kind":"attack_component","category":"Endpoint activity","description":"Creation or overwrite of a file at an observed path.","collection_focus":"Scope Sysmon FileCreate (11) to the lab directory; retain the process and file path. Differentiate creation/overwrite if the sensor can.","providers":[{"name":"Microsoft Sysmon","scope":"Windows event-based collection; enable the event types needed below.","source_id":"sysmon"},{"name":"Linux Audit","scope":"Linux alternative for supported system-call and file events; different semantics and fields.","source_id":"linux"},{"name":"Apple Endpoint Security clients","scope":"macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.","source_id":"apple"}],"configuration":["On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.","Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.","For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms."],"configuration_example":null,"required_fields":["process_id","path","action","size_bytes"],"example":{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0039","collector":"illustrative-lab-collector","observation":{"process_id":4200,"path":"C:\\Lab\\demo.txt","action":"create","size_bytes":64}},"example_note":"Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.","limitations":"Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.","sources":[{"id":"sysmon","title":"Microsoft Sysmon events and configuration","url":"https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon"},{"id":"sysmon_config","title":"Microsoft Sysmon configuration files","url":"https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-configuration-files"},{"id":"linux","title":"Linux Audit rule configuration","url":"https://www.man7.org/linux/man-pages/man8/auditctl.8.html"},{"id":"apple","title":"Apple Endpoint Security framework for macOS","url":"https://developer.apple.com/documentation/endpointsecurity"},{"id":"process_audit","title":"Microsoft process creation event 4688","url":"https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4688"}],"association":"attack_component","anomaly_design":"Per host role and user: rare process/object combinations, bursts of object access or modification, and ordered parent/action sequences. Compare maintenance windows and signed software rollout activity."},{"id":"DC0082","name":"Network Connection Creation","page":"telemetry/DC0082/","kind":"attack_component","category":"Endpoint activity","description":"Creation of an endpoint network connection linked to a process.","collection_focus":"Enable scoped Sysmon NetworkConnect (3), disabled by default, or a platform-equivalent process-aware network sensor.","providers":[{"name":"Microsoft Sysmon","scope":"Windows event-based collection; enable the event types needed below.","source_id":"sysmon"},{"name":"Linux Audit","scope":"Linux alternative for supported system-call and file events; different semantics and fields.","source_id":"linux"},{"name":"Apple Endpoint Security clients","scope":"macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.","source_id":"apple"}],"configuration":["On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.","Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.","For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms."],"configuration_example":null,"required_fields":["process_guid","destination_ip","destination_port","protocol","initiated"],"example":{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0082","collector":"illustrative-lab-collector","observation":{"process_guid":"lab-process-001","destination_ip":"198.51.100.20","destination_port":443,"protocol":"tcp","initiated":true}},"example_note":"Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.","limitations":"Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.","sources":[{"id":"sysmon","title":"Microsoft Sysmon events and configuration","url":"https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon"},{"id":"sysmon_config","title":"Microsoft Sysmon configuration files","url":"https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-configuration-files"},{"id":"linux","title":"Linux Audit rule configuration","url":"https://www.man7.org/linux/man-pages/man8/auditctl.8.html"},{"id":"apple","title":"Apple Endpoint Security framework for macOS","url":"https://developer.apple.com/documentation/endpointsecurity"},{"id":"process_audit","title":"Microsoft process creation event 4688","url":"https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4688"}],"association":"attack_component","anomaly_design":"Per host role and user: rare process/object combinations, bursts of object access or modification, and ordered parent/action sequences. Compare maintenance windows and signed software rollout activity."},{"id":"DC0078","name":"Network Traffic Flow","page":"telemetry/DC0078/","kind":"attack_component","category":"Network and protocol telemetry","description":"Connection/flow summaries such as endpoints, duration, byte counts and transport.","collection_focus":"Collect Zeek conn.log, Suricata flow events or exporter equivalents, including observation point and sampling settings.","providers":[{"name":"Zeek","scope":"Connection and protocol metadata from traffic visible to the sensor.","source_id":"zeek"},{"name":"Suricata EVE","scope":"Configured flow, alert, DNS, HTTP, TLS and protocol records.","source_id":"suricata"},{"name":"AWS VPC Flow Logs","scope":"IP traffic metadata alternative; no packet payload or DNS answer history, and some traffic is not logged.","source_id":"flow"}],"configuration":["Use an authorized lab TAP/SPAN, virtual mirror or gateway interface. Define which traffic crosses it; avoid assuming visibility into every segment.","Enable the required Zeek analyzers or Suricata EVE event types. Export logs with sensor identity, clock synchronization and flow correlation identifiers.","Monitor capture loss, truncation and exporter sampling. Capture payload only with approval and restrictive retention; encryption normally prevents plaintext inspection."],"configuration_example":null,"required_fields":["source_ip","destination_ip","destination_port","protocol","bytes_sent","bytes_received"],"example":{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0078","collector":"illustrative-lab-collector","observation":{"source_ip":"192.0.2.10","destination_ip":"198.51.100.20","destination_port":443,"protocol":"tcp","bytes_sent":128,"bytes_received":512}},"example_note":"Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.","limitations":"Flows are not packet payloads. NAT, asymmetric routes, encryption, missing mirrors and sampling can hide attribution or content. A destination connection alone does not prove malicious intent.","sources":[{"id":"zeek","title":"Zeek protocol and connection logs","url":"https://docs.zeek.org/en/current/reference/logs/index.html"},{"id":"zeek_start","title":"Zeek capture setup","url":"https://docs.zeek.org/en/current/quickstart.html"},{"id":"suricata","title":"Suricata EVE JSON output","url":"https://docs.suricata.io/en/latest/output/eve/eve-json-output.html"},{"id":"flow","title":"AWS VPC Flow Logs","url":"https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html"}],"association":"attack_component","anomaly_design":"Per source and observation point: connection rate, destination-host/port fan-out, response/failure ratio and previously unseen destinations. Compare equivalent time windows; separate authorized scanners, NAT and sampling effects."},{"id":"DC0032","name":"Process Creation","page":"telemetry/DC0032/","kind":"attack_component","category":"Endpoint activity","description":"Creation of a process with executable, command line, parent and security context.","collection_focus":"Collect Sysmon ProcessCreate (1); preserve ProcessGuid and parent identifiers. Security 4688 is an alternative with separate audit/command-line settings.","providers":[{"name":"Microsoft Sysmon","scope":"Windows event-based collection; enable the event types needed below.","source_id":"sysmon"},{"name":"Linux Audit","scope":"Linux alternative for supported system-call and file events; different semantics and fields.","source_id":"linux"},{"name":"Apple Endpoint Security clients","scope":"macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.","source_id":"apple"}],"configuration":["On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.","Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.","For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms."],"configuration_example":{"label":"Sysmon filter fragment · merge into the reviewed lab configuration","language":"xml","source_id":"sysmon_config","content":"<EventFiltering>\n  <ProcessCreate onmatch=\"include\">\n    <Image condition=\"is\">C:\\Windows\\System32\\whoami.exe</Image>\n  </ProcessCreate>\n</EventFiltering>","note":"This fragment only selects the named process. It is not a complete production policy. Inspect the installed schema with sysmon64 -s; preserve existing rules, then apply the reviewed complete configuration with sysmon64 -c <configuration-file>."},"required_fields":["process_guid","image","parent_image","command_line","user"],"example":{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0032","collector":"illustrative-lab-collector","observation":{"process_guid":"lab-process-001","image":"C:\\Windows\\System32\\whoami.exe","parent_image":"C:\\Windows\\System32\\cmd.exe","command_line":"whoami","user":"LAB\\analyst"}},"example_note":"Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.","limitations":"Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.","sources":[{"id":"sysmon","title":"Microsoft Sysmon events and configuration","url":"https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon"},{"id":"sysmon_config","title":"Microsoft Sysmon configuration files","url":"https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-configuration-files"},{"id":"linux","title":"Linux Audit rule configuration","url":"https://www.man7.org/linux/man-pages/man8/auditctl.8.html"},{"id":"apple","title":"Apple Endpoint Security framework for macOS","url":"https://developer.apple.com/documentation/endpointsecurity"},{"id":"process_audit","title":"Microsoft process creation event 4688","url":"https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4688"}],"association":"attack_component","anomaly_design":"Per host role and user: rare process/object combinations, bursts of object access or modification, and ordered parent/action sequences. Compare maintenance windows and signed software rollout activity."}],"detection":{"key":"enterprise/T1105","id":"T1105","name":"Ingress Tool Transfer","domain":"enterprise","platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"environments":["cloud-hosted-endpoint","network-infrastructure","onprem","virtualization"],"source_url":"https://attack.mitre.org/techniques/T1105","technique_page":"techniques/enterprise/T1105/","page":"detections/enterprise/T1105/","status":"rule_source_available","counts":{"sigma":70,"atlas_basic":1,"atlas_anomaly":0,"strategies":1,"analytics":5,"live_validated":0},"sigma_rules":[{"id":"7a14080d-a048-4de8-ae58-604ce58a795b","title":"Remote File Copy","status":"stable","level":"low","logsource":{"product":"linux"},"data_path":"data/detection-rules/7a14080d-a048-4de8-ae58-604ce58a795b.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/builtin/lnx_file_copy.yml","author":"Ömer Günal","kind":"sigma"},{"id":"35a05c60-9012-49b6-a11f-6bab741c9f74","title":"Wget Creating Files in Tmp Directory","status":"test","level":"medium","logsource":{"product":"linux","category":"file_event"},"data_path":"data/detection-rules/35a05c60-9012-49b6-a11f-6bab741c9f74.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/file_event/file_event_lnx_wget_download_file_in_tmp_dir.yml","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","kind":"sigma"},{"id":"ea34fb97-e2c4-4afb-810f-785e4459b194","title":"Curl Usage on Linux","status":"test","level":"low","logsource":{"category":"process_creation","product":"linux"},"data_path":"data/detection-rules/ea34fb97-e2c4-4afb-810f-785e4459b194.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/process_creation/proc_creation_lnx_curl_usage.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"00b90cc1-17ec-402c-96ad-3a8117d7a582","title":"Suspicious Curl File Upload - Linux","status":"test","level":"medium","logsource":{"category":"process_creation","product":"linux"},"data_path":"data/detection-rules/00b90cc1-17ec-402c-96ad-3a8117d7a582.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/process_creation/proc_creation_lnx_susp_curl_fileupload.yml","author":"Nasreddine Bencherchali (Nextron Systems), Cedric MAURUGEON (Update)","kind":"sigma"},{"id":"cf610c15-ed71-46e1-bdf8-2bd1a99de6c4","title":"Download File To Potentially Suspicious Directory Via Wget","status":"test","level":"medium","logsource":{"category":"process_creation","product":"linux"},"data_path":"data/detection-rules/cf610c15-ed71-46e1-bdf8-2bd1a99de6c4.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/linux/process_creation/proc_creation_lnx_wget_download_suspicious_directory.yml","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","kind":"sigma"},{"id":"3b2c1059-ae5f-40b6-b5d4-6106d3ac20fe","title":"Hidden Flag Set On File/Directory Via Chflags - MacOS","status":"test","level":"medium","logsource":{"product":"macos","category":"process_creation"},"data_path":"data/detection-rules/3b2c1059-ae5f-40b6-b5d4-6106d3ac20fe.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml","author":"Omar Khaled (@beacon_exe)","kind":"sigma"},{"id":"6d8a7cf1-8085-423b-b87d-7e880faabbdf","title":"File Download Via Nscurl - MacOS","status":"test","level":"medium","logsource":{"category":"process_creation","product":"macos"},"data_path":"data/detection-rules/6d8a7cf1-8085-423b-b87d-7e880faabbdf.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml","author":"Daniel Cortez","kind":"sigma"},{"id":"13db8d2e-7723-4c2c-93c1-a4d36994f7ef","title":"Potential In-Memory Download And Compile Of Payloads","status":"test","level":"medium","logsource":{"category":"process_creation","product":"macos"},"data_path":"data/detection-rules/13db8d2e-7723-4c2c-93c1-a4d36994f7ef.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/macos/process_creation/proc_creation_macos_susp_in_memory_download_and_compile.yml","author":"Sohan G (D4rkCiph3r), Red Canary (idea)","kind":"sigma"},{"id":"5e51acb2-bcbe-435b-99c6-0e3cd5e2aa59","title":"Cisco Stage Data","status":"test","level":"low","logsource":{"product":"cisco","service":"aaa"},"data_path":"data/detection-rules/5e51acb2-bcbe-435b-99c6-0e3cd5e2aa59.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/network/cisco/aaa/cisco_cli_moving_data.yml","author":"Austin Clark","kind":"sigma"},{"id":"aac2fd97-bcba-491b-ad66-a6edf89c71bf","title":"Executable from Webdav","status":"test","level":"medium","logsource":{"product":"zeek","service":"http"},"data_path":"data/detection-rules/aac2fd97-bcba-491b-ad66-a6edf89c71bf.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/network/zeek/zeek_http_executable_download_from_webdav.yml","author":"SOC Prime, Adam Swan","kind":"sigma"},{"id":"195c1119-ef07-4909-bb12-e66f5e07bf3c","title":"Download from Suspicious Dyndns Hosts","status":"test","level":"medium","logsource":{"category":"proxy"},"data_path":"data/detection-rules/195c1119-ef07-4909-bb12-e66f5e07bf3c.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/web/proxy_generic/proxy_download_susp_dyndns.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"54f0434b-726f-48a1-b2aa-067df14516e4","title":"Password Protected ZIP File Opened (Suspicious Filenames)","status":"test","level":"high","logsource":{"product":"windows","service":"security"},"data_path":"data/detection-rules/54f0434b-726f-48a1-b2aa-067df14516e4.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_susp_opened_encrypted_zip_filename.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"7cff77e1-9663-46a3-8260-17f2e1aa9d0a","title":"AppX Package Installation Attempts Via AppInstaller.EXE","status":"test","level":"medium","logsource":{"product":"windows","category":"dns_query"},"data_path":"data/detection-rules/7cff77e1-9663-46a3-8260-17f2e1aa9d0a.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/dns_query/dns_query_win_appinstaller.yml","author":"frack113","kind":"sigma"},{"id":"e890acee-d488-420e-8f20-d9b19b3c3d43","title":"Suspicious File Created by ArcSOC.exe","status":"experimental","level":"high","logsource":{"category":"file_event","product":"windows"},"data_path":"data/detection-rules/e890acee-d488-420e-8f20-d9b19b3c3d43.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_arcsoc_susp_file_created.yml","author":"Micah Babinski","kind":"sigma"},{"id":"9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d","title":"Potentially Suspicious File Creation by OpenEDR's ITSMService","status":"experimental","level":"medium","logsource":{"product":"windows","category":"file_event"},"data_path":"data/detection-rules/9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_comodo_itsm_potentially_suspicious_file_creation.yml","author":"@kostastsale","kind":"sigma"},{"id":"6c0ce3b6-85e2-49d4-9c3f-6e008ce9796e","title":"Suspicious Deno File Written from Remote Source","status":"experimental","level":"low","logsource":{"category":"file_event","product":"windows"},"data_path":"data/detection-rules/6c0ce3b6-85e2-49d4-9c3f-6e008ce9796e.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_creation_deno.yml","author":"Josh Nickels, Michael Taggart","kind":"sigma"},{"id":"fc4f4817-0c53-4683-a4ee-b17a64bc1039","title":"Suspicious Desktopimgdownldr Target File","status":"test","level":"high","logsource":{"product":"windows","category":"file_event"},"data_path":"data/detection-rules/fc4f4817-0c53-4683-a4ee-b17a64bc1039.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"1cf465a1-2609-4c15-9b66-c32dbe4bfd67","title":"Legitimate Application Writing Files In Uncommon Location","status":"experimental","level":"high","logsource":{"product":"windows","category":"file_event"},"data_path":"data/detection-rules/1cf465a1-2609-4c15-9b66-c32dbe4bfd67.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/file/file_event/file_event_win_susp_legitimate_app_dropping_in_uncommon_location.yml","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","kind":"sigma"},{"id":"0dba975d-a193-4ed1-a067-424df57570d1","title":"Uncommon Network Connection Initiated By Certutil.EXE","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/0dba975d-a193-4ed1-a067-424df57570d1.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_certutil_initiated_connection.yml","author":"frack113, Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"25eabf56-22f0-4915-a1ed-056b8dae0a68","title":"Suspicious Dropbox API Usage","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/25eabf56-22f0-4915-a1ed-056b8dae0a68.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_domain_dropbox_api.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"c3dbbc9f-ef1d-470a-a90a-d343448d5875","title":"Suspicious Non-Browser Network Communication With Telegram API","status":"test","level":"medium","logsource":{"product":"windows","category":"network_connection"},"data_path":"data/detection-rules/c3dbbc9f-ef1d-470a-a90a-d343448d5875.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_domain_telegram_api_non_browser_access.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"8d7e392e-9b28-49e1-831d-5949c6281228","title":"Network Connection Initiated By IMEWDBLD.EXE","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/8d7e392e-9b28-49e1-831d-5949c6281228.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_imewdbld.yml","author":"frack113","kind":"sigma"},{"id":"e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97","title":"Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_susp_file_sharing_domains_susp_folders.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"7b434893-c57d-4f41-908d-6a17bf1ae98f","title":"Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/7b434893-c57d-4f41-908d-6a17bf1ae98f.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_susp_initiated_uncommon_or_suspicious_locations.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"08249dc0-a28d-4555-8ba5-9255a198e08c","title":"Local Network Connection Initiated By Script Interpreter","status":"test","level":"medium","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/08249dc0-a28d-4555-8ba5-9255a198e08c.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_wscript_cscript_local_connection.yml","author":"frack113","kind":"sigma"},{"id":"992a6cae-db6a-43c8-9cec-76d7195c96fc","title":"Outbound Network Connection Initiated By Script Interpreter","status":"test","level":"high","logsource":{"category":"network_connection","product":"windows"},"data_path":"data/detection-rules/992a6cae-db6a-43c8-9cec-76d7195c96fc.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_wscript_cscript_outbound_connection.yml","author":"frack113, Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"3236fcd0-b7e3-4433-b4f8-86ad61a9af2d","title":"PowerShell Download Via Net.WebClient - PowerShell Classic","status":"test","level":"low","logsource":{"product":"windows","category":"ps_classic_start"},"data_path":"data/detection-rules/3236fcd0-b7e3-4433-b4f8-86ad61a9af2d.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_classic/posh_pc_download_via_webclient.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"3c7d1587-3b13-439f-9941-7d14313dbdfe","title":"Potential COM Objects Download Cradles Usage - PS Script","status":"test","level":"medium","logsource":{"product":"windows","category":"ps_script","definition":"Script Block Logging must be enable"},"data_path":"data/detection-rules/3c7d1587-3b13-439f-9941-7d14313dbdfe.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_script/posh_ps_download_com_cradles.yml","author":"frack113","kind":"sigma"},{"id":"d059842b-6b9d-4ed1-b5c3-5b89143c6ede","title":"File Download Via Bitsadmin","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/d059842b-6b9d-4ed1-b5c3-5b89143c6ede.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml","author":"Michael Haag, FPT.EagleEye","kind":"sigma"},{"id":"8518ed3d-f7c9-4601-a26c-f361a4256a0c","title":"Suspicious Download From File-Sharing Website Via Bitsadmin","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/8518ed3d-f7c9-4601-a26c-f361a4256a0c.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"5b80a791-ad9b-4b75-bcc1-ad4e1e89c200","title":"File With Suspicious Extension Downloaded Via Bitsadmin","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/5b80a791-ad9b-4b75-bcc1-ad4e1e89c200.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_extensions.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"2ddef153-167b-4e89-86b6-757a9e65dcac","title":"File Download Via Bitsadmin To A Suspicious Target Folder","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/2ddef153-167b-4e89-86b6-757a9e65dcac.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"ef9dcfed-690c-4c5d-a9d1-482cd422225c","title":"Browser Execution In Headless Mode","status":"test","level":"low","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/ef9dcfed-690c-4c5d-a9d1-482cd422225c.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_exec.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"0e8cfe08-02c9-4815-a2f8-0d157b7ed33e","title":"File Download with Headless Browser","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/0e8cfe08-02c9-4815-a2f8-0d157b7ed33e.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml","author":"Sreeman, Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"94771a71-ba41-4b6e-a757-b531372eaab6","title":"File Download From Browser Process Via Inline URL","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/94771a71-ba41-4b6e-a757-b531372eaab6.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_browsers_inline_file_download.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"70ad0861-d1fe-491c-a45f-fa48148a300d","title":"File Download via CertOC.EXE","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/70ad0861-d1fe-491c-a45f-fa48148a300d.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certoc_download.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"b86f6dea-0b2f-41f5-bdcc-a057bd19cd6a","title":"File Download From IP Based URL Via CertOC.EXE","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/b86f6dea-0b2f-41f5-bdcc-a057bd19cd6a.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certoc_download_direct_ip.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"4480827a-9799-4232-b2c4-ccc6c4e9e12b","title":"Suspicious CertReq Command to Download","status":"experimental","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/4480827a-9799-4232-b2c4-ccc6c4e9e12b.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certreq_download.yml","author":"Christian Burkard (Nextron Systems)","kind":"sigma"},{"id":"19b08b1c-861d-4e75-a1ef-ea0c1baf202b","title":"Suspicious Download Via Certutil.EXE","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/19b08b1c-861d-4e75-a1ef-ea0c1baf202b.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certutil_download.yml","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"13e6fe51-d478-4c7e-b0f2-6da9b400a829","title":"Suspicious File Downloaded From Direct IP Via Certutil.EXE","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/13e6fe51-d478-4c7e-b0f2-6da9b400a829.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certutil_download_direct_ip.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"42a5f1e7-9603-4f6d-97ae-3f37d130d794","title":"Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/42a5f1e7-9603-4f6d-97ae-3f37d130d794.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_certutil_download_file_sharing_domains.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"21dd6d38-2b18-4453-9404-a0fe4a0cc288","title":"Curl Download And Execute Combination","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/21dd6d38-2b18-4453-9404-a0fe4a0cc288.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_cmd_curl_download_exec_combo.yml","author":"Sreeman, Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"1ac8666b-046f-4201-8aba-1951aaec03a3","title":"Command Line Execution with Suspicious URL and AppData Strings","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/1ac8666b-046f-4201-8aba-1951aaec03a3.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_cmd_http_appdata.yml","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","kind":"sigma"},{"id":"aa0b3a82-eacc-4ec3-9150-b5a9a3e3f82f","title":"Potential Download/Upload Activity Using Type Command","status":"test","level":"medium","logsource":{"product":"windows","category":"process_creation"},"data_path":"data/detection-rules/aa0b3a82-eacc-4ec3-9150-b5a9a3e3f82f.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_cmd_type_arbitrary_file_download.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"e218595b-bbe7-4ee5-8a96-f32a24ad3468","title":"Suspicious Curl.EXE Download","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/e218595b-bbe7-4ee5-8a96-f32a24ad3468.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_curl_susp_download.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"214641c2-c579-4ecb-8427-0cf19df6842e","title":"Remote File Download Via Desktopimgdownldr Utility","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/214641c2-c579-4ecb-8427-0cf19df6842e.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_remote_file_download.yml","author":"Tim Rauch, Elastic (idea)","kind":"sigma"},{"id":"bb58aa4a-b80b-415a-a2c0-2f65a4c81009","title":"Suspicious Desktopimgdownldr Command","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/bb58aa4a-b80b-415a-a2c0-2f65a4c81009.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"587254ee-a24b-4335-b3cd-065c0f1f4baa","title":"Remote File Download Via Findstr.EXE","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/587254ee-a24b-4335-b3cd-065c0f1f4baa.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_findstr_download.yml","author":"Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"04936b66-3915-43ad-a8e5-809eadfd1141","title":"Insensitive Subfolder Search Via Findstr.EXE","status":"test","level":"low","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/04936b66-3915-43ad-a8e5-809eadfd1141.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_findstr_subfolder_search.yml","author":"Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"af491bca-e752-4b44-9c86-df5680533dbc","title":"Finger.EXE Execution","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/af491bca-e752-4b44-9c86-df5680533dbc.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_finger_execution.yml","author":"Florian Roth (Nextron Systems), omkar72, oscd.community","kind":"sigma"},{"id":"eee00933-a761-4cd0-be70-c42fe91731e7","title":"Arbitrary File Download Via GfxDownloadWrapper.EXE","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/eee00933-a761-4cd0-be70-c42fe91731e7.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_gfxdownloadwrapper_arbitrary_file_download.yml","author":"Victor Sergeev, oscd.community","kind":"sigma"},{"id":"44143844-0631-49ab-97a0-96387d6b2d7c","title":"File Download Using Notepad++ GUP Utility","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/44143844-0631-49ab-97a0-96387d6b2d7c.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_gup_download.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"9801abb8-e297-4dbf-9fbd-57dde0e830ad","title":"File Download And Execution Via IEExec.EXE","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/9801abb8-e297-4dbf-9fbd-57dde0e830ad.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_ieexec_download.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"6f535e01-ca1f-40be-ab8d-45b19c0c8b7f","title":"Import LDAP Data Interchange Format File Via Ldifde.EXE","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/6f535e01-ca1f-40be-ab8d-45b19c0c8b7f.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml","author":"@gott_cyber","kind":"sigma"},{"id":"185d7418-f250-42d0-b72e-0c8b70661e93","title":"Suspicious Diantz Download and Compress Into a CAB File","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/185d7418-f250-42d0-b72e-0c8b70661e93.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml","author":"frack113","kind":"sigma"},{"id":"aa8e035d-7be4-48d3-a944-102aec04400d","title":"Suspicious Extrac32 Execution","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/aa8e035d-7be4-48d3-a944-102aec04400d.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml","author":"frack113","kind":"sigma"},{"id":"cafeeba3-01da-4ab4-b6c4-a31b1d9730c7","title":"PrintBrm ZIP Creation of Extraction","status":"test","level":"high","logsource":{"product":"windows","category":"process_creation"},"data_path":"data/detection-rules/cafeeba3-01da-4ab4-b6c4-a31b1d9730c7.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml","author":"frack113","kind":"sigma"},{"id":"9292293b-8496-4715-9db6-37028dcda4b3","title":"Replace.exe Usage","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/9292293b-8496-4715-9db6-37028dcda4b3.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml","author":"frack113","kind":"sigma"},{"id":"46123129-1024-423e-9fae-43af4a0fa9a5","title":"File Download Via Windows Defender MpCmpRun.EXE","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/46123129-1024-423e-9fae-43af4a0fa9a5.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_mpcmdrun_download_arbitrary_file.yml","author":"Matthew Matchen","kind":"sigma"},{"id":"f7b5f842-a6af-4da5-9e95-e32478f3cd2f","title":"MsiExec Web Install","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/f7b5f842-a6af-4da5-9e95-e32478f3cd2f.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml","author":"Florian Roth (Nextron Systems)","kind":"sigma"},{"id":"222720a7-047f-4054-baa5-bab9be757db0","title":"PowerShell MSI Install via WindowsInstaller COM From Remote Location","status":"experimental","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/222720a7-047f-4054-baa5-bab9be757db0.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_powershell_comobject_msi_remote.yml","author":"Meroujan Antonyan (vx3r)","kind":"sigma"},{"id":"02b64f1b-3f33-4e67-aede-ef3b0a5a8fcf","title":"Potential COM Objects Download Cradles Usage - Process Creation","status":"test","level":"medium","logsource":{"product":"windows","category":"process_creation"},"data_path":"data/detection-rules/02b64f1b-3f33-4e67-aede-ef3b0a5a8fcf.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_powershell_download_com_cradles.yml","author":"frack113","kind":"sigma"},{"id":"0f0450f3-8b47-441e-a31b-15a91dc243e2","title":"Potential DLL File Download Via PowerShell Invoke-WebRequest","status":"test","level":"medium","logsource":{"product":"windows","category":"process_creation"},"data_path":"data/detection-rules/0f0450f3-8b47-441e-a31b-15a91dc243e2.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_powershell_download_dll.yml","author":"Florian Roth (Nextron Systems), Hieu Tran","kind":"sigma"},{"id":"1edff897-9146-48d2-9066-52e8d8f80a2f","title":"Suspicious Invoke-WebRequest Execution With DirectIP","status":"test","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/1edff897-9146-48d2-9066-52e8d8f80a2f.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_powershell_invoke_webrequest_direct_ip.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"5e3cc4d8-3e68-43db-8656-eaaeefdec9cc","title":"Suspicious Invoke-WebRequest Execution","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/5e3cc4d8-3e68-43db-8656-eaaeefdec9cc.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_powershell_invoke_webrequest_download.yml","author":"Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"74a12f18-505c-4114-8d0b-8448dd5485c6","title":"PUA - Nimgrab Execution","status":"test","level":"high","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/74a12f18-505c-4114-8d0b-8448dd5485c6.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_pua_nimgrab.yml","author":"frack113","kind":"sigma"},{"id":"2db93a3f-3249-4f73-9e68-0e77a0f8ae7e","title":"Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server","status":"experimental","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/2db93a3f-3249-4f73-9e68-0e77a0f8ae7e.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_remote_access_tools_tacticalrmm_agent_registration_via_cli.yml","author":"Ahmed Nosir (@egycondor)","kind":"sigma"},{"id":"1d174d38-8fda-4081-a9b6-56d9763c0cd8","title":"Scheduled Task Creation with Curl and PowerShell Execution Combo","status":"experimental","level":"medium","logsource":{"category":"process_creation","product":"windows"},"data_path":"data/detection-rules/1d174d38-8fda-4081-a9b6-56d9763c0cd8.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_schtasks_curl_and_powershell_combo.yml","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","kind":"sigma"},{"id":"00d49ed5-4491-4271-a8db-650a4ef6f8c1","title":"Suspicious Download from Office Domain","status":"test","level":"high","logsource":{"product":"windows","category":"process_creation"},"data_path":"data/detection-rules/00d49ed5-4491-4271-a8db-650a4ef6f8c1.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_susp_download_office_domain.yml","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","kind":"sigma"},{"id":"3aff0be0-7802-4a7e-a4fa-c60c74bc5e1d","title":"Lolbas OneDriveStandaloneUpdater.exe Proxy Download","status":"test","level":"high","logsource":{"category":"registry_set","product":"windows"},"data_path":"data/detection-rules/3aff0be0-7802-4a7e-a4fa-c60c74bc5e1d.json","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml","author":"frack113","kind":"sigma"}],"atlas_basic":[{"id":"atlas-basic-t1105-1","technique_id":"T1105","title":"T1105 Ingress Tool Transfer","kind":"basic","source_url":"https://1200km.com/anomaly-detection-atlas/attack-basic-detection-rule-catalog/#command-and-control","source_path":"docs/attack-basic-detection-rule-catalog.md","source_line":169,"pinned_source_url":"https://github.com/anpa1200/anomaly-detection-atlas/blob/e1f75007376022b2f596e413bea8612e514a5aa3/docs/attack-basic-detection-rule-catalog.md#L169","source_file_sha256":"396a87e3d8da74d170684c0f377fe5dc11cd1a486d4f2f89f7fbe94deaaa2a1e","source_row_sha256":"b774b019e221dea04c3b68c8ba922d9e203bb6812b5a4412a6217301e0e0b774","validation":"published_concept_not_executable_or_live_validated","logic":"MATCH(download_hash_or_url IN denylist) OR SEQUENCE(network_download, executable_file_creation) WITHIN 2m -> ALERT","log_sources":[{"title":"Proxy and Secure Web Gateway Logs","url":"https://1200km.com/anomaly-detection-atlas/security-log-source-taxonomy/#66-proxy-and-secure-web-gateway-logs"},{"title":"File-System Activity Logs","url":"https://1200km.com/anomaly-detection-atlas/security-log-source-taxonomy/#13-file-system-activity-logs"},{"title":"Content Inspection and Malware Scanning Logs","url":"https://1200km.com/anomaly-detection-atlas/security-log-source-taxonomy/#101-content-inspection-and-malware-scanning-logs"}]}],"atlas_anomaly":[],"anomaly_types":[],"strategies":[{"id":"DET0060","name":"Detect Ingress Tool Transfers via Behavioral Chain","url":"https://attack.mitre.org/detectionstrategies/DET0060","stix_id":"x-mitre-detection-strategy--67677c4c-5778-49eb-ae74-1920645b8554","relationship_id":"relationship--280c13b6-71c5-4e78-9cef-057528d42589","description":"","analytics":[{"id":"AN0165","name":"Analytic 0165","guidance":"Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0165","platforms":["Windows"],"tuning":[{"field":"ParentProcessName","description":"Tune for known good updaters (e.g., ChromeUpdate, OneDrive)"},{"field":"DestinationIPCategory","description":"Allow filtering by internal vs external IP blocks"},{"field":"FilePathRegex","description":"Focus on uncommon file drop paths (e.g., C:\\Users\\Public\\)"}],"log_sources":[{"component_id":"DC0082","component":"Network Connection Creation","name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","platforms":["Windows"],"analytic_id":"AN0165","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0165","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0082/"},{"component_id":"DC0039","component":"File Creation","name":"WinEventLog:Sysmon","channel":"EventCode=11","platforms":["Windows"],"analytic_id":"AN0165","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0165","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0039/"},{"component_id":"DC0032","component":"Process Creation","name":"WinEventLog:Sysmon","channel":"EventCode=1","platforms":["Windows"],"analytic_id":"AN0165","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0165","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0032/"}]},{"id":"AN0166","name":"Analytic 0166","guidance":"Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0166","platforms":["Linux"],"tuning":[{"field":"ToolName","description":"Match on curl, wget, rsync, etc. based on environment"},{"field":"DownloadExtension","description":"Tunable filter to limit to suspicious file types (.sh, .bin, .elf)"}],"log_sources":[{"component_id":"DC0064","component":"Command Execution","name":"auditd:SYSCALL","channel":"connect, execve, write","platforms":["Linux"],"analytic_id":"AN0166","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0166","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0064/"},{"component_id":"DC0039","component":"File Creation","name":"auditd:SYSCALL","channel":"file creation/modification","platforms":["Linux"],"analytic_id":"AN0166","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0166","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0039/"},{"component_id":"DC0078","component":"Network Traffic Flow","name":"iptables:LOG","channel":"TCP connections","platforms":["Linux"],"analytic_id":"AN0166","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0166","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0078/"}]},{"id":"AN0167","name":"Analytic 0167","guidance":"Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0167","platforms":["macOS"],"tuning":[{"field":"DirectoryTargeted","description":"Restrict to high-risk directories like /Users/Shared, /tmp/"},{"field":"ProcessPath","description":"May tune based on custom tooling or MDM activity"}],"log_sources":[{"component_id":"DC0032","component":"Process Creation","name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","platforms":["macOS"],"analytic_id":"AN0167","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0167","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0032/"},{"component_id":"DC0039","component":"File Creation","name":"macos:unifiedlog","channel":"file write/create","platforms":["macOS"],"analytic_id":"AN0167","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0167","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0039/"},{"component_id":"DC0082","component":"Network Connection Creation","name":"macos:unifiedlog","channel":"connection open","platforms":["macOS"],"analytic_id":"AN0167","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0167","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0082/"}]},{"id":"AN0168","name":"Analytic 0168","guidance":"Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0168","platforms":["ESXi"],"tuning":[{"field":"ToolName","description":"Tune for wget, curl, netcat, and scripting languages in use"},{"field":"DatastorePath","description":"Filter or prioritize specific paths (e.g., /vmfs/volumes/)"}],"log_sources":[{"component_id":"DC0064","component":"Command Execution","name":"esxi:hostd","channel":"command execution","platforms":["ESXi"],"analytic_id":"AN0168","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0168","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0064/"},{"component_id":"DC0039","component":"File Creation","name":"esxi:vmkernel","channel":"file write","platforms":["ESXi"],"analytic_id":"AN0168","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0168","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0039/"}]},{"id":"AN0169","name":"Analytic 0169","guidance":"Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0169","platforms":["Network Devices"],"tuning":[{"field":"PayloadVolumeThreshold","description":"Tune based on expected update size vs anomalous bulk data transfers"},{"field":"ProtocolUsed","description":"Flag unexpected protocols like TFTP, FTP, HTTP"}],"log_sources":[{"component_id":"DC0078","component":"Network Traffic Flow","name":"NSM:Flow","channel":"connection metadata","platforms":["Network Devices"],"analytic_id":"AN0169","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0169","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0078/"},{"component_id":"DC0039","component":"File Creation","name":"snmp:syslog","channel":"firmware write/log event","platforms":["Network Devices"],"analytic_id":"AN0169","source_url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0169","validation":"upstream_definition_not_locally_validated","component_page":"telemetry/DC0039/"}]}]}],"telemetry_references":[{"id":"DC0064","name":"Command Execution","tag":"Command Execution","page":"telemetry/DC0064/","kind":"attack_component"},{"id":"DC0039","name":"File Creation","tag":"File Creation","page":"telemetry/DC0039/","kind":"attack_component"},{"id":"DC0082","name":"Network Connection Creation","tag":"Network Connection Creation","page":"telemetry/DC0082/","kind":"attack_component"},{"id":"DC0078","name":"Network Traffic Flow","tag":"Network Traffic Flow","page":"telemetry/DC0078/","kind":"attack_component"},{"id":"DC0032","name":"Process Creation","tag":"Process Creation","page":"telemetry/DC0032/","kind":"attack_component"}],"visibility":"source_mapped","visibility_note":null,"tool_references":[{"id":"S1087","name":"AsyncRAT","page":"tools/S1087/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0190","name":"BITSAdmin","page":"tools/S0190/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S1063","name":"Brute Ratel C4","page":"tools/S1063/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0465","name":"CARROTBALL","page":"tools/S0465/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0160","name":"certutil","page":"tools/S0160/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0106","name":"cmd","page":"tools/S0106/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0154","name":"Cobalt Strike","page":"tools/S0154/","kind":"selected_framework","bases":["attack_uses"],"guides":[]},{"id":"S0527","name":"CSPY Downloader","page":"tools/S0527/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0695","name":"Donut","page":"tools/S0695/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0363","name":"Empire","page":"tools/S0363/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0404","name":"esentutl","page":"tools/S0404/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0095","name":"ftp","page":"tools/S0095/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0250","name":"Koadic","page":"tools/S0250/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0500","name":"MCMD","page":"tools/S0500/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0192","name":"Pupy","page":"tools/S0192/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0262","name":"QuasarRAT","page":"tools/S0262/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0332","name":"Remcos","page":"tools/S0332/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0592","name":"RemoteUtilities","page":"tools/S0592/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0445","name":"ShimRatReporter","page":"tools/S0445/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0692","name":"SILENTTRINITY","page":"tools/S0692/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0633","name":"Sliver","page":"tools/S0633/","kind":"attack_tool","bases":["attack_uses"],"guides":[{"id":"38602f432e5c","title":"Lab Architecture — Operation DragonRx","published_at":"2026-05-02","url":"https://1200km.com/articles/read/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c/","original_url":"https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c","archive_path":"docs/articles/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c.md","source_sha256":"51e18974e1481d1b83f58c3bff3a997c21e58fd027e2a159389ace500f2bc289","tool_ids":["S0633"]},{"id":"91339316f0df","title":"Attack Playbook — Operation DragonRx","published_at":"2026-05-04","url":"https://1200km.com/articles/read/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df/","original_url":"https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df","archive_path":"docs/articles/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df.md","source_sha256":"9b81bd1fd3daa8174dfb523b4b050f4710e62a9ce176029571975b56f6d246a0","tool_ids":["S0633"]}]}],"related_parent":null,"article_url":"https://1200km.com/articles/read/2026/2026-04-20-malicious-activity-as-a-statistical-signal-a-detection-engineering-analysis-of-anomaly-bas-90df8b6dea12/","validation":{"source_join":"exact_ids","sigma_yaml":"parsed","backend_compilation":"not_run","live_telemetry":"not_run","detection_execution":"not_run"}},"tools":[{"id":"S1087","name":"AsyncRAT","page":"tools/S1087/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0190","name":"BITSAdmin","page":"tools/S0190/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S1063","name":"Brute Ratel C4","page":"tools/S1063/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0465","name":"CARROTBALL","page":"tools/S0465/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0160","name":"certutil","page":"tools/S0160/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0106","name":"cmd","page":"tools/S0106/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0154","name":"Cobalt Strike","page":"tools/S0154/","kind":"selected_framework","bases":["attack_uses"],"guides":[]},{"id":"S0527","name":"CSPY Downloader","page":"tools/S0527/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0695","name":"Donut","page":"tools/S0695/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0363","name":"Empire","page":"tools/S0363/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0404","name":"esentutl","page":"tools/S0404/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0095","name":"ftp","page":"tools/S0095/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0250","name":"Koadic","page":"tools/S0250/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0500","name":"MCMD","page":"tools/S0500/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0192","name":"Pupy","page":"tools/S0192/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0262","name":"QuasarRAT","page":"tools/S0262/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0332","name":"Remcos","page":"tools/S0332/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0592","name":"RemoteUtilities","page":"tools/S0592/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0445","name":"ShimRatReporter","page":"tools/S0445/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0692","name":"SILENTTRINITY","page":"tools/S0692/","kind":"attack_tool","bases":["attack_uses"],"guides":[]},{"id":"S0633","name":"Sliver","page":"tools/S0633/","kind":"attack_tool","bases":["attack_uses"],"guides":[{"id":"38602f432e5c","title":"Lab Architecture — Operation DragonRx","published_at":"2026-05-02","url":"https://1200km.com/articles/read/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c/","original_url":"https://medium.com/@1200km/lab-architecture-operation-dragonrx-38602f432e5c","archive_path":"docs/articles/2026/2026-05-02-lab-architecture-operation-dragonrx-38602f432e5c.md","source_sha256":"51e18974e1481d1b83f58c3bff3a997c21e58fd027e2a159389ace500f2bc289","tool_ids":["S0633"]},{"id":"91339316f0df","title":"Attack Playbook — Operation DragonRx","published_at":"2026-05-04","url":"https://1200km.com/articles/read/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df/","original_url":"https://medium.com/@1200km/attack-playbook-operation-dragonrx-91339316f0df","archive_path":"docs/articles/2026/2026-05-04-attack-playbook-operation-dragonrx-91339316f0df.md","source_sha256":"9b81bd1fd3daa8174dfb523b4b050f4710e62a9ce176029571975b56f6d246a0","tool_ids":["S0633"]}]}],"software":[{"id":"S0009","name":"Hikit","url":"https://attack.mitre.org/software/S0009","kind":"malware","description":"[Hikit](https://attack.mitre.org/software/S0009) has the ability to download files to a compromised host.(Citation: Novetta-Axiom)","relationship_id":"relationship--fb0206c4-ed10-4922-9935-cbb2c7462acd","references":[{"source_name":"Novetta-Axiom","description":"Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.","url":"https://web.archive.org/web/20230115144216/http://www.novetta.com/wp-content/uploads/2014/11/Executive_Summary-Final_1.pdf"}]},{"id":"S0011","name":"Taidoor","url":"https://attack.mitre.org/software/S0011","kind":"malware","description":"[Taidoor](https://attack.mitre.org/software/S0011) has downloaded additional files onto a compromised host.(Citation: TrendMicro Taidoor)","relationship_id":"relationship--665f8af6-bdac-4574-9d8c-9c7829e0e4e7","references":[{"source_name":"TrendMicro Taidoor","description":"Trend Micro. (2012). The Taidoor Campaign. Retrieved November 12, 2014.","url":"http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_the_taidoor_campaign.pdf"}]},{"id":"S0012","name":"PoisonIvy","url":"https://attack.mitre.org/software/S0012","kind":"malware","description":"[PoisonIvy](https://attack.mitre.org/software/S0012) creates a backdoor through which remote attackers can upload files.(Citation: Symantec Darkmoon Aug 2005)","relationship_id":"relationship--ae7b632b-bb15-4807-be21-bdfff70f4f2e","references":[{"source_name":"Symantec Darkmoon Aug 2005","description":"Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2005-081910-3934-99"}]},{"id":"S0013","name":"PlugX","url":"https://attack.mitre.org/software/S0013","kind":"malware","description":"[PlugX](https://attack.mitre.org/software/S0013) has a module to download and execute files on the compromised machine.(Citation: CIRCL PlugX March 2013)(Citation: DOJ Affidavit Search and Seizure PlugX December 2024)(Citation: Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025)(Citation: Proofpoint TA416 Europe March 2022)","relationship_id":"relationship--7c8e34ad-89a4-44cf-bd56-d1583803f086","references":[{"source_name":"CIRCL PlugX March 2013","description":"Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.","url":"http://circl.lu/assets/files/tr-12/tr-12-circl-plugx-analysis-v1.pdf"},{"source_name":"DOJ Affidavit Search and Seizure PlugX December 2024","description":"DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION  FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND  SEIZURE OF COMPUTERS IN THE  UNITED STATES INFECTED WITH  PLUGX MALWARE . Retrieved September 9, 2025.","url":"https://www.justice.gov/archives/opa/media/1384136/dl"},{"source_name":"Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025","description":"Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.","url":"https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats"},{"source_name":"Proofpoint TA416 Europe March 2022","description":"Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.","url":"https://www.proofpoint.com/us/blog/threat-insight/good-bad-and-web-bug-ta416-increases-operational-tempo-against-european"}]},{"id":"S0015","name":"Ixeshe","url":"https://attack.mitre.org/software/S0015","kind":"malware","description":"[Ixeshe](https://attack.mitre.org/software/S0015) can download and execute additional files.(Citation: Trend Micro IXESHE 2012)","relationship_id":"relationship--79b980bb-f79e-4576-b927-be52be236f15","references":[{"source_name":"Trend Micro IXESHE 2012","description":"Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.","url":"https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp_ixeshe.pdf"}]},{"id":"S0017","name":"BISCUIT","url":"https://attack.mitre.org/software/S0017","kind":"malware","description":"[BISCUIT](https://attack.mitre.org/software/S0017) has a command to download a file from the C2 server.(Citation: Mandiant APT1 Appendix)","relationship_id":"relationship--b0220134-2033-4261-9b1d-e94abd691476","references":[{"source_name":"Mandiant APT1 Appendix","description":"Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.","url":"https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf"}]},{"id":"S0020","name":"China Chopper","url":"https://attack.mitre.org/software/S0020","kind":"malware","description":"[China Chopper](https://attack.mitre.org/software/S0020)'s server component can download remote files.(Citation: FireEye Periscope March 2018)(Citation: Lee 2013)(Citation: NCSC Joint Report Public Tools)(Citation: Rapid7 HAFNIUM Mar 2021)(Citation: Kaspersky ToddyCat June 2022)","relationship_id":"relationship--30da0c3d-8767-4828-b50d-181d9a89b9a8","references":[{"source_name":"Kaspersky ToddyCat June 2022","description":"Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.","url":"https://securelist.com/toddycat/106799/"},{"source_name":"Rapid7 HAFNIUM Mar 2021","description":"Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.","url":"https://www.rapid7.com/blog/post/2021/03/23/defending-against-the-zero-day-analyzing-attacker-behavior-post-exploitation-of-microsoft-exchange/"},{"source_name":"FireEye Periscope March 2018","description":"FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.","url":"https://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese-espionage-group-targeting-maritime-and-engineering-industries.html"},{"source_name":"Lee 2013","description":"Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015.","url":"https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-i.html"},{"source_name":"NCSC Joint Report Public Tools","description":"The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.","url":"https://www.ncsc.gov.uk/report/joint-report-on-publicly-available-hacking-tools"}]},{"id":"S0022","name":"Uroburos","url":"https://attack.mitre.org/software/S0022","kind":"malware","description":"[Uroburos](https://attack.mitre.org/software/S0022) can use a `Put` command to write files to an infected machine.(Citation: Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023)","relationship_id":"relationship--b107d35b-fa2b-4dcb-844e-cacaf15f9982","references":[{"source_name":"Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023","description":"FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.","url":"https://www.cisa.gov/sites/default/files/2023-05/aa23-129a_snake_malware_2.pdf"}]},{"id":"S0023","name":"CHOPSTICK","url":"https://attack.mitre.org/software/S0023","kind":"malware","description":"[CHOPSTICK](https://attack.mitre.org/software/S0023) is capable of performing remote file transmission.(Citation: Crowdstrike DNC June 2016)","relationship_id":"relationship--731710ae-a6b9-47b7-b8b2-8526ce60be2f","references":[{"source_name":"Crowdstrike DNC June 2016","description":"Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.","url":"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"}]},{"id":"S0024","name":"Dyre","url":"https://attack.mitre.org/software/S0024","kind":"malware","description":"[Dyre](https://attack.mitre.org/software/S0024) has a command to download and executes additional files.(Citation: Symantec Dyre June 2015)","relationship_id":"relationship--47cd42b3-1a19-415f-8522-a601268d8017","references":[{"source_name":"Symantec Dyre June 2015","description":"Symantec Security Response. (2015, June 23). Dyre: Emerging threat on financial fraud landscape. Retrieved August 23, 2018.","url":"http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/dyre-emerging-threat.pdf"}]},{"id":"S0032","name":"gh0st RAT","url":"https://attack.mitre.org/software/S0032","kind":"malware","description":"[gh0st RAT](https://attack.mitre.org/software/S0032) can download files to the victim’s machine.(Citation: Nccgroup Gh0st April 2018)(Citation: Gh0stRAT ATT March 2019)","relationship_id":"relationship--33a382a9-ebb3-48d9-bb7e-394a27783668","references":[{"source_name":"Nccgroup Gh0st April 2018","description":"Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.","url":"https://research.nccgroup.com/2018/04/17/decoding-network-data-from-a-gh0st-rat-variant/"},{"source_name":"Gh0stRAT ATT March 2019","description":"Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.","url":"https://cybersecurity.att.com/blogs/labs-research/the-odd-case-of-a-gh0strat-variant"}]},{"id":"S0042","name":"LOWBALL","url":"https://attack.mitre.org/software/S0042","kind":"malware","description":"[LOWBALL](https://attack.mitre.org/software/S0042) uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the [LOWBALL](https://attack.mitre.org/software/S0042) malware.(Citation: FireEye admin@338)","relationship_id":"relationship--25cb2c8f-79d2-4157-8329-fb86caaca0c3","references":[{"source_name":"FireEye admin@338","description":"FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.","url":"https://www.fireeye.com/blog/threat-research/2015/11/china-based-threat.html"}]},{"id":"S0044","name":"JHUHUGIT","url":"https://attack.mitre.org/software/S0044","kind":"malware","description":"[JHUHUGIT](https://attack.mitre.org/software/S0044) can retrieve an additional payload from its C2 server.(Citation: ESET Sednit Part 1)(Citation: Unit 42 Sofacy Feb 2018) [JHUHUGIT](https://attack.mitre.org/software/S0044) has a command to download files to the victim’s machine.(Citation: Talos Seduploader Oct 2017)","relationship_id":"relationship--f39d9e4d-b4f9-4c12-aa8e-a44f8550b57f","references":[{"source_name":"ESET Sednit Part 1","description":"ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.","url":"http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf"},{"source_name":"Unit 42 Sofacy Feb 2018","description":"Lee, B, et al. (2018, February 28). Sofacy Attacks Multiple Government Entities. Retrieved March 15, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/02/unit42-sofacy-attacks-multiple-government-entities/"},{"source_name":"Talos Seduploader Oct 2017","description":"Mercer, W., et al. (2017, October 22). \"Cyber Conflict\" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.","url":"https://blog.talosintelligence.com/2017/10/cyber-conflict-decoy-document.html"}]},{"id":"S0051","name":"MiniDuke","url":"https://attack.mitre.org/software/S0051","kind":"malware","description":"[MiniDuke](https://attack.mitre.org/software/S0051) can download additional encrypted backdoors onto the victim via GIF files.(Citation: Securelist MiniDuke Feb 2013)(Citation: ESET Dukes October 2019)","relationship_id":"relationship--67b49860-e1e4-4b56-bf83-108c4ac25e5c","references":[{"source_name":"ESET Dukes October 2019","description":"Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf"},{"source_name":"Securelist MiniDuke Feb 2013","description":"Kaspersky Lab's Global Research & Analysis Team. (2013, February 27). The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20170630181406/https://cdn.securelist.com/files/2014/07/themysteryofthepdf0-dayassemblermicrobackdoor.pdf"}]},{"id":"S0053","name":"SeaDuke","url":"https://attack.mitre.org/software/S0053","kind":"malware","description":"[SeaDuke](https://attack.mitre.org/software/S0053) is capable of uploading and downloading files.(Citation: Unit 42 SeaDuke 2015)","relationship_id":"relationship--5abaaa8f-19c7-448f-9e5a-66f1cbf412f9","references":[{"source_name":"Unit 42 SeaDuke 2015","description":"Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.","url":"http://researchcenter.paloaltonetworks.com/2015/07/unit-42-technical-analysis-seaduke/"}]},{"id":"S0054","name":"CloudDuke","url":"https://attack.mitre.org/software/S0054","kind":"malware","description":"[CloudDuke](https://attack.mitre.org/software/S0054) downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.(Citation: F-Secure The Dukes)","relationship_id":"relationship--800825f5-6e74-43ad-a732-476fdf471225","references":[{"source_name":"F-Secure The Dukes","description":"F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.","url":"https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf"}]},{"id":"S0055","name":"RARSTONE","url":"https://attack.mitre.org/software/S0055","kind":"malware","description":"[RARSTONE](https://attack.mitre.org/software/S0055) downloads its backdoor component from a C2 server and loads it directly into memory.(Citation: Aquino RARSTONE)","relationship_id":"relationship--4bf364ad-1e9c-4860-93c0-241da4c81068","references":[{"source_name":"Aquino RARSTONE","description":"Aquino, M. (2013, June 13). RARSTONE Found In Targeted Attacks. Retrieved December 17, 2015.","url":"http://blog.trendmicro.com/trendlabs-security-intelligence/rarstone-found-in-targeted-attacks/"}]},{"id":"S0070","name":"HTTPBrowser","url":"https://attack.mitre.org/software/S0070","kind":"malware","description":"[HTTPBrowser](https://attack.mitre.org/software/S0070) is capable of writing a file to the compromised system from the C2 server.(Citation: Dell TG-3390)","relationship_id":"relationship--0e12d7d1-5c46-4314-97fb-263853eed6af","references":[{"source_name":"Dell TG-3390","description":"Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.","url":"https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-cyberespionage"}]},{"id":"S0074","name":"Sakula","url":"https://attack.mitre.org/software/S0074","kind":"malware","description":"[Sakula](https://attack.mitre.org/software/S0074) has the capability to download files.(Citation: Dell Sakula)","relationship_id":"relationship--33162cc2-a800-4d42-89bb-13ac1e75dfce","references":[{"source_name":"Dell Sakula","description":"Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.","url":"http://www.secureworks.com/cyber-threat-intelligence/threats/sakula-malware-family/"}]},{"id":"S0077","name":"CallMe","url":"https://attack.mitre.org/software/S0077","kind":"malware","description":"[CallMe](https://attack.mitre.org/software/S0077) has the capability to download a file to the victim from the C2 server.(Citation: Scarlet Mimic Jan 2016)","relationship_id":"relationship--bdd64378-e348-4156-8490-528392c6ea82","references":[{"source_name":"Scarlet Mimic Jan 2016","description":"Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.","url":"http://researchcenter.paloaltonetworks.com/2016/01/scarlet-mimic-years-long-espionage-targets-minority-activists/"}]},{"id":"S0078","name":"Psylo","url":"https://attack.mitre.org/software/S0078","kind":"malware","description":"[Psylo](https://attack.mitre.org/software/S0078) has a command to download a file to the system from its C2 server.(Citation: Scarlet Mimic Jan 2016)","relationship_id":"relationship--a1e74408-5c7b-4538-afd9-a01b23a92429","references":[{"source_name":"Scarlet Mimic Jan 2016","description":"Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.","url":"http://researchcenter.paloaltonetworks.com/2016/01/scarlet-mimic-years-long-espionage-targets-minority-activists/"}]},{"id":"S0079","name":"MobileOrder","url":"https://attack.mitre.org/software/S0079","kind":"malware","description":"[MobileOrder](https://attack.mitre.org/software/S0079) has a command to download a file from the C2 server to the victim mobile device's SD card.(Citation: Scarlet Mimic Jan 2016)","relationship_id":"relationship--56d858ef-2d62-4aa9-b050-699de9b048e9","references":[{"source_name":"Scarlet Mimic Jan 2016","description":"Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.","url":"http://researchcenter.paloaltonetworks.com/2016/01/scarlet-mimic-years-long-espionage-targets-minority-activists/"}]},{"id":"S0080","name":"Mivast","url":"https://attack.mitre.org/software/S0080","kind":"malware","description":"[Mivast](https://attack.mitre.org/software/S0080) has the capability to download and execute .exe files.(Citation: Symantec Backdoor.Mivast)","relationship_id":"relationship--d7699bcf-5732-40f5-a715-d430b00b043e","references":[{"source_name":"Symantec Backdoor.Mivast","description":"Stama, D.. (2015, February 6). Backdoor.Mivast. Retrieved February 15, 2016.","url":"http://www.symantec.com/security_response/writeup.jsp?docid=2015-020623-0740-99&tabid=2"}]},{"id":"S0081","name":"Elise","url":"https://attack.mitre.org/software/S0081","kind":"malware","description":"[Elise](https://attack.mitre.org/software/S0081) can download additional files from the C2 server for execution.(Citation: Accenture Dragonfish Jan 2018)","relationship_id":"relationship--138c4559-eae3-49a2-baea-b9549aef881c","references":[{"source_name":"Accenture Dragonfish Jan 2018","description":"Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20190508165226/https://www.accenture.com/t20180127T003755Z_w_/us-en/_acnmedia/PDF-46/Accenture-Security-Dragonfish-Threat-Analysis.pdf"}]},{"id":"S0082","name":"Emissary","url":"https://attack.mitre.org/software/S0082","kind":"malware","description":"[Emissary](https://attack.mitre.org/software/S0082) has the capability to download files from the C2 server.(Citation: Lotus Blossom Dec 2015)","relationship_id":"relationship--85ca1e00-24c4-403e-8aff-9890f91e9b78","references":[{"source_name":"Lotus Blossom Dec 2015","description":"Falcone, R. and Miller-Osborn, J.. (2015, December 18). Attack on French Diplomat Linked to Operation Lotus Blossom. Retrieved February 15, 2016.","url":"http://researchcenter.paloaltonetworks.com/2015/12/attack-on-french-diplomat-linked-to-operation-lotus-blossom/"}]},{"id":"S0083","name":"Misdat","url":"https://attack.mitre.org/software/S0083","kind":"malware","description":"[Misdat](https://attack.mitre.org/software/S0083) is capable of downloading files from the C2.(Citation: Cylance Dust Storm)","relationship_id":"relationship--ae3be82b-3d54-4be8-939b-e074a2cea170","references":[{"source_name":"Cylance Dust Storm","description":"Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.","url":"https://s7d2.scene7.com/is/content/cylance/prod/cylance-web/en-us/resources/knowledge-center/resource-library/reports/Op_Dust_Storm_Report.pdf"}]},{"id":"S0084","name":"Mis-Type","url":"https://attack.mitre.org/software/S0084","kind":"malware","description":"[Mis-Type](https://attack.mitre.org/software/S0084) has downloaded additional malware and files onto a compromised host.(Citation: Cylance Dust Storm)","relationship_id":"relationship--424b60eb-a6d1-405f-8f95-648fd6d52658","references":[{"source_name":"Cylance Dust Storm","description":"Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.","url":"https://s7d2.scene7.com/is/content/cylance/prod/cylance-web/en-us/resources/knowledge-center/resource-library/reports/Op_Dust_Storm_Report.pdf"}]},{"id":"S0085","name":"S-Type","url":"https://attack.mitre.org/software/S0085","kind":"malware","description":"[S-Type](https://attack.mitre.org/software/S0085) can download additional files onto a compromised host.(Citation: Cylance Dust Storm)","relationship_id":"relationship--4a42e063-e5c1-4408-9634-fe2fe8af76b5","references":[{"source_name":"Cylance Dust Storm","description":"Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.","url":"https://s7d2.scene7.com/is/content/cylance/prod/cylance-web/en-us/resources/knowledge-center/resource-library/reports/Op_Dust_Storm_Report.pdf"}]},{"id":"S0086","name":"ZLib","url":"https://attack.mitre.org/software/S0086","kind":"malware","description":"[ZLib](https://attack.mitre.org/software/S0086) has the ability to download files.(Citation: Cylance Dust Storm)","relationship_id":"relationship--2025480a-6d91-4ef5-a6ea-cc025c8aecfb","references":[{"source_name":"Cylance Dust Storm","description":"Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.","url":"https://s7d2.scene7.com/is/content/cylance/prod/cylance-web/en-us/resources/knowledge-center/resource-library/reports/Op_Dust_Storm_Report.pdf"}]},{"id":"S0087","name":"Hi-Zor","url":"https://attack.mitre.org/software/S0087","kind":"malware","description":"[Hi-Zor](https://attack.mitre.org/software/S0087) has the ability to upload and download files from its C2 server.(Citation: Fidelis INOCNATION)","relationship_id":"relationship--18572125-3439-4f7c-92c8-d787913dc989","references":[{"source_name":"Fidelis INOCNATION","description":"Fidelis Cybersecurity. (2015, December 16). Fidelis Threat Advisory #1020: Dissecting the Malware Involved in the INOCNATION Campaign. Retrieved November 17, 2024.","url":"https://fidelissecurity.com/resource/report/fidelis-threat-advisory-1020-dissecting-the-malware-involved-in-the-inocnation-campaign/"}]},{"id":"S0088","name":"Kasidet","url":"https://attack.mitre.org/software/S0088","kind":"malware","description":"[Kasidet](https://attack.mitre.org/software/S0088) has the ability to download and execute additional files.(Citation: Zscaler Kasidet)","relationship_id":"relationship--c39e878e-a496-4271-9998-2d5c9511e0a4","references":[{"source_name":"Zscaler Kasidet","description":"Yadav, A., et al. (2016, January 29). Malicious Office files dropping Kasidet and Dridex. Retrieved March 24, 2016.","url":"http://research.zscaler.com/2016/01/malicious-office-files-dropping-kasidet.html"}]},{"id":"S0092","name":"Agent.btz","url":"https://attack.mitre.org/software/S0092","kind":"malware","description":"[Agent.btz](https://attack.mitre.org/software/S0092) attempts to download an encrypted binary from a specified domain.(Citation: ThreatExpert Agent.btz)","relationship_id":"relationship--fcc12c1f-1a46-49f4-a872-99cb97968bf0","references":[{"source_name":"ThreatExpert Agent.btz","description":"Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016.","url":"http://blog.threatexpert.com/2008/11/agentbtz-threat-that-hit-pentagon.html"}]},{"id":"S0093","name":"Backdoor.Oldrea","url":"https://attack.mitre.org/software/S0093","kind":"malware","description":"[Backdoor.Oldrea](https://attack.mitre.org/software/S0093) can download additional modules from C2.(Citation: Gigamon Berserk Bear October 2021)","relationship_id":"relationship--984a898c-f469-4e7c-94c6-bf512ec69938","references":[{"source_name":"Gigamon Berserk Bear October 2021","description":"Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.","url":"https://vblocalhost.com/uploads/VB2021-Slowik.pdf"}]},{"id":"S0094","name":"Trojan.Karagany","url":"https://attack.mitre.org/software/S0094","kind":"malware","description":"[Trojan.Karagany](https://attack.mitre.org/software/S0094) can upload, download, and execute files on the victim.(Citation: Symantec Dragonfly)(Citation: Secureworks Karagany July 2019)","relationship_id":"relationship--7282eabe-73e0-4a10-824b-f18df7f892e2","references":[{"source_name":"Symantec Dragonfly","description":"Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.","url":"https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=7382dce7-0260-4782-84cc-890971ed3f17&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments"},{"source_name":"Secureworks Karagany July 2019","description":"Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.","url":"https://www.secureworks.com/research/updated-karagany-malware-targets-energy-sector"}]},{"id":"S0095","name":"ftp","url":"https://attack.mitre.org/software/S0095","kind":"tool","description":"[ftp](https://attack.mitre.org/software/S0095) may be abused by adversaries to transfer tools or files from an external system into a compromised environment.(Citation: Microsoft FTP)(Citation: Linux FTP)","relationship_id":"relationship--bb4592cf-4e26-4999-bb6d-5120e0695bfa","references":[{"source_name":"Microsoft FTP","description":"Microsoft. (2021, July 21). ftp. Retrieved February 25, 2022.","url":"https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/ftp"},{"source_name":"Linux FTP","description":"N/A. (n.d.). ftp(1) - Linux man page. Retrieved February 25, 2022.","url":"https://linux.die.net/man/1/ftp"}]},{"id":"S0106","name":"cmd","url":"https://attack.mitre.org/software/S0106","kind":"tool","description":"[cmd](https://attack.mitre.org/software/S0106) can be used to copy files to/from a remotely connected external system.(Citation: TechNet Copy)","relationship_id":"relationship--2c13a056-b82d-4f56-a530-8562e0e9b038","references":[{"source_name":"TechNet Copy","description":"Microsoft. (n.d.). Copy. Retrieved April 26, 2016.","url":"https://technet.microsoft.com/en-us/library/bb490886.aspx"}]},{"id":"S0109","name":"WEBC2","url":"https://attack.mitre.org/software/S0109","kind":"malware","description":"[WEBC2](https://attack.mitre.org/software/S0109) can download and execute a file.(Citation: Mandiant APT1)","relationship_id":"relationship--a33a1a9c-c8d1-45f5-ad29-4a4188e5a54b","references":[{"source_name":"Mandiant APT1","description":"Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.","url":"https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"}]},{"id":"S0115","name":"Crimson","url":"https://attack.mitre.org/software/S0115","kind":"malware","description":"[Crimson](https://attack.mitre.org/software/S0115) contains a command to retrieve files from its C2 server.(Citation: Proofpoint Operation Transparent Tribe March 2016)(Citation: Kaspersky Transparent Tribe August 2020)(Citation: Cisco Talos Transparent Tribe Education Campaign July 2022)","relationship_id":"relationship--a0186caf-482a-4f2a-bf2f-cac9fc51244a","references":[{"source_name":"Kaspersky Transparent Tribe August 2020","description":"Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.","url":"https://securelist.com/transparent-tribe-part-1/98127/"},{"source_name":"Proofpoint Operation Transparent Tribe March 2016","description":"Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.","url":"https://www.proofpoint.com/sites/default/files/proofpoint-operation-transparent-tribe-threat-insight-en.pdf"},{"source_name":"Cisco Talos Transparent Tribe Education Campaign July 2022","description":"N. Baisini. (2022, July 13). Transparent Tribe begins targeting education sector in latest campaign. Retrieved September 22, 2022.","url":"https://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html"}]},{"id":"S0118","name":"Nidiran","url":"https://attack.mitre.org/software/S0118","kind":"malware","description":"[Nidiran](https://attack.mitre.org/software/S0118) can download and execute files.(Citation: Symantec Backdoor.Nidiran)","relationship_id":"relationship--438cae9c-cb03-4db9-ae59-24ed27147725","references":[{"source_name":"Symantec Backdoor.Nidiran","description":"Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2015-120123-5521-99"}]},{"id":"S0124","name":"Pisloader","url":"https://attack.mitre.org/software/S0124","kind":"malware","description":"[Pisloader](https://attack.mitre.org/software/S0124) has a command to upload a file to the victim machine.(Citation: Palo Alto DNS Requests)","relationship_id":"relationship--ce4707f0-d5b8-4dd6-b5ab-cf1483dd236f","references":[{"source_name":"Palo Alto DNS Requests","description":"Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.","url":"http://researchcenter.paloaltonetworks.com/2016/05/unit42-new-wekby-attacks-use-dns-requests-as-command-and-control-mechanism/"}]},{"id":"S0125","name":"Remsec","url":"https://attack.mitre.org/software/S0125","kind":"malware","description":"[Remsec](https://attack.mitre.org/software/S0125) contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.(Citation: Symantec Remsec IOCs)(Citation: Kaspersky ProjectSauron Technical Analysis)","relationship_id":"relationship--820c50f3-65e8-4a3a-a71a-e079ae8badad","references":[{"source_name":"Symantec Remsec IOCs","description":"Symantec Security Response. (2016, August 8). Backdoor.Remsec indicators of compromise. Retrieved August 17, 2016.","url":"http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/Symantec_Remsec_IOCs.pdf"},{"source_name":"Kaspersky ProjectSauron Technical Analysis","description":"Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Technical Analysis. Retrieved August 17, 2016.","url":"https://securelist.com/files/2016/07/The-ProjectSauron-APT_Technical_Analysis_KL.pdf"}]},{"id":"S0128","name":"BADNEWS","url":"https://attack.mitre.org/software/S0128","kind":"malware","description":"[BADNEWS](https://attack.mitre.org/software/S0128) is capable of downloading additional files through C2 channels, including a new version of itself.(Citation: Forcepoint Monsoon)(Citation: PaloAlto Patchwork Mar 2018)(Citation: TrendMicro Patchwork Dec 2017)","relationship_id":"relationship--b3f53743-4bd9-47a6-bf41-6f7786bbdc87","references":[{"source_name":"Forcepoint Monsoon","description":"Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.","url":"https://www.forcepoint.com/sites/default/files/resources/files/forcepoint-security-labs-monsoon-analysis-report.pdf"},{"source_name":"PaloAlto Patchwork Mar 2018","description":"Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/03/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"},{"source_name":"TrendMicro Patchwork Dec 2017","description":"Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.","url":"https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-cyberespionage-group.pdf"}]},{"id":"S0130","name":"Unknown Logger","url":"https://attack.mitre.org/software/S0130","kind":"malware","description":"[Unknown Logger](https://attack.mitre.org/software/S0130) is capable of downloading remote files.(Citation: Forcepoint Monsoon)","relationship_id":"relationship--321544e0-902c-443e-adf9-d7e78f0e4d13","references":[{"source_name":"Forcepoint Monsoon","description":"Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.","url":"https://www.forcepoint.com/sites/default/files/resources/files/forcepoint-security-labs-monsoon-analysis-report.pdf"}]},{"id":"S0132","name":"H1N1","url":"https://attack.mitre.org/software/S0132","kind":"malware","description":"[H1N1](https://attack.mitre.org/software/S0132) contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.(Citation: Cisco H1N1 Part 2)","relationship_id":"relationship--a7e5ffbc-d123-4f62-88eb-36b32656cd35","references":[{"source_name":"Cisco H1N1 Part 2","description":"Reynolds, J.. (2016, September 14). H1N1: Technical analysis reveals new capabilities – part 2. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20231210122239/https://blogs.cisco.com/security/h1n1-technical-analysis-reveals-new-capabilities-part-2"}]},{"id":"S0134","name":"Downdelph","url":"https://attack.mitre.org/software/S0134","kind":"malware","description":"After downloading its main config file, [Downdelph](https://attack.mitre.org/software/S0134) downloads multiple payloads from C2 servers.(Citation: ESET Sednit Part 3)","relationship_id":"relationship--9c7a9bd0-4f52-4c10-8e79-3b6e72d431d1","references":[{"source_name":"ESET Sednit Part 3","description":"ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.","url":"http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part3.pdf"}]},{"id":"S0137","name":"CORESHELL","url":"https://attack.mitre.org/software/S0137","kind":"malware","description":"[CORESHELL](https://attack.mitre.org/software/S0137) downloads another dropper from its C2 server.(Citation: FireEye APT28)","relationship_id":"relationship--e41ab3e7-2b69-4461-a693-e53a24c9ab59","references":[{"source_name":"FireEye APT28","description":"FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.","url":"https://web.archive.org/web/20151022204649/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf"}]},{"id":"S0139","name":"PowerDuke","url":"https://attack.mitre.org/software/S0139","kind":"malware","description":"[PowerDuke](https://attack.mitre.org/software/S0139) has a command to download a file.(Citation: Volexity PowerDuke November 2016)","relationship_id":"relationship--8ef27cd6-3909-4174-b57c-3dbe3061a6dd","references":[{"source_name":"Volexity PowerDuke November 2016","description":"Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.","url":"https://www.volexity.com/blog/2016/11/09/powerduke-post-election-spear-phishing-campaigns-targeting-think-tanks-and-ngos/"}]},{"id":"S0140","name":"Shamoon","url":"https://attack.mitre.org/software/S0140","kind":"malware","description":"[Shamoon](https://attack.mitre.org/software/S0140) can download an executable to run on the victim.(Citation: Palo Alto Shamoon Nov 2016)","relationship_id":"relationship--3ded5760-4f2e-41f5-a2c5-f2b39eaf5733","references":[{"source_name":"Palo Alto Shamoon Nov 2016","description":"Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.","url":"http://researchcenter.paloaltonetworks.com/2016/11/unit42-shamoon-2-return-disttrack-wiper/"}]},{"id":"S0141","name":"Winnti for Windows","url":"https://attack.mitre.org/software/S0141","kind":"malware","description":"The [Winnti for Windows](https://attack.mitre.org/software/S0141) dropper can place malicious payloads on targeted systems.(Citation: Novetta Winnti April 2015)","relationship_id":"relationship--ace0d0ba-7ee5-46cd-be08-2b33d217a13d","references":[{"source_name":"Novetta Winnti April 2015","description":"Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.","url":"https://web.archive.org/web/20150412223949/http://www.novetta.com/wp-content/uploads/2015/04/novetta_winntianalysis.pdf"}]},{"id":"S0144","name":"ChChes","url":"https://attack.mitre.org/software/S0144","kind":"malware","description":"[ChChes](https://attack.mitre.org/software/S0144) is capable of downloading files, including additional modules.(Citation: Palo Alto menuPass Feb 2017)(Citation: JPCERT ChChes Feb 2017)(Citation: FireEye APT10 April 2017)","relationship_id":"relationship--92c901ce-5edb-417f-8af5-d569203e241c","references":[{"source_name":"FireEye APT10 April 2017","description":"FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.","url":"https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html"},{"source_name":"Palo Alto menuPass Feb 2017","description":"Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.","url":"http://researchcenter.paloaltonetworks.com/2017/02/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations/"},{"source_name":"JPCERT ChChes Feb 2017","description":"Nakamura, Y.. (2017, February 17). ChChes - Malware that Communicates with C&C Servers Using Cookie Headers. Retrieved November 17, 2024.","url":"https://blogs.jpcert.or.jp/en/2017/02/chches-malware--93d6.html"}]},{"id":"S0145","name":"POWERSOURCE","url":"https://attack.mitre.org/software/S0145","kind":"malware","description":"[POWERSOURCE](https://attack.mitre.org/software/S0145) has been observed being used to download [TEXTMATE](https://attack.mitre.org/software/S0146) and the Cobalt Strike Beacon payload onto victims.(Citation: FireEye FIN7 March 2017)","relationship_id":"relationship--d04d6101-f6f6-42a2-8679-351956b75228","references":[{"source_name":"FireEye FIN7 March 2017","description":"Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.","url":"https://web.archive.org/web/20180808125108/https:/www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html"}]},{"id":"S0147","name":"Pteranodon","url":"https://attack.mitre.org/software/S0147","kind":"malware","description":"[Pteranodon](https://attack.mitre.org/software/S0147) can download and execute additional files.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: Symantec Shuckworm January 2022)(Citation: Unit 42 Gamaredon February 2022)","relationship_id":"relationship--35ae6625-8563-493c-8950-1230bd0fd122","references":[{"source_name":"Palo Alto Gamaredon Feb 2017","description":"Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.","url":"https://researchcenter.paloaltonetworks.com/2017/02/unit-42-title-gamaredon-group-toolset-evolution/"},{"source_name":"Symantec Shuckworm January 2022","description":"Symantec. (2022, January 31). Shuckworm Continues Cyber-Espionage Attacks Against Ukraine. Retrieved February 17, 2022.","url":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-gamaredon-espionage-ukraine"},{"source_name":"Unit 42 Gamaredon February 2022","description":"Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.","url":"https://unit42.paloaltonetworks.com/gamaredon-primitive-bear-ukraine-update-2021/"}]},{"id":"S0148","name":"RTM","url":"https://attack.mitre.org/software/S0148","kind":"malware","description":"[RTM](https://attack.mitre.org/software/S0148) can download additional files.(Citation: ESET RTM Feb 2017)(Citation: Unit42 Redaman January 2019)","relationship_id":"relationship--c839344c-a96d-412f-bded-5ac7c8fd446a","references":[{"source_name":"ESET RTM Feb 2017","description":"Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.","url":"https://www.welivesecurity.com/wp-content/uploads/2017/02/Read-The-Manual.pdf"},{"source_name":"Unit42 Redaman January 2019","description":"Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.","url":"https://unit42.paloaltonetworks.com/russian-language-malspam-pushing-redaman-banking-malware/"}]},{"id":"S0150","name":"POSHSPY","url":"https://attack.mitre.org/software/S0150","kind":"malware","description":"[POSHSPY](https://attack.mitre.org/software/S0150) downloads and executes additional PowerShell code and Windows binaries.(Citation: FireEye POSHSPY April 2017)","relationship_id":"relationship--be31bf6d-ce4f-4620-8940-445f35ff90a7","references":[{"source_name":"FireEye POSHSPY April 2017","description":"Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.","url":"https://www.fireeye.com/blog/threat-research/2017/03/dissecting_one_ofap.html"}]},{"id":"S0153","name":"RedLeaves","url":"https://attack.mitre.org/software/S0153","kind":"malware","description":"[RedLeaves](https://attack.mitre.org/software/S0153) is capable of downloading a file from a specified URL.(Citation: PWC Cloud Hopper Technical Annex April 2017)","relationship_id":"relationship--f4902ad9-b1bb-41ce-a448-55e2d9437503","references":[{"source_name":"PWC Cloud Hopper Technical Annex April 2017","description":"PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.","url":"https://www.pwc.co.uk/cyber-security/pdf/pwc-uk-operation-cloud-hopper-technical-annex-april-2017.pdf"}]},{"id":"S0154","name":"Cobalt Strike","url":"https://attack.mitre.org/software/S0154","kind":"malware","description":"[Cobalt Strike](https://attack.mitre.org/software/S0154) can deliver additional payloads to victim machines.(Citation: Talos Cobalt Strike September 2020)(Citation: Cobalt Strike Manual 4.3 November 2020)","relationship_id":"relationship--cecb2ce6-cb40-453d-9487-9f59f156a98c","references":[{"source_name":"Talos Cobalt Strike September 2020","description":"Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.","url":"https://web.archive.org/web/20210219195905/https://talos-intelligence-site.s3.amazonaws.com/production/document_files/files/000/095/031/original/Talos_Cobalt_Strike.pdf"},{"source_name":"Cobalt Strike Manual 4.3 November 2020","description":"Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.","url":"https://web.archive.org/web/20210708035426/https://www.cobaltstrike.com/downloads/csmanual43.pdf"}]},{"id":"S0160","name":"certutil","url":"https://attack.mitre.org/software/S0160","kind":"tool","description":"[certutil](https://attack.mitre.org/software/S0160) can be used to download files from a given URL.(Citation: TechNet Certutil)(Citation: LOLBAS Certutil)","relationship_id":"relationship--73f5c564-53b1-48bc-8cab-32fa4a608672","references":[{"source_name":"TechNet Certutil","description":"Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.","url":"https://technet.microsoft.com/library/cc732443.aspx"},{"source_name":"LOLBAS Certutil","description":"LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019.","url":"https://lolbas-project.github.io/lolbas/Binaries/Certutil/"}]},{"id":"S0164","name":"TDTESS","url":"https://attack.mitre.org/software/S0164","kind":"malware","description":"[TDTESS](https://attack.mitre.org/software/S0164) has a command to download and execute an additional file.(Citation: ClearSky Wilted Tulip July 2017)","relationship_id":"relationship--af4d45e1-1aa4-444c-b176-31df7aaf9374","references":[{"source_name":"ClearSky Wilted Tulip July 2017","description":"ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.","url":"http://www.clearskysec.com/wp-content/uploads/2017/07/Operation_Wilted_Tulip.pdf"}]},{"id":"S0166","name":"RemoteCMD","url":"https://attack.mitre.org/software/S0166","kind":"malware","description":"[RemoteCMD](https://attack.mitre.org/software/S0166) copies a file over to the remote system before execution.(Citation: Symantec Buckeye)","relationship_id":"relationship--b3831788-f18f-4315-997e-275e425c0d31","references":[{"source_name":"Symantec Buckeye","description":"Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.","url":"https://web.archive.org/web/20160910124439/http://www.symantec.com/connect/blogs/buckeye-cyberespionage-group-shifts-gaze-us-hong-kong"}]},{"id":"S0168","name":"Gazer","url":"https://attack.mitre.org/software/S0168","kind":"malware","description":"[Gazer](https://attack.mitre.org/software/S0168) can execute a task to download a file.(Citation: ESET Gazer Aug 2017)(Citation: Securelist WhiteBear Aug 2017)","relationship_id":"relationship--8db1b5bd-8f0c-4c13-8667-c83713ce799e","references":[{"source_name":"ESET Gazer Aug 2017","description":"ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.","url":"https://www.welivesecurity.com/wp-content/uploads/2017/08/eset-gazer.pdf"},{"source_name":"Securelist WhiteBear Aug 2017","description":"Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.","url":"https://securelist.com/introducing-whitebear/81638/"}]},{"id":"S0170","name":"Helminth","url":"https://attack.mitre.org/software/S0170","kind":"malware","description":"[Helminth](https://attack.mitre.org/software/S0170) can download additional files.(Citation: Palo Alto OilRig May 2016)","relationship_id":"relationship--86b2980a-dd9f-4553-8f65-69f75f0f4332","references":[{"source_name":"Palo Alto OilRig May 2016","description":"Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.","url":"http://researchcenter.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/"}]},{"id":"S0171","name":"Felismus","url":"https://attack.mitre.org/software/S0171","kind":"malware","description":"[Felismus](https://attack.mitre.org/software/S0171) can download files from remote servers.(Citation: Forcepoint Felismus Mar 2017)","relationship_id":"relationship--e9011839-ca57-434d-a0cc-007594247110","references":[{"source_name":"Forcepoint Felismus Mar 2017","description":"Somerville, L. and Toro, A. (2017, March 30). Playing Cat & Mouse: Introducing the Felismus Malware. Retrieved November 16, 2017.","url":"https://blogs.forcepoint.com/security-labs/playing-cat-mouse-introducing-felismus-malware"}]},{"id":"S0180","name":"Volgmer","url":"https://attack.mitre.org/software/S0180","kind":"malware","description":"[Volgmer](https://attack.mitre.org/software/S0180) can download remote files and additional payloads to the victim's machine.(Citation: US-CERT Volgmer Nov 2017)(Citation: US-CERT Volgmer 2 Nov 2017)(Citation: Symantec Volgmer Aug 2014)","relationship_id":"relationship--720cc0d6-9285-425b-bda2-3bdd59b4ea8f","references":[{"source_name":"US-CERT Volgmer 2 Nov 2017","description":"US-CERT. (2017, November 01). Malware Analysis Report (MAR) - 10135536-D. Retrieved July 16, 2018.","url":"https://www.us-cert.gov/sites/default/files/publications/MAR-10135536-D_WHITE_S508C.PDF"},{"source_name":"US-CERT Volgmer Nov 2017","description":"US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.","url":"https://www.us-cert.gov/ncas/alerts/TA17-318B"},{"source_name":"Symantec Volgmer Aug 2014","description":"Yagi, J. (2014, August 24). Trojan.Volgmer. Retrieved July 16, 2018.","url":"https://web.archive.org/web/20181126143456/https://www.symantec.com/security-center/writeup/2014-081811-3237-99?tabid=2"}]},{"id":"S0184","name":"POWRUNER","url":"https://attack.mitre.org/software/S0184","kind":"malware","description":"[POWRUNER](https://attack.mitre.org/software/S0184) can download or upload files from its C2 server.(Citation: FireEye APT34 Dec 2017)","relationship_id":"relationship--c4d77981-d2e4-4a12-8e52-5b7464cdc8fd","references":[{"source_name":"FireEye APT34 Dec 2017","description":"Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.","url":"https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html"}]},{"id":"S0185","name":"SEASHARPEE","url":"https://attack.mitre.org/software/S0185","kind":"malware","description":"[SEASHARPEE](https://attack.mitre.org/software/S0185) can download remote files onto victims.(Citation: FireEye APT34 Webinar Dec 2017)","relationship_id":"relationship--04ecc705-0027-4dda-85fe-d6ce028ef05e","references":[{"source_name":"FireEye APT34 Webinar Dec 2017","description":"Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.","url":"https://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east"}]},{"id":"S0187","name":"Daserf","url":"https://attack.mitre.org/software/S0187","kind":"malware","description":"[Daserf](https://attack.mitre.org/software/S0187) can download remote files.(Citation: Trend Micro Daserf Nov 2017)(Citation: Secureworks BRONZE BUTLER Oct 2017)","relationship_id":"relationship--24503815-4ac5-4d57-9e95-ebeb84e0c11b","references":[{"source_name":"Trend Micro Daserf Nov 2017","description":"Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.","url":"http://blog.trendmicro.com/trendlabs-security-intelligence/redbaldknight-bronze-butler-daserf-backdoor-now-using-steganography/"},{"source_name":"Secureworks BRONZE BUTLER Oct 2017","description":"Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.","url":"https://www.secureworks.com/research/bronze-butler-targets-japanese-businesses"}]},{"id":"S0190","name":"BITSAdmin","url":"https://attack.mitre.org/software/S0190","kind":"tool","description":"[BITSAdmin](https://attack.mitre.org/software/S0190) can be used to create [BITS Jobs](https://attack.mitre.org/techniques/T1197) to upload and/or download files.(Citation: Microsoft BITSAdmin)","relationship_id":"relationship--9edfa8b5-2e9f-4022-93b2-fd819156fe95","references":[{"source_name":"Microsoft BITSAdmin","description":"Microsoft. (n.d.). BITSAdmin Tool. Retrieved January 12, 2018.","url":"https://msdn.microsoft.com/library/aa362813.aspx"}]},{"id":"S0192","name":"Pupy","url":"https://attack.mitre.org/software/S0192","kind":"tool","description":"[Pupy](https://attack.mitre.org/software/S0192) can upload and download to/from a victim machine.(Citation: GitHub Pupy)","relationship_id":"relationship--151dd9ac-7e33-4580-a4a4-09f71fa73f51","references":[{"source_name":"GitHub Pupy","description":"Nicolas Verdier. (n.d.). Retrieved January 29, 2018.","url":"https://github.com/n1nj4sec/pupy"}]},{"id":"S0196","name":"PUNCHBUGGY","url":"https://attack.mitre.org/software/S0196","kind":"malware","description":"[PUNCHBUGGY](https://attack.mitre.org/software/S0196) can download additional files and payloads to compromised hosts.(Citation: FireEye Know Your Enemy FIN8 Aug 2016)(Citation: Morphisec ShellTea June 2019)","relationship_id":"relationship--8e7887b3-f622-4860-9bda-3f4ab6231393","references":[{"source_name":"FireEye Know Your Enemy FIN8 Aug 2016","description":"Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy:  New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.","url":"https://www2.fireeye.com/WBNR-Know-Your-Enemy-UNC622-Spear-Phishing.html"},{"source_name":"Morphisec ShellTea June 2019","description":"Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.","url":"http://blog.morphisec.com/security-alert-fin8-is-back"}]},{"id":"S0198","name":"NETWIRE","url":"https://attack.mitre.org/software/S0198","kind":"malware","description":"[NETWIRE](https://attack.mitre.org/software/S0198) can downloaded payloads from C2 to the compromised host.(Citation: FireEye NETWIRE March 2019)(Citation: Proofpoint NETWIRE December 2020)","relationship_id":"relationship--f4ea1985-0e88-488d-b7ed-ac294719738a","references":[{"source_name":"FireEye NETWIRE March 2019","description":"Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.","url":"https://www.mandiant.com/resources/blog/dissecting-netwire-phishing-campaigns-usage-process-hollowing"},{"source_name":"Proofpoint NETWIRE December 2020","description":"Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.","url":"https://www.proofpoint.com/us/blog/threat-insight/geofenced-netwire-campaigns"}]},{"id":"S0199","name":"TURNEDUP","url":"https://attack.mitre.org/software/S0199","kind":"malware","description":"[TURNEDUP](https://attack.mitre.org/software/S0199) is capable of downloading additional files.(Citation: FireEye APT33 Sept 2017)","relationship_id":"relationship--1251d1e2-21d3-48f2-a869-44507b34943a","references":[{"source_name":"FireEye APT33 Sept 2017","description":"O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.","url":"https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html"}]},{"id":"S0200","name":"Dipsind","url":"https://attack.mitre.org/software/S0200","kind":"malware","description":"[Dipsind](https://attack.mitre.org/software/S0200) can download remote files.(Citation: Microsoft PLATINUM April 2016)","relationship_id":"relationship--2a2b6def-5d29-41f7-b274-64bed33eb8ed","references":[{"source_name":"Microsoft PLATINUM April 2016","description":"Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.","url":"https://download.microsoft.com/download/2/2/5/225BFE3E-E1DE-4F5B-A77B-71200928D209/Platinum%20feature%20article%20-%20Targeted%20attacks%20in%20South%20and%20Southeast%20Asia%20April%202016.pdf"}]},{"id":"S0201","name":"JPIN","url":"https://attack.mitre.org/software/S0201","kind":"malware","description":"[JPIN](https://attack.mitre.org/software/S0201) can download files and upgrade itself.(Citation: Microsoft PLATINUM April 2016)","relationship_id":"relationship--74c1fa45-5ac3-47a0-a442-2cc5e89f7b4c","references":[{"source_name":"Microsoft PLATINUM April 2016","description":"Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.","url":"https://download.microsoft.com/download/2/2/5/225BFE3E-E1DE-4F5B-A77B-71200928D209/Platinum%20feature%20article%20-%20Targeted%20attacks%20in%20South%20and%20Southeast%20Asia%20April%202016.pdf"}]},{"id":"S0203","name":"Hydraq","url":"https://attack.mitre.org/software/S0203","kind":"malware","description":"[Hydraq](https://attack.mitre.org/software/S0203) creates a backdoor through which remote attackers can download files and additional malware components.(Citation: Symantec Trojan.Hydraq Jan 2010)(Citation: Symantec Hydraq Jan 2010)","relationship_id":"relationship--5d914544-0a93-43ba-b890-1f4a4fa818e8","references":[{"source_name":"Symantec Trojan.Hydraq Jan 2010","description":"Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.","url":"https://www.symantec.com/connect/blogs/trojanhydraq-incident"},{"source_name":"Symantec Hydraq Jan 2010","description":"Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2010-011114-1830-99"}]},{"id":"S0204","name":"Briba","url":"https://attack.mitre.org/software/S0204","kind":"malware","description":"[Briba](https://attack.mitre.org/software/S0204) downloads files onto infected hosts.(Citation: Symantec Briba May 2012)","relationship_id":"relationship--36755c7d-92bf-4851-91ef-f1bf41f27210","references":[{"source_name":"Symantec Briba May 2012","description":"Ladley, F. (2012, May 15). Backdoor.Briba. Retrieved February 21, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051515-2843-99"}]},{"id":"S0206","name":"Wiarp","url":"https://attack.mitre.org/software/S0206","kind":"malware","description":"[Wiarp](https://attack.mitre.org/software/S0206) creates a backdoor through which remote attackers can download files.(Citation: Symantec Wiarp May 2012)","relationship_id":"relationship--0f7e7dc5-ea9c-4d9e-9acd-5fa0dd25910a","references":[{"source_name":"Symantec Wiarp May 2012","description":"Zhou, R. (2012, May 15). Backdoor.Wiarp. Retrieved February 22, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051606-1005-99"}]},{"id":"S0207","name":"Vasport","url":"https://attack.mitre.org/software/S0207","kind":"malware","description":"[Vasport](https://attack.mitre.org/software/S0207) can download files.(Citation: Symantec Vasport May 2012)","relationship_id":"relationship--0e8a0760-f21e-4936-80a1-769c7ef61950","references":[{"source_name":"Symantec Vasport May 2012","description":"Zhou, R. (2012, May 15). Backdoor.Vasport. Retrieved February 22, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051606-5938-99"}]},{"id":"S0208","name":"Pasam","url":"https://attack.mitre.org/software/S0208","kind":"malware","description":"[Pasam](https://attack.mitre.org/software/S0208) creates a backdoor through which remote attackers can upload files.(Citation: Symantec Pasam May 2012)","relationship_id":"relationship--80383098-470f-4293-b4b1-90c4362be307","references":[{"source_name":"Symantec Pasam May 2012","description":"Mullaney, C. & Honda, H. (2012, May 4). Trojan.Pasam. Retrieved February 22, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-050412-4128-99"}]},{"id":"S0210","name":"Nerex","url":"https://attack.mitre.org/software/S0210","kind":"malware","description":"[Nerex](https://attack.mitre.org/software/S0210) creates a backdoor through which remote attackers can download files onto a compromised host.(Citation: Symantec Ristol May 2012)","relationship_id":"relationship--107e2686-a764-4ace-9200-43ead29ce579","references":[{"source_name":"Symantec Ristol May 2012","description":"Ladley, F. (2012, May 15). Backdoor.Ritsol. Retrieved February 23, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051515-3909-99"}]},{"id":"S0211","name":"Linfo","url":"https://attack.mitre.org/software/S0211","kind":"malware","description":"[Linfo](https://attack.mitre.org/software/S0211) creates a backdoor through which remote attackers can download files onto compromised hosts.(Citation: Symantec Linfo May 2012)","relationship_id":"relationship--5c08eb3a-d7a0-4ce0-97a2-496ea4c9f3ed","references":[{"source_name":"Symantec Linfo May 2012","description":"Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051605-2535-99"}]},{"id":"S0213","name":"DOGCALL","url":"https://attack.mitre.org/software/S0213","kind":"malware","description":"[DOGCALL](https://attack.mitre.org/software/S0213) can download and execute additional payloads.(Citation: Unit 42 Nokki Oct 2018)","relationship_id":"relationship--8f41386c-5760-409e-b8b4-513f3d791d9f","references":[{"source_name":"Unit 42 Nokki Oct 2018","description":"Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/10/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"id":"S0214","name":"HAPPYWORK","url":"https://attack.mitre.org/software/S0214","kind":"malware","description":"can download and execute a second-stage payload.(Citation: FireEye APT37 Feb 2018)","relationship_id":"relationship--72ac0ee1-24c0-4b4e-b96d-f42575ce9af8","references":[{"source_name":"FireEye APT37 Feb 2018","description":"FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf"}]},{"id":"S0215","name":"KARAE","url":"https://attack.mitre.org/software/S0215","kind":"malware","description":"[KARAE](https://attack.mitre.org/software/S0215) can upload and download files, including second-stage malware.(Citation: FireEye APT37 Feb 2018)","relationship_id":"relationship--2fa47765-a47e-430b-9a88-68db5795f557","references":[{"source_name":"FireEye APT37 Feb 2018","description":"FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf"}]},{"id":"S0217","name":"SHUTTERSPEED","url":"https://attack.mitre.org/software/S0217","kind":"malware","description":"[SHUTTERSPEED](https://attack.mitre.org/software/S0217) can download and execute an arbitary executable.(Citation: FireEye APT37 Feb 2018)","relationship_id":"relationship--c4cbbe25-bc29-406d-b92e-6e50ee4cd322","references":[{"source_name":"FireEye APT37 Feb 2018","description":"FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf"}]},{"id":"S0218","name":"SLOWDRIFT","url":"https://attack.mitre.org/software/S0218","kind":"malware","description":"[SLOWDRIFT](https://attack.mitre.org/software/S0218) downloads additional payloads.(Citation: FireEye APT37 Feb 2018)","relationship_id":"relationship--4c5ae895-9a08-40b6-a548-273a9f96ad5b","references":[{"source_name":"FireEye APT37 Feb 2018","description":"FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf"}]},{"id":"S0223","name":"POWERSTATS","url":"https://attack.mitre.org/software/S0223","kind":"malware","description":"[POWERSTATS](https://attack.mitre.org/software/S0223) can retrieve and execute additional [PowerShell](https://attack.mitre.org/techniques/T1059/001) payloads from the C2 server.(Citation: FireEye MuddyWater Mar 2018)","relationship_id":"relationship--ce7b27ac-fff6-4d3c-bceb-50c16f462552","references":[{"source_name":"FireEye MuddyWater Mar 2018","description":"Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.","url":"https://www.fireeye.com/blog/threat-research/2018/03/iranian-threat-group-updates-ttps-in-spear-phishing-campaign.html"}]},{"id":"S0226","name":"Smoke Loader","url":"https://attack.mitre.org/software/S0226","kind":"malware","description":"[Smoke Loader](https://attack.mitre.org/software/S0226) downloads a new version of itself once it has installed. It also downloads additional plugins.(Citation: Malwarebytes SmokeLoader 2016)","relationship_id":"relationship--4bb79228-9531-47c0-8e73-401e741593a8","references":[{"source_name":"Malwarebytes SmokeLoader 2016","description":"Hasherezade. (2016, September 12). Smoke Loader – downloader with a smokescreen still alive. Retrieved March 20, 2018.","url":"https://blog.malwarebytes.com/threat-analysis/2016/08/smoke-loader-downloader-with-a-smokescreen-still-alive/"}]},{"id":"S0228","name":"NanHaiShu","url":"https://attack.mitre.org/software/S0228","kind":"malware","description":"[NanHaiShu](https://attack.mitre.org/software/S0228) can download additional files from URLs.(Citation: Proofpoint Leviathan Oct 2017)","relationship_id":"relationship--484add44-6a43-4700-b1bc-d64f24157353","references":[{"source_name":"Proofpoint Leviathan Oct 2017","description":"Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.","url":"https://www.proofpoint.com/us/threat-insight/post/leviathan-espionage-actor-spearphishes-maritime-and-defense-targets"}]},{"id":"S0229","name":"Orz","url":"https://attack.mitre.org/software/S0229","kind":"malware","description":"[Orz](https://attack.mitre.org/software/S0229) can download files onto the victim.(Citation: Proofpoint Leviathan Oct 2017)","relationship_id":"relationship--73db6a54-2270-431b-b7eb-2c5c71389637","references":[{"source_name":"Proofpoint Leviathan Oct 2017","description":"Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.","url":"https://www.proofpoint.com/us/threat-insight/post/leviathan-espionage-actor-spearphishes-maritime-and-defense-targets"}]},{"id":"S0230","name":"ZeroT","url":"https://attack.mitre.org/software/S0230","kind":"malware","description":"[ZeroT](https://attack.mitre.org/software/S0230) can download additional payloads onto the victim.(Citation: Proofpoint ZeroT Feb 2017)","relationship_id":"relationship--bff3220c-6fea-4925-a9d0-46f06efb7337","references":[{"source_name":"Proofpoint ZeroT Feb 2017","description":"Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.","url":"https://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx"}]},{"id":"S0234","name":"Bandook","url":"https://attack.mitre.org/software/S0234","kind":"malware","description":"[Bandook](https://attack.mitre.org/software/S0234) can download files to the system.(Citation: CheckPoint Bandook Nov 2020)","relationship_id":"relationship--47afdb05-0327-4feb-b80e-1be491b57693","references":[{"source_name":"CheckPoint Bandook Nov 2020","description":"Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021.","url":"https://research.checkpoint.com/2020/bandook-signed-delivered/"}]},{"id":"S0236","name":"Kwampirs","url":"https://attack.mitre.org/software/S0236","kind":"malware","description":"[Kwampirs](https://attack.mitre.org/software/S0236) downloads additional files from C2 servers.(Citation: Symantec Security Center Trojan.Kwampirs)","relationship_id":"relationship--9b102737-2d47-4dd5-b4f2-2a323c506cfb","references":[{"source_name":"Symantec Security Center Trojan.Kwampirs","description":"Moench, B. and Aboud, E. (2016, August 23). Trojan.Kwampirs. Retrieved May 10, 2018.","url":"https://www.symantec.com/security-center/writeup/2016-081923-2700-99"}]},{"id":"S0239","name":"Bankshot","url":"https://attack.mitre.org/software/S0239","kind":"malware","description":"[Bankshot](https://attack.mitre.org/software/S0239) uploads files and secondary payloads to the victim's machine.(Citation: US-CERT Bankshot Dec 2017)","relationship_id":"relationship--a15e391d-cc21-484d-839a-b7057ae40179","references":[{"source_name":"US-CERT Bankshot Dec 2017","description":"US-CERT. (2017, December 13). Malware Analysis Report (MAR) - 10135536-B. Retrieved July 17, 2018.","url":"https://www.us-cert.gov/sites/default/files/publications/MAR-10135536-B_WHITE.PDF"}]},{"id":"S0240","name":"ROKRAT","url":"https://attack.mitre.org/software/S0240","kind":"malware","description":"[ROKRAT](https://attack.mitre.org/software/S0240) can retrieve additional malicious payloads from its C2 server.(Citation: Talos ROKRAT)(Citation: NCCGroup RokRat Nov 2018)(Citation: Volexity InkySquid RokRAT August 2021)(Citation: Malwarebytes RokRAT VBA January 2021)","relationship_id":"relationship--921b3245-0795-40cd-82e1-04f38bc42b14","references":[{"source_name":"Talos ROKRAT","description":"Mercer, W., Rascagneres, P. (2017, April 03). Introducing ROKRAT. Retrieved May 21, 2018.","url":"https://blog.talosintelligence.com/2017/04/introducing-rokrat.html"},{"source_name":"NCCGroup RokRat Nov 2018","description":"Pantazopoulos, N.. (2018, November 8). RokRat Analysis. Retrieved May 21, 2020.","url":"https://research.nccgroup.com/2018/11/08/rokrat-analysis/"},{"source_name":"Volexity InkySquid RokRAT August 2021","description":"Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.","url":"https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-inkysquid-deploys-rokrat/"},{"source_name":"Malwarebytes RokRAT VBA January 2021","description":"Jazi, Hossein. (2021, January 6). Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat. Retrieved March 22, 2022.","url":"https://blog.malwarebytes.com/threat-analysis/2021/01/retrohunting-apt37-north-korean-apt-used-vba-self-decode-technique-to-inject-rokrat/"}]},{"id":"S0241","name":"RATANKBA","url":"https://attack.mitre.org/software/S0241","kind":"malware","description":"[RATANKBA](https://attack.mitre.org/software/S0241) uploads and downloads information.(Citation: Lazarus RATANKBA)(Citation: RATANKBA)","relationship_id":"relationship--d8d6740b-a359-4f5c-b7d4-2189eea77892","references":[{"source_name":"Lazarus RATANKBA","description":"Lei, C., et al. (2018, January 24). Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More. Retrieved May 22, 2018.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/lazarus-campaign-targeting-cryptocurrencies-reveals-remote-controller-tool-evolved-ratankba/"},{"source_name":"RATANKBA","description":"Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.","url":"https://www.trendmicro.com/en_us/research/17/b/ratankba-watering-holes-against-enterprises.html"}]},{"id":"S0247","name":"NavRAT","url":"https://attack.mitre.org/software/S0247","kind":"malware","description":"[NavRAT](https://attack.mitre.org/software/S0247) can download files remotely.(Citation: Talos NavRAT May 2018)","relationship_id":"relationship--5b48c2b1-0ce7-4856-9bc7-ae359826550c","references":[{"source_name":"Talos NavRAT May 2018","description":"Mercer, W., Rascagneres, P. (2018, May 31). NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea. Retrieved June 11, 2018.","url":"https://blog.talosintelligence.com/2018/05/navrat.html"}]},{"id":"S0249","name":"Gold Dragon","url":"https://attack.mitre.org/software/S0249","kind":"malware","description":"[Gold Dragon](https://attack.mitre.org/software/S0249) can download additional components from the C2 server.(Citation: McAfee Gold Dragon)","relationship_id":"relationship--47880b58-f0e2-4898-a218-6df6333329ed","references":[{"source_name":"McAfee Gold Dragon","description":"Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.","url":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/"}]},{"id":"S0250","name":"Koadic","url":"https://attack.mitre.org/software/S0250","kind":"tool","description":"[Koadic](https://attack.mitre.org/software/S0250) can download additional files and tools.(Citation: Github Koadic)(Citation: MalwareBytes LazyScripter Feb 2021)","relationship_id":"relationship--419392f5-e6a8-4eee-b7c2-f0bac5cce833","references":[{"source_name":"MalwareBytes LazyScripter Feb 2021","description":"Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20211003035156/https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf"},{"source_name":"Github Koadic","description":"Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.","url":"https://github.com/offsecginger/koadic"}]},{"id":"S0251","name":"Zebrocy","url":"https://attack.mitre.org/software/S0251","kind":"malware","description":"[Zebrocy](https://attack.mitre.org/software/S0251) obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.(Citation: Palo Alto Sofacy 06-2018)(Citation: Unit42 Cannon Nov 2018)(Citation: ESET Zebrocy May 2019)(Citation: Accenture SNAKEMACKEREL Nov 2018)","relationship_id":"relationship--24bf6b49-b492-44b0-bcc9-37bfba489d62","references":[{"source_name":"Palo Alto Sofacy 06-2018","description":"Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-attacks/"},{"source_name":"Unit42 Cannon Nov 2018","description":"Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/11/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan/"},{"source_name":"ESET Zebrocy May 2019","description":"ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.","url":"https://www.welivesecurity.com/2019/05/22/journey-zebrocy-land/"},{"source_name":"Accenture SNAKEMACKEREL Nov 2018","description":"Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.","url":"https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf#zoom=50"}]},{"id":"S0254","name":"PLAINTEE","url":"https://attack.mitre.org/software/S0254","kind":"malware","description":"[PLAINTEE](https://attack.mitre.org/software/S0254) has downloaded and executed additional plugins.(Citation: Rancor Unit42 June 2018)","relationship_id":"relationship--fdea1dc1-4b00-411e-a5d3-cd72688237b5","references":[{"source_name":"Rancor Unit42 June 2018","description":"Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"id":"S0255","name":"DDKONG","url":"https://attack.mitre.org/software/S0255","kind":"malware","description":"[DDKONG](https://attack.mitre.org/software/S0255) downloads and uploads files on the victim’s machine.(Citation: Rancor Unit42 June 2018)","relationship_id":"relationship--083cbf6f-82e3-4d78-b18f-aa2d1f566713","references":[{"source_name":"Rancor Unit42 June 2018","description":"Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"id":"S0256","name":"Mosquito","url":"https://attack.mitre.org/software/S0256","kind":"malware","description":"[Mosquito](https://attack.mitre.org/software/S0256) can upload and download files to the victim.(Citation: ESET Turla Mosquito Jan 2018)","relationship_id":"relationship--6d17cbbf-dd7e-456c-ad9e-e084c95efdaf","references":[{"source_name":"ESET Turla Mosquito Jan 2018","description":"ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.","url":"https://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf"}]},{"id":"S0257","name":"VERMIN","url":"https://attack.mitre.org/software/S0257","kind":"malware","description":"[VERMIN](https://attack.mitre.org/software/S0257) can download and upload files to the victim's machine.(Citation: Unit 42 VERMIN Jan 2018)","relationship_id":"relationship--d68649d8-4f18-48b8-93b8-82c8660fc464","references":[{"source_name":"Unit 42 VERMIN Jan 2018","description":"Lancaster, T., Cortes, J. (2018, January 29). VERMIN: Quasar RAT and Custom Malware Used In Ukraine. Retrieved July 5, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/01/unit42-vermin-quasar-rat-custom-malware-used-ukraine/"}]},{"id":"S0258","name":"RGDoor","url":"https://attack.mitre.org/software/S0258","kind":"malware","description":"[RGDoor](https://attack.mitre.org/software/S0258) uploads and downloads files to and from the victim’s machine.(Citation: Unit 42 RGDoor Jan 2018)","relationship_id":"relationship--ee03d4e8-79e5-408f-a533-462774da46ed","references":[{"source_name":"Unit 42 RGDoor Jan 2018","description":"Falcone, R. (2018, January 25). OilRig uses RGDoor IIS Backdoor on Targets in the Middle East. Retrieved July 6, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/"}]},{"id":"S0260","name":"InvisiMole","url":"https://attack.mitre.org/software/S0260","kind":"malware","description":"[InvisiMole](https://attack.mitre.org/software/S0260) can upload files to the victim's machine for operations.(Citation: ESET InvisiMole June 2018)(Citation: ESET InvisiMole June 2020)","relationship_id":"relationship--b7760f6b-9b57-4fa8-895a-4f4a209aa366","references":[{"source_name":"ESET InvisiMole June 2018","description":"Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.","url":"https://www.welivesecurity.com/2018/06/07/invisimole-equipped-spyware-undercover/"},{"source_name":"ESET InvisiMole June 2020","description":"Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2020/06/ESET_InvisiMole.pdf"}]},{"id":"S0262","name":"QuasarRAT","url":"https://attack.mitre.org/software/S0262","kind":"tool","description":"[QuasarRAT](https://attack.mitre.org/software/S0262) can download files to the victim’s machine and execute them.(Citation: GitHub QuasarRAT)(Citation: Volexity Patchwork June 2018)","relationship_id":"relationship--4a33da76-c838-48fe-97ad-80d285cf165f","references":[{"source_name":"GitHub QuasarRAT","description":"MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.","url":"https://github.com/quasar/QuasarRAT"},{"source_name":"Volexity Patchwork June 2018","description":"Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.","url":"https://www.volexity.com/blog/2018/06/07/patchwork-apt-group-targets-us-think-tanks/"}]},{"id":"S0263","name":"TYPEFRAME","url":"https://attack.mitre.org/software/S0263","kind":"malware","description":"[TYPEFRAME](https://attack.mitre.org/software/S0263) can upload and download files to the victim’s machine.(Citation: US-CERT TYPEFRAME June 2018)","relationship_id":"relationship--42914dfa-9644-4bf6-bb5f-45c0e3303d7b","references":[{"source_name":"US-CERT TYPEFRAME June 2018","description":"US-CERT. (2018, June 14). MAR-10135536-12 – North Korean Trojan: TYPEFRAME. Retrieved July 13, 2018.","url":"https://www.us-cert.gov/ncas/analysis-reports/AR18-165A"}]},{"id":"S0264","name":"OopsIE","url":"https://attack.mitre.org/software/S0264","kind":"malware","description":"[OopsIE](https://attack.mitre.org/software/S0264) can download files from its C2 server to the victim's machine.(Citation: Unit 42 OopsIE! Feb 2018)(Citation: Unit 42 OilRig Sept 2018)","relationship_id":"relationship--978dbb17-c5c5-4248-8385-9dc6f691030b","references":[{"source_name":"Unit 42 OopsIE! Feb 2018","description":"Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/02/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/"},{"source_name":"Unit 42 OilRig Sept 2018","description":"Falcone, R., et al. (2018, September 04). OilRig Targets a Middle Eastern Government and Adds Evasion Techniques to OopsIE. Retrieved September 24, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/09/unit42-oilrig-targets-middle-eastern-government-adds-evasion-techniques-oopsie/"}]},{"id":"S0265","name":"Kazuar","url":"https://attack.mitre.org/software/S0265","kind":"malware","description":"[Kazuar](https://attack.mitre.org/software/S0265) downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.(Citation: Unit 42 Kazuar May 2017)","relationship_id":"relationship--2286857e-ad96-4dda-abac-988e8cadda5c","references":[{"source_name":"Unit 42 Kazuar May 2017","description":"Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.","url":"https://researchcenter.paloaltonetworks.com/2017/05/unit42-kazuar-multiplatform-espionage-backdoor-api-access/"}]},{"id":"S0266","name":"TrickBot","url":"https://attack.mitre.org/software/S0266","kind":"malware","description":"[TrickBot](https://attack.mitre.org/software/S0266) downloads several additional files and saves them to the victim's machine.(Citation: Trend Micro Totbrick Oct 2016)(Citation: Bitdefender Trickbot VNC module Whitepaper 2021)","relationship_id":"relationship--d8e0ed13-7938-4c9c-99ef-511b8dbf76aa","references":[{"source_name":"Trend Micro Totbrick Oct 2016","description":"Antazo, F. (2016, October 31). TSPY_TRICKLOAD.N. Retrieved September 14, 2018.","url":"https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/tspy_trickload.n"},{"source_name":"Bitdefender Trickbot VNC module Whitepaper 2021","description":"Radu Tudorica. (2021, July 12). A Fresh Look at Trickbot’s Ever-Improving VNC Module. Retrieved September 28, 2021.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/399/Bitdefender-PR-Whitepaper-Trickbot-creat5515-en-EN.pdf"}]},{"id":"S0267","name":"FELIXROOT","url":"https://attack.mitre.org/software/S0267","kind":"malware","description":"[FELIXROOT](https://attack.mitre.org/software/S0267) downloads and uploads files to and from the victim’s machine.(Citation: FireEye FELIXROOT July 2018)(Citation: ESET GreyEnergy Oct 2018)","relationship_id":"relationship--e4c5ab65-e084-4844-9bf8-546d78f20e96","references":[{"source_name":"ESET GreyEnergy Oct 2018","description":"Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.","url":"https://www.welivesecurity.com/wp-content/uploads/2018/10/ESET_GreyEnergy.pdf"},{"source_name":"FireEye FELIXROOT July 2018","description":"Patil, S. (2018, June 26). Microsoft Office Vulnerabilities Used to Distribute FELIXROOT Backdoor in Recent Campaign. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20200607025424/https://www.fireeye.com/blog/threat-research/2018/07/microsoft-office-vulnerabilities-used-to-distribute-felixroot-backdoor.html"}]},{"id":"S0268","name":"Bisonal","url":"https://attack.mitre.org/software/S0268","kind":"malware","description":"[Bisonal](https://attack.mitre.org/software/S0268) has the capability to download files to execute on the victim’s machine.(Citation: Unit 42 Bisonal July 2018)(Citation: Kaspersky CactusPete Aug 2020)(Citation: Talos Bisonal Mar 2020) ","relationship_id":"relationship--1b95cd32-155b-488d-bbf8-e16f22e2a1d5","references":[{"source_name":"Unit 42 Bisonal July 2018","description":"Hayashi, K., Ray, V. (2018, July 31). Bisonal Malware Used in Attacks Against Russia and South Korea. Retrieved August 7, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/07/unit42-bisonal-malware-used-attacks-russia-south-korea/"},{"source_name":"Kaspersky CactusPete Aug 2020","description":"Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.","url":"https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/"},{"source_name":"Talos Bisonal Mar 2020","description":"Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.","url":"https://blog.talosintelligence.com/2020/03/bisonal-10-years-of-play.html"}]},{"id":"S0270","name":"RogueRobin","url":"https://attack.mitre.org/software/S0270","kind":"malware","description":"[RogueRobin](https://attack.mitre.org/software/S0270) can save a new file to the system from the C2 server.(Citation: Unit 42 DarkHydrus July 2018)(Citation: Unit42 DarkHydrus Jan 2019)","relationship_id":"relationship--2227a2ce-2eda-4fe3-a9ca-524e0de0ded2","references":[{"source_name":"Unit 42 DarkHydrus July 2018","description":"Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/"},{"source_name":"Unit42 DarkHydrus Jan 2019","description":"Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.","url":"https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/"}]},{"id":"S0271","name":"KEYMARBLE","url":"https://attack.mitre.org/software/S0271","kind":"malware","description":"[KEYMARBLE](https://attack.mitre.org/software/S0271) can upload files to the victim’s machine and can download additional payloads.(Citation: US-CERT KEYMARBLE Aug 2018)","relationship_id":"relationship--30efb3df-f7b4-47f8-9c5a-53a94509c929","references":[{"source_name":"US-CERT KEYMARBLE Aug 2018","description":"US-CERT. (2018, August 09). MAR-10135536-17 – North Korean Trojan: KEYMARBLE. Retrieved August 16, 2018.","url":"https://www.us-cert.gov/ncas/analysis-reports/AR18-221A"}]},{"id":"S0272","name":"NDiskMonitor","url":"https://attack.mitre.org/software/S0272","kind":"malware","description":"[NDiskMonitor](https://attack.mitre.org/software/S0272) can download and execute a file from given URL.(Citation: TrendMicro Patchwork Dec 2017)","relationship_id":"relationship--34d105a6-47ac-4a8b-b892-6f630cd97096","references":[{"source_name":"TrendMicro Patchwork Dec 2017","description":"Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.","url":"https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-cyberespionage-group.pdf"}]},{"id":"S0274","name":"Calisto","url":"https://attack.mitre.org/software/S0274","kind":"malware","description":"[Calisto](https://attack.mitre.org/software/S0274) has the capability to upload and download files to the victim's machine.(Citation: Symantec Calisto July 2018)","relationship_id":"relationship--406257ac-ff42-4e15-b72e-50202e38b675","references":[{"source_name":"Symantec Calisto July 2018","description":"Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.","url":"https://web.archive.org/web/20190111082249/https://www.symantec.com/security-center/writeup/2018-073014-2512-99?om_rssid=sr-latestthreats30days"}]},{"id":"S0275","name":"UPPERCUT","url":"https://attack.mitre.org/software/S0275","kind":"malware","description":"[UPPERCUT](https://attack.mitre.org/software/S0275) can download and upload files to and from the victim’s machine.(Citation: FireEye APT10 Sept 2018)(Citation: Trend Micro Earth Kasha Updates APR 2025)(Citation: Trend Micro Earth Kasha Anel NOV 2024)\n","relationship_id":"relationship--a2ad2bea-4359-47a8-ae5f-f18beab07316","references":[{"source_name":"Trend Micro Earth Kasha Anel NOV 2024","description":"Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.","url":"https://www.trendmicro.com/en_us/research/24/k/return-of-anel-in-the-recent-earth-kasha-spearphishing-campaign.html"},{"source_name":"Trend Micro Earth Kasha Updates APR 2025","description":"Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.","url":"https://www.trendmicro.com/en_us/research/25/d/earth-kasha-updates-ttps.html"},{"source_name":"FireEye APT10 Sept 2018","description":"Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.","url":"https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html"}]},{"id":"S0283","name":"jRAT","url":"https://attack.mitre.org/software/S0283","kind":"malware","description":"[jRAT](https://attack.mitre.org/software/S0283) can download and execute files.(Citation: jRAT Symantec Aug 2018)(Citation: Kaspersky Adwind Feb 2016)(Citation: Symantec Frutas Feb 2013)","relationship_id":"relationship--730190b3-d372-4461-9bf4-94de4c078968","references":[{"source_name":"jRAT Symantec Aug 2018","description":"Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018.","url":"https://www.symantec.com/blogs/threat-intelligence/jrat-new-anti-parsing-techniques"},{"source_name":"Kaspersky Adwind Feb 2016","description":"Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.","url":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07195002/KL_AdwindPublicReport_2016.pdf"},{"source_name":"Symantec Frutas Feb 2013","description":"Bingham, J. (2013, February 11). Cross-Platform Frutas RAT Builder and Back Door. Retrieved April 23, 2019.","url":"https://www.symantec.com/connect/blogs/cross-platform-frutas-rat-builder-and-back-door"}]},{"id":"S0284","name":"More_eggs","url":"https://attack.mitre.org/software/S0284","kind":"malware","description":"[More_eggs](https://attack.mitre.org/software/S0284) can download and launch additional payloads.(Citation: Talos Cobalt Group July 2018)(Citation: Security Intelligence More Eggs Aug 2019)","relationship_id":"relationship--0485006f-c4f6-4657-85a0-6beec8d9368a","references":[{"source_name":"Talos Cobalt Group July 2018","description":"Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.","url":"https://blog.talosintelligence.com/2018/07/multiple-cobalt-personality-disorder.html"},{"source_name":"Security Intelligence More Eggs Aug 2019","description":"Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.","url":"https://securityintelligence.com/posts/more_eggs-anyone-threat-actor-itg08-strikes-again/"}]},{"id":"S0330","name":"Zeus Panda","url":"https://attack.mitre.org/software/S0330","kind":"malware","description":"[Zeus Panda](https://attack.mitre.org/software/S0330) can download additional malware plug-in modules and execute them on the victim’s machine.(Citation: GDATA Zeus Panda June 2017)","relationship_id":"relationship--4c0f441f-13b1-4b79-b658-e081d5143a94","references":[{"source_name":"GDATA Zeus Panda June 2017","description":"Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.","url":"https://cyberwtf.files.wordpress.com/2017/07/panda-whitepaper.pdf"}]},{"id":"S0331","name":"Agent Tesla","url":"https://attack.mitre.org/software/S0331","kind":"malware","description":"[Agent Tesla](https://attack.mitre.org/software/S0331) can download additional files for execution on the victim’s machine.(Citation: Talos Agent Tesla Oct 2018)(Citation: DigiTrust Agent Tesla Jan 2017)","relationship_id":"relationship--40ae8100-d02c-445a-acf5-8e30f04ec6c0","references":[{"source_name":"Talos Agent Tesla Oct 2018","description":"Brumaghin, E., et al. (2018, October 15). Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox. Retrieved November 5, 2018.","url":"https://blog.talosintelligence.com/2018/10/old-dog-new-tricks-analysing-new-rtf_15.html"},{"source_name":"DigiTrust Agent Tesla Jan 2017","description":"The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.","url":"https://www.digitrustgroup.com/agent-tesla-keylogger/"}]},{"id":"S0332","name":"Remcos","url":"https://attack.mitre.org/software/S0332","kind":"tool","description":"[Remcos](https://attack.mitre.org/software/S0332) can upload and download files to and from the victim’s machine.(Citation: Riskiq Remcos Jan 2018)(Citation: Fortinet Remcos Campaign NOV 2024)","relationship_id":"relationship--ad787fb5-9d63-423d-941f-bfe7648b2e24","references":[{"source_name":"Riskiq Remcos Jan 2018","description":"Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.","url":"https://web.archive.org/web/20180124082756/https://www.riskiq.com/blog/labs/spear-phishing-turkish-defense-contractors/"},{"source_name":"Fortinet Remcos Campaign NOV 2024","description":"Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.","url":"https://www.fortinet.com/blog/threat-research/new-campaign-uses-remcos-rat-to-exploit-victims"}]},{"id":"S0333","name":"UBoatRAT","url":"https://attack.mitre.org/software/S0333","kind":"malware","description":"[UBoatRAT](https://attack.mitre.org/software/S0333) can upload and download files to the victim’s machine.(Citation: PaloAlto UBoatRAT Nov 2017)","relationship_id":"relationship--ebf44df8-d7c7-4c95-87f0-e31f88b83c72","references":[{"source_name":"PaloAlto UBoatRAT Nov 2017","description":"Hayashi, K. (2017, November 28). UBoatRAT Navigates East Asia. Retrieved January 12, 2018.","url":"https://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/"}]},{"id":"S0334","name":"DarkComet","url":"https://attack.mitre.org/software/S0334","kind":"malware","description":"[DarkComet](https://attack.mitre.org/software/S0334) can load any files onto the infected machine to execute.(Citation: TrendMicro DarkComet Sept 2014)(Citation: Malwarebytes DarkComet March 2018)","relationship_id":"relationship--75f88090-55cb-4b3b-84af-cf51058c3ccc","references":[{"source_name":"TrendMicro DarkComet Sept 2014","description":"TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.","url":"https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/DARKCOMET"},{"source_name":"Malwarebytes DarkComet March 2018","description":"Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.","url":"https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"}]},{"id":"S0336","name":"NanoCore","url":"https://attack.mitre.org/software/S0336","kind":"malware","description":"[NanoCore](https://attack.mitre.org/software/S0336) has the capability to download and activate additional modules for execution.(Citation: DigiTrust NanoCore Jan 2017)(Citation: PaloAlto NanoCore Feb 2016)","relationship_id":"relationship--10806c6b-100d-456b-bb05-62d90713be64","references":[{"source_name":"DigiTrust NanoCore Jan 2017","description":"The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.","url":"https://www.digitrustgroup.com/nanocore-not-your-average-rat/"},{"source_name":"PaloAlto NanoCore Feb 2016","description":"Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.","url":"https://researchcenter.paloaltonetworks.com/2016/02/nanocorerat-behind-an-increase-in-tax-themed-phishing-e-mails/"}]},{"id":"S0337","name":"BadPatch","url":"https://attack.mitre.org/software/S0337","kind":"malware","description":"[BadPatch](https://attack.mitre.org/software/S0337) can download and execute or update malware.(Citation: Unit 42 BadPatch Oct 2017)","relationship_id":"relationship--91eab726-0a0c-4898-8376-66987fd1037c","references":[{"source_name":"Unit 42 BadPatch Oct 2017","description":"Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.","url":"https://researchcenter.paloaltonetworks.com/2017/10/unit42-badpatch/"}]},{"id":"S0339","name":"Micropsia","url":"https://attack.mitre.org/software/S0339","kind":"malware","description":"[Micropsia](https://attack.mitre.org/software/S0339) can download and execute an executable from the C2 server.(Citation: Talos Micropsia June 2017)(Citation: Radware Micropsia July 2018)","relationship_id":"relationship--7ec1ddbb-57d1-4530-97d1-dd5d02cd3eb2","references":[{"source_name":"Talos Micropsia June 2017","description":"Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.","url":"https://blog.talosintelligence.com/2017/06/palestine-delphi.html"},{"source_name":"Radware Micropsia July 2018","description":"Tsarfaty, Y. (2018, July 25). Micropsia Malware. Retrieved November 13, 2018.","url":"https://www.radware.com/blog/security/2018/07/micropsia-malware/"}]},{"id":"S0340","name":"Octopus","url":"https://attack.mitre.org/software/S0340","kind":"malware","description":"[Octopus](https://attack.mitre.org/software/S0340) can download additional files and tools onto the victim’s machine.(Citation: Securelist Octopus Oct 2018)(Citation: Security Affairs DustSquad Oct 2018)(Citation: ESET Nomadic Octopus 2018)","relationship_id":"relationship--c77d6f2a-664e-4bbb-bf86-c2c58adbdc84","references":[{"source_name":"Securelist Octopus Oct 2018","description":"Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.","url":"https://securelist.com/octopus-infested-seas-of-central-asia/88200/"},{"source_name":"Security Affairs DustSquad Oct 2018","description":"Paganini, P. (2018, October 16). Russia-linked APT group DustSquad targets diplomatic entities in Central Asia. Retrieved August 24, 2021.","url":"https://securityaffairs.co/wordpress/77165/apt/russia-linked-apt-dustsquad.html"},{"source_name":"ESET Nomadic Octopus 2018","description":"Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.","url":"https://www.virusbulletin.com/uploads/pdf/conference_slides/2018/Cherepanov-VB2018-Octopus.pdf"}]},{"id":"S0341","name":"Xbash","url":"https://attack.mitre.org/software/S0341","kind":"malware","description":"[Xbash](https://attack.mitre.org/software/S0341) can download additional malicious files from its C2 server.(Citation: Unit42 Xbash Sept 2018)","relationship_id":"relationship--809ffec1-52a1-45a5-b410-049352b99700","references":[{"source_name":"Unit42 Xbash Sept 2018","description":"Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/"}]},{"id":"S0342","name":"GreyEnergy","url":"https://attack.mitre.org/software/S0342","kind":"malware","description":"[GreyEnergy](https://attack.mitre.org/software/S0342) can download additional modules and payloads.(Citation: ESET GreyEnergy Oct 2018)","relationship_id":"relationship--a21e7dd8-9194-4c09-870c-11f44f391838","references":[{"source_name":"ESET GreyEnergy Oct 2018","description":"Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.","url":"https://www.welivesecurity.com/wp-content/uploads/2018/10/ESET_GreyEnergy.pdf"}]},{"id":"S0344","name":"Azorult","url":"https://attack.mitre.org/software/S0344","kind":"malware","description":"[Azorult](https://attack.mitre.org/software/S0344) can download and execute additional files. [Azorult](https://attack.mitre.org/software/S0344) has also downloaded a ransomware payload called Hermes.(Citation: Unit42 Azorult Nov 2018)(Citation: Proofpoint Azorult July 2018)","relationship_id":"relationship--6dbac0dd-ebd3-49dc-bbef-d5a7fd464e02","references":[{"source_name":"Unit42 Azorult Nov 2018","description":"Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/11/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit/"},{"source_name":"Proofpoint Azorult July 2018","description":"Proofpoint. (2018, July 30). New version of AZORult stealer improves loading features, spreads alongside ransomware in new campaign. Retrieved November 29, 2018.","url":"https://www.proofpoint.com/us/threat-insight/post/new-version-azorult-stealer-improves-loading-features-spreads-alongside"}]},{"id":"S0345","name":"Seasalt","url":"https://attack.mitre.org/software/S0345","kind":"malware","description":"[Seasalt](https://attack.mitre.org/software/S0345) has a command to download additional files.(Citation: Mandiant APT1 Appendix)(Citation: Mandiant APT1 Appendix)","relationship_id":"relationship--75f47e28-75dd-4471-8d00-ed4a2c4d3328","references":[{"source_name":"Mandiant APT1 Appendix","description":"Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.","url":"https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf"}]},{"id":"S0347","name":"AuditCred","url":"https://attack.mitre.org/software/S0347","kind":"malware","description":"[AuditCred](https://attack.mitre.org/software/S0347) can download files and additional malware.(Citation: TrendMicro Lazarus Nov 2018)","relationship_id":"relationship--4d23c95c-366e-464c-b41c-64e48f4e166a","references":[{"source_name":"TrendMicro Lazarus Nov 2018","description":"Trend Micro. (2018, November 20). Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America. Retrieved December 3, 2018.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/lazarus-continues-heists-mounts-attacks-on-financial-organizations-in-latin-america/"}]},{"id":"S0348","name":"Cardinal RAT","url":"https://attack.mitre.org/software/S0348","kind":"malware","description":"[Cardinal RAT](https://attack.mitre.org/software/S0348) can download and execute additional payloads.(Citation: PaloAlto CardinalRat Apr 2017)","relationship_id":"relationship--2e83c5c4-76f3-46a3-980f-0063069671cf","references":[{"source_name":"PaloAlto CardinalRat Apr 2017","description":"Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.","url":"https://researchcenter.paloaltonetworks.com/2017/04/unit42-cardinal-rat-active-two-years/"}]},{"id":"S0351","name":"Cannon","url":"https://attack.mitre.org/software/S0351","kind":"malware","description":"[Cannon](https://attack.mitre.org/software/S0351) can download a payload for execution.(Citation: Unit42 Cannon Nov 2018)","relationship_id":"relationship--f315cbb6-e49c-4820-99cb-262d36acf17f","references":[{"source_name":"Unit42 Cannon Nov 2018","description":"Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/11/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan/"}]},{"id":"S0352","name":"OSX_OCEANLOTUS.D","url":"https://attack.mitre.org/software/S0352","kind":"malware","description":"[OSX_OCEANLOTUS.D](https://attack.mitre.org/software/S0352) has a command to download and execute a file on the victim’s machine.(Citation: TrendMicro MacOS April 2018)(Citation: Trend Micro MacOS Backdoor November 2020)","relationship_id":"relationship--5cb54f4b-f615-44ad-94d6-136ff507c2d6","references":[{"source_name":"TrendMicro MacOS April 2018","description":"Horejsi, J. (2018, April 04). New MacOS Backdoor Linked to OceanLotus Found. Retrieved November 13, 2018.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/new-macos-backdoor-linked-to-oceanlotus-found/"},{"source_name":"Trend Micro MacOS Backdoor November 2020","description":"Magisa, L. (2020, November 27). New MacOS Backdoor Connected to OceanLotus Surfaces. Retrieved December 2, 2020.","url":"https://www.trendmicro.com/en_us/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html"}]},{"id":"S0353","name":"NOKKI","url":"https://attack.mitre.org/software/S0353","kind":"malware","description":"[NOKKI](https://attack.mitre.org/software/S0353) has downloaded a remote module for execution.(Citation: Unit 42 NOKKI Sept 2018)","relationship_id":"relationship--65384e27-6d16-4d25-a17b-3d74dde8f224","references":[{"source_name":"Unit 42 NOKKI Sept 2018","description":"Grunzweig, J., Lee, B. (2018, September 27). New KONNI Malware attacking Eurasia and Southeast Asia. Retrieved November 5, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/"}]},{"id":"S0354","name":"Denis","url":"https://attack.mitre.org/software/S0354","kind":"malware","description":"[Denis](https://attack.mitre.org/software/S0354) deploys additional backdoors and hacking tools to the system.(Citation: Cybereason Cobalt Kitty 2017)","relationship_id":"relationship--117ecbd3-b4cd-4ad2-a5f4-30ba79563406","references":[{"source_name":"Cybereason Cobalt Kitty 2017","description":"Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.","url":"https://cdn2.hubspot.net/hubfs/3354902/Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty.pdf"}]},{"id":"S0356","name":"KONNI","url":"https://attack.mitre.org/software/S0356","kind":"malware","description":"[KONNI](https://attack.mitre.org/software/S0356) can download files and execute them on the victim’s machine.(Citation: Talos Konni May 2017)(Citation: Malwarebytes Konni Aug 2021) ","relationship_id":"relationship--8720f2bc-c099-4d2c-a9b4-faf019bf55a4","references":[{"source_name":"Talos Konni May 2017","description":"Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.","url":"https://blog.talosintelligence.com/2017/05/konni-malware-under-radar-for-years.html"},{"source_name":"Malwarebytes Konni Aug 2021","description":"Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.","url":"https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/"}]},{"id":"S0360","name":"BONDUPDATER","url":"https://attack.mitre.org/software/S0360","kind":"malware","description":"[BONDUPDATER](https://attack.mitre.org/software/S0360) can download or upload files from its C2 server.(Citation: Palo Alto OilRig Sep 2018)","relationship_id":"relationship--dd4a0bb3-b9f0-4d69-9768-a17d95783398","references":[{"source_name":"Palo Alto OilRig Sep 2018","description":"Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019.","url":"https://unit42.paloaltonetworks.com/unit42-oilrig-uses-updated-bondupdater-target-middle-eastern-government/"}]},{"id":"S0363","name":"Empire","url":"https://attack.mitre.org/software/S0363","kind":"tool","description":"[Empire](https://attack.mitre.org/software/S0363) can upload and download to and from a victim machine.(Citation: Github PowerShell Empire)","relationship_id":"relationship--efd94521-6d23-4947-a257-1c81ac52f0d9","references":[{"source_name":"Github PowerShell Empire","description":"Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.","url":"https://github.com/PowerShellEmpire/Empire"}]},{"id":"S0367","name":"Emotet","url":"https://attack.mitre.org/software/S0367","kind":"malware","description":"[Emotet](https://attack.mitre.org/software/S0367) can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.(Citation: Pincus Emotet 2020)","relationship_id":"relationship--622ba39c-2f40-4605-81ce-ef04cea95808","references":[{"source_name":"Pincus Emotet 2020","description":"Süleyman Özarslan, PhD; Pincus Security Inc.. (2020, July 14). An Analysis of Emotet Malware: PowerShell Unobfuscation. Retrieved November 25, 2024.","url":"https://medium.com/picus-security/an-analysis-of-emotet-malware-powershell-unobfuscation-4f46b50dcf2b"}]},{"id":"S0369","name":"CoinTicker","url":"https://attack.mitre.org/software/S0369","kind":"malware","description":"[CoinTicker](https://attack.mitre.org/software/S0369) executes a Python script to download its second stage.(Citation: CoinTicker 2019)","relationship_id":"relationship--9a5f9534-a2a4-402e-89bd-d014c2fba224","references":[{"source_name":"CoinTicker 2019","description":"Thomas Reed. (2018, October 29). Mac cryptocurrency ticker app installs backdoors. Retrieved April 23, 2019.","url":"https://blog.malwarebytes.com/threat-analysis/2018/10/mac-cryptocurrency-ticker-app-installs-backdoors/"}]},{"id":"S0373","name":"Astaroth","url":"https://attack.mitre.org/software/S0373","kind":"malware","description":"[Astaroth](https://attack.mitre.org/software/S0373) uses [certutil](https://attack.mitre.org/software/S0160) and [BITSAdmin](https://attack.mitre.org/software/S0190) to download additional malware. (Citation: Cofense Astaroth Sept 2018)(Citation: Cybereason Astaroth Feb 2019)(Citation: Securelist Brazilian Banking Malware July 2020)","relationship_id":"relationship--ad731b3e-709e-49d0-a501-6fe69f78a428","references":[{"source_name":"Cofense Astaroth Sept 2018","description":"Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.","url":"https://web.archive.org/web/20200302071436/https://cofense.com/seeing-resurgence-demonic-astaroth-wmic-trojan/"},{"source_name":"Securelist Brazilian Banking Malware July 2020","description":"GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.","url":"https://securelist.com/the-tetrade-brazilian-banking-malware/97779/"},{"source_name":"Cybereason Astaroth Feb 2019","description":"Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.","url":"https://www.cybereason.com/blog/information-stealing-malware-targeting-brazil-full-research"}]},{"id":"S0374","name":"SpeakUp","url":"https://attack.mitre.org/software/S0374","kind":"malware","description":"[SpeakUp](https://attack.mitre.org/software/S0374) downloads and executes additional files from a remote server. (Citation: CheckPoint SpeakUp Feb 2019)","relationship_id":"relationship--1c3d2111-f234-4624-999e-ce902367c212","references":[{"source_name":"CheckPoint SpeakUp Feb 2019","description":"Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.","url":"https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/"}]},{"id":"S0376","name":"HOPLIGHT","url":"https://attack.mitre.org/software/S0376","kind":"malware","description":"[HOPLIGHT](https://attack.mitre.org/software/S0376) has the ability to connect to a remote host in order to upload and download files.(Citation: US-CERT HOPLIGHT Apr 2019)\t","relationship_id":"relationship--b4349e95-eeff-4784-8a7d-2c6d60a734dd","references":[{"source_name":"US-CERT HOPLIGHT Apr 2019","description":"US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.","url":"https://www.us-cert.gov/ncas/analysis-reports/AR19-100A"}]},{"id":"S0379","name":"Revenge RAT","url":"https://attack.mitre.org/software/S0379","kind":"malware","description":"[Revenge RAT](https://attack.mitre.org/software/S0379) has the ability to upload and download files.(Citation: Cylance Shaheen Nov 2018)","relationship_id":"relationship--1f5aee41-e3bc-4ed0-a0e2-fa8f7cd6de26","references":[{"source_name":"Cylance Shaheen Nov 2018","description":"Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.","url":"https://www.cylance.com/content/dam/cylance-web/en-us/resources/knowledge-center/resource-library/reports/WhiteCompanyOperationShaheenReport.pdf?_ga=2.161661948.1943296560.1555683782-1066572390.1555511517"}]},{"id":"S0380","name":"StoneDrill","url":"https://attack.mitre.org/software/S0380","kind":"malware","description":"[StoneDrill](https://attack.mitre.org/software/S0380) has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.(Citation: Kaspersky StoneDrill 2017)\t","relationship_id":"relationship--10974f3d-30fc-4ab6-b691-21acff792a05","references":[{"source_name":"Kaspersky StoneDrill 2017","description":"Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.","url":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180722/Report_Shamoon_StoneDrill_final.pdf"}]},{"id":"S0381","name":"FlawedAmmyy","url":"https://attack.mitre.org/software/S0381","kind":"malware","description":"[FlawedAmmyy](https://attack.mitre.org/software/S0381) can transfer files from C2.(Citation: Korean FSI TA505 2020)","relationship_id":"relationship--9f43174e-9fec-447c-b5d9-12b348447853","references":[{"source_name":"Korean FSI TA505 2020","description":"Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.","url":"https://www.fsec.or.kr/user/bbs/fsec/163/344/bbsDataView/1382.do?page=1&column=&search=&searchSDate=&searchEDate=&bbsDataCategory="}]},{"id":"S0382","name":"ServHelper","url":"https://attack.mitre.org/software/S0382","kind":"malware","description":"[ServHelper](https://attack.mitre.org/software/S0382) may download additional files to execute.(Citation: Proofpoint TA505 Jan 2019)(Citation: Deep Instinct TA505 Apr 2019)","relationship_id":"relationship--435f910b-21a6-4814-b167-5262ca1e1e58","references":[{"source_name":"Proofpoint TA505 Jan 2019","description":"Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.","url":"https://www.proofpoint.com/us/threat-insight/post/servhelper-and-flawedgrace-new-malware-introduced-ta505"},{"source_name":"Deep Instinct TA505 Apr 2019","description":"Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..","url":"https://www.deepinstinct.com/blog/new-servhelper-variant-employs-excel-4-0-macro-to-drop-signed-payload"}]},{"id":"S0385","name":"njRAT","url":"https://attack.mitre.org/software/S0385","kind":"malware","description":"[njRAT](https://attack.mitre.org/software/S0385) can download files to the victim’s machine.(Citation: Fidelis njRAT June 2013)(Citation: Trend Micro njRAT 2018) [APT-C-36](https://attack.mitre.org/groups/G0099) has used modified versions of [njRAT](https://attack.mitre.org/software/S0385) to enable the download of .NET assemblies.(Citation: Kaspersky BlindEagle AUG 2024)","relationship_id":"relationship--168ab4a2-db4d-4d64-9951-6547145aabe6","references":[{"source_name":"Fidelis njRAT June 2013","description":"Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: \"njRAT\" Uncovered. Retrieved June 4, 2019.","url":"https://www.threatminer.org/_reports/2013/fta-1009---njrat-uncovered-1.pdf"},{"source_name":"Kaspersky BlindEagle AUG 2024","description":"Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.","url":"https://securelist.com/blindeagle-apt/113414/"},{"source_name":"Trend Micro njRAT 2018","description":"Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/autoit-compiled-worm-affecting-removable-media-delivers-fileless-version-of-bladabindi-njrat-backdoor/"}]},{"id":"S0386","name":"Ursnif","url":"https://attack.mitre.org/software/S0386","kind":"malware","description":"[Ursnif](https://attack.mitre.org/software/S0386) has dropped payload and configuration files to disk. [Ursnif](https://attack.mitre.org/software/S0386) has also been used to download and execute additional payloads.(Citation: TrendMicro PE_URSNIF.A2)(Citation: TrendMicro BKDR_URSNIF.SM)","relationship_id":"relationship--0d88d99d-88b0-4e49-b2c3-3607a32069ed","references":[{"source_name":"TrendMicro PE_URSNIF.A2","description":"Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.","url":"https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_URSNIF.A2?_ga=2.131425807.1462021705.1559742358-1202584019.1549394279"},{"source_name":"TrendMicro BKDR_URSNIF.SM","description":"Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.","url":"https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279"}]},{"id":"S0387","name":"KeyBoy","url":"https://attack.mitre.org/software/S0387","kind":"malware","description":"[KeyBoy](https://attack.mitre.org/software/S0387) has a download and upload functionality.(Citation: PWC KeyBoys Feb 2017)(Citation: Rapid7 KeyBoy Jun 2013)","relationship_id":"relationship--8833fac6-778f-4cf8-8b2a-6dee29164ffa","references":[{"source_name":"Rapid7 KeyBoy Jun 2013","description":"Guarnieri, C., Schloesser M. (2013, June 7). KeyBoy, Targeted Attacks against Vietnam and India. Retrieved June 14, 2019.","url":"https://blog.rapid7.com/2013/06/07/keyboy-targeted-attacks-against-vietnam-and-india/"},{"source_name":"PWC KeyBoys Feb 2017","description":"Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.","url":"https://web.archive.org/web/20211129064701/https://www.pwc.co.uk/issues/cyber-security-services/research/the-keyboys-are-back-in-town.html"}]},{"id":"S0388","name":"YAHOYAH","url":"https://attack.mitre.org/software/S0388","kind":"malware","description":"[YAHOYAH](https://attack.mitre.org/software/S0388) uses HTTP GET requests to download other files that are executed in memory.(Citation: TrendMicro TropicTrooper 2015)","relationship_id":"relationship--1729ebeb-c92c-4d8e-a859-0d081b3821a1","references":[{"source_name":"TrendMicro TropicTrooper 2015","description":"Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.","url":"https://documents.trendmicro.com/assets/wp/wp-operation-tropic-trooper.pdf"}]},{"id":"S0390","name":"SQLRat","url":"https://attack.mitre.org/software/S0390","kind":"malware","description":"[SQLRat](https://attack.mitre.org/software/S0390) can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.(Citation: Flashpoint FIN 7 March 2019)\t","relationship_id":"relationship--1cfc5611-b428-4fce-8b8d-f591523c9d9c","references":[{"source_name":"Flashpoint FIN 7 March 2019","description":"Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.","url":"https://www.flashpoint-intel.com/blog/fin7-revisited-inside-astra-panel-and-sqlrat-malware/"}]},{"id":"S0394","name":"HiddenWasp","url":"https://attack.mitre.org/software/S0394","kind":"malware","description":"[HiddenWasp](https://attack.mitre.org/software/S0394) downloads a tar compressed archive from a download server to the system.(Citation: Intezer HiddenWasp Map 2019)","relationship_id":"relationship--bf66a7c4-7d72-4769-a96a-83d3363fa7a9","references":[{"source_name":"Intezer HiddenWasp Map 2019","description":"Sanmillan, I. (2019, May 29). HiddenWasp Malware Stings Targeted Linux Systems. Retrieved June 24, 2019.","url":"https://www.intezer.com/blog-hiddenwasp-malware-targeting-linux-systems/"}]},{"id":"S0395","name":"LightNeuron","url":"https://attack.mitre.org/software/S0395","kind":"malware","description":"[LightNeuron](https://attack.mitre.org/software/S0395) has the ability to download and execute additional files.(Citation: ESET LightNeuron May 2019)","relationship_id":"relationship--80cc26ad-62b5-49f0-bb8d-bd588bd51585","references":[{"source_name":"ESET LightNeuron May 2019","description":"Faou, M. (2019, May). Turla LightNeuron: One email away from remote code execution. Retrieved June 24, 2019.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf"}]},{"id":"S0396","name":"EvilBunny","url":"https://attack.mitre.org/software/S0396","kind":"malware","description":"[EvilBunny](https://attack.mitre.org/software/S0396) has downloaded additional Lua scripts from the C2.(Citation: Cyphort EvilBunny Dec 2014)","relationship_id":"relationship--0109ee05-c2a9-4dcf-80d1-f859500c97c9","references":[{"source_name":"Cyphort EvilBunny Dec 2014","description":"Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.","url":"https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/"}]},{"id":"S0398","name":"HyperBro","url":"https://attack.mitre.org/software/S0398","kind":"malware","description":"[HyperBro](https://attack.mitre.org/software/S0398) has the ability to download additional files.(Citation: Unit42 Emissary Panda May 2019)","relationship_id":"relationship--c96b0cbe-7523-4ee6-ae73-b6a8cba3ea44","references":[{"source_name":"Unit42 Emissary Panda May 2019","description":"Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.","url":"https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/"}]},{"id":"S0401","name":"Exaramel for Linux","url":"https://attack.mitre.org/software/S0401","kind":"malware","description":"[Exaramel for Linux](https://attack.mitre.org/software/S0401) has a command to download a file from  and to a remote C2 server.(Citation: ESET TeleBots Oct 2018)(Citation: ANSSI Sandworm January 2021)","relationship_id":"relationship--15bb2796-7c6d-4d03-8d86-8d83254bcf0b","references":[{"source_name":"ESET TeleBots Oct 2018","description":"Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.","url":"https://www.welivesecurity.com/2018/10/11/new-telebots-backdoor-linking-industroyer-notpetya/"},{"source_name":"ANSSI Sandworm January 2021","description":"ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.","url":"https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf"}]},{"id":"S0402","name":"OSX/Shlayer","url":"https://attack.mitre.org/software/S0402","kind":"malware","description":"[OSX/Shlayer](https://attack.mitre.org/software/S0402) can download payloads, and extract bytes from files. [OSX/Shlayer](https://attack.mitre.org/software/S0402) uses the <code>curl -fsL \"$url\" >$tmp_path</code> command to download malicious payloads into a temporary directory.(Citation: Carbon Black Shlayer Feb 2019)(Citation: sentinelone shlayer to zshlayer)(Citation: 20 macOS Common Tools and Techniques)(Citation: objectivesee osx.shlayer apple approved 2020)","relationship_id":"relationship--bd79d063-3407-4da9-b6d1-6170a3b9edfc","references":[{"source_name":"Carbon Black Shlayer Feb 2019","description":"Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019.","url":"https://blogs.vmware.com/security/2020/02/vmware-carbon-black-tau-threat-analysis-shlayer-macos.html"},{"source_name":"objectivesee osx.shlayer apple approved 2020","description":"Patrick Wardle. (2020, August 30). Apple Approved Malware malicious code ...now notarized!? #2020. Retrieved September 13, 2021.","url":"https://objective-see.com/blog/blog_0x4E.html"},{"source_name":"sentinelone shlayer to zshlayer","description":"Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.","url":"https://www.sentinelone.com/blog/coming-out-of-your-shell-from-shlayer-to-zshlayer/"},{"source_name":"20 macOS Common Tools and Techniques","description":"Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.","url":"https://labs.sentinelone.com/20-common-tools-techniques-used-by-macos-threat-actors-malware/"}]},{"id":"S0404","name":"esentutl","url":"https://attack.mitre.org/software/S0404","kind":"tool","description":"[esentutl](https://attack.mitre.org/software/S0404) can be used to copy files from a given URL.(Citation: LOLBAS Esentutl)","relationship_id":"relationship--bb4f1b15-8382-44f9-b201-6726e83b79b0","references":[{"source_name":"LOLBAS Esentutl","description":"LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019.","url":"https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"}]},{"id":"S0409","name":"Machete","url":"https://attack.mitre.org/software/S0409","kind":"malware","description":" [Machete](https://attack.mitre.org/software/S0409) can download additional files for execution on the victim’s machine.(Citation: ESET Machete July 2019) ","relationship_id":"relationship--9901b17d-551e-4971-9ff7-7142e7c2bb4e","references":[{"source_name":"ESET Machete July 2019","description":"ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/08/ESET_Machete.pdf"}]},{"id":"S0412","name":"ZxShell","url":"https://attack.mitre.org/software/S0412","kind":"malware","description":"[ZxShell](https://attack.mitre.org/software/S0412) has a command to transfer files from a remote host.(Citation: Talos ZxShell Oct 2014) ","relationship_id":"relationship--ffffed15-5695-44b9-b85b-89ba8187415d","references":[{"source_name":"Talos ZxShell Oct 2014","description":"Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.","url":"https://blogs.cisco.com/security/talos/opening-zxshell"}]},{"id":"S0414","name":"BabyShark","url":"https://attack.mitre.org/software/S0414","kind":"malware","description":"[BabyShark](https://attack.mitre.org/software/S0414) has downloaded additional files from the C2.(Citation: Unit42 BabyShark Apr 2019)(Citation: CISA AA20-301A Kimsuky)","relationship_id":"relationship--18d97b33-8ad5-426e-a390-72bea109bee0","references":[{"source_name":"Unit42 BabyShark Apr 2019","description":"Lim, M.. (2019, April 26). BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat . Retrieved October 7, 2019.","url":"https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/"},{"source_name":"CISA AA20-301A Kimsuky","description":"CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.","url":"https://us-cert.cisa.gov/ncas/alerts/aa20-301a"}]},{"id":"S0428","name":"PoetRAT","url":"https://attack.mitre.org/software/S0428","kind":"malware","description":"[PoetRAT](https://attack.mitre.org/software/S0428) has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.(Citation: Talos PoetRAT April 2020)(Citation: Talos PoetRAT October 2020)","relationship_id":"relationship--3337112a-0b29-450f-9183-a0ec428c4898","references":[{"source_name":"Talos PoetRAT April 2020","description":"Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.","url":"https://blog.talosintelligence.com/2020/04/poetrat-covid-19-lures.html"},{"source_name":"Talos PoetRAT October 2020","description":"Mercer, W. Rascagneres, P. Ventura, V. (2020, October 6). PoetRAT: Malware targeting public and private sector in Azerbaijan evolves . Retrieved April 9, 2021.","url":"https://blog.talosintelligence.com/2020/10/poetrat-update.html"}]},{"id":"S0430","name":"Winnti for Linux","url":"https://attack.mitre.org/software/S0430","kind":"malware","description":"[Winnti for Linux](https://attack.mitre.org/software/S0430) has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host. (Citation: Chronicle Winnti for Linux May 2019)","relationship_id":"relationship--90925137-7ffe-46d6-82d4-0ad7748740a3","references":[{"source_name":"Chronicle Winnti for Linux May 2019","description":"Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020.","url":"https://medium.com/chronicle-blog/winnti-more-than-just-windows-and-gates-e4f03436031a"}]},{"id":"S0431","name":"HotCroissant","url":"https://attack.mitre.org/software/S0431","kind":"malware","description":"[HotCroissant](https://attack.mitre.org/software/S0431) has the ability to upload a file from the command and control (C2) server to the victim machine.(Citation: Carbon Black HotCroissant April 2020)","relationship_id":"relationship--967c2498-0f51-464f-b5e5-2a0539614033","references":[{"source_name":"Carbon Black HotCroissant April 2020","description":"Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.","url":"https://www.carbonblack.com/2020/04/16/vmware-carbon-black-tau-threat-analysis-the-evolution-of-lazarus/"}]},{"id":"S0435","name":"PLEAD","url":"https://attack.mitre.org/software/S0435","kind":"malware","description":"[PLEAD](https://attack.mitre.org/software/S0435) has the ability to upload and download files to and from an infected host.(Citation: JPCert PLEAD Downloader June 2018)","relationship_id":"relationship--9020d567-103b-4dc2-b27d-115078ae2a76","references":[{"source_name":"JPCert PLEAD Downloader June 2018","description":"Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.","url":"https://blogs.jpcert.or.jp/en/2018/03/malware-tscooki-7aa0.html"}]},{"id":"S0436","name":"TSCookie","url":"https://attack.mitre.org/software/S0436","kind":"malware","description":"[TSCookie](https://attack.mitre.org/software/S0436) has the ability to upload and download files to and from the infected host.(Citation: JPCert TSCookie March 2018)","relationship_id":"relationship--1e54c837-6d59-40dc-a114-3bcef0037327","references":[{"source_name":"JPCert TSCookie March 2018","description":"Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.","url":"https://blogs.jpcert.or.jp/en/2018/03/malware-tscooki-7aa0.html"}]},{"id":"S0437","name":"Kivars","url":"https://attack.mitre.org/software/S0437","kind":"malware","description":"[Kivars](https://attack.mitre.org/software/S0437) has the ability to download and execute files.(Citation: TrendMicro BlackTech June 2017)","relationship_id":"relationship--93dc6241-29b4-45c6-9593-f7862936ffd8","references":[{"source_name":"TrendMicro BlackTech June 2017","description":"Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/following-trail-blacktech-cyber-espionage-campaigns/"}]},{"id":"S0438","name":"Attor","url":"https://attack.mitre.org/software/S0438","kind":"malware","description":"[Attor](https://attack.mitre.org/software/S0438) can download additional plugins, updates and other files. (Citation: ESET Attor Oct 2019)","relationship_id":"relationship--57a19f3b-838f-45df-8cfe-964cbe5396d2","references":[{"source_name":"ESET Attor Oct 2019","description":"Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Attor.pdf"}]},{"id":"S0439","name":"Okrum","url":"https://attack.mitre.org/software/S0439","kind":"malware","description":"[Okrum](https://attack.mitre.org/software/S0439) has built-in commands for uploading, downloading, and executing files to the system.(Citation: ESET Okrum July 2019)","relationship_id":"relationship--140dda5e-b3d5-47ce-aac5-22060d5bddf2","references":[{"source_name":"ESET Okrum July 2019","description":"Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/07/ESET_Okrum_and_Ketrican.pdf"}]},{"id":"S0442","name":"VBShower","url":"https://attack.mitre.org/software/S0442","kind":"malware","description":"[VBShower](https://attack.mitre.org/software/S0442) has the ability to download VBS files to the target computer.(Citation: Kaspersky Cloud Atlas August 2019)","relationship_id":"relationship--fe3b8cb8-8ff1-4abf-ac98-ce31108e5bb5","references":[{"source_name":"Kaspersky Cloud Atlas August 2019","description":"GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.","url":"https://securelist.com/recent-cloud-atlas-activity/92016/"}]},{"id":"S0444","name":"ShimRat","url":"https://attack.mitre.org/software/S0444","kind":"malware","description":"[ShimRat](https://attack.mitre.org/software/S0444) can download additional files.(Citation: FOX-IT May 2016 Mofang)","relationship_id":"relationship--0177d430-a0b9-4f2f-8c66-8dfa4391611a","references":[{"source_name":"FOX-IT May 2016 Mofang","description":"Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.","url":"https://foxitsecurity.files.wordpress.com/2016/06/fox-it_mofang_threatreport_tlp-white.pdf"}]},{"id":"S0445","name":"ShimRatReporter","url":"https://attack.mitre.org/software/S0445","kind":"tool","description":"[ShimRatReporter](https://attack.mitre.org/software/S0445) had the ability to download additional payloads.(Citation: FOX-IT May 2016 Mofang)","relationship_id":"relationship--137f13ee-0607-47ba-952b-dbe39c1330bb","references":[{"source_name":"FOX-IT May 2016 Mofang","description":"Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.","url":"https://foxitsecurity.files.wordpress.com/2016/06/fox-it_mofang_threatreport_tlp-white.pdf"}]},{"id":"S0447","name":"Lokibot","url":"https://attack.mitre.org/software/S0447","kind":"malware","description":"[Lokibot](https://attack.mitre.org/software/S0447) downloaded several staged items onto the victim's machine.(Citation: Talos Lokibot Jan 2021) ","relationship_id":"relationship--f7328802-07f4-4f00-821a-962fb2678e15","references":[{"source_name":"Talos Lokibot Jan 2021","description":"Muhammad, I., Unterbrink, H.. (2021, January 6). A Deep Dive into Lokibot Infection Chain. Retrieved August 31, 2021.","url":"https://blog.talosintelligence.com/2021/01/a-deep-dive-into-lokibot-infection-chain.html"}]},{"id":"S0450","name":"SHARPSTATS","url":"https://attack.mitre.org/software/S0450","kind":"malware","description":"[SHARPSTATS](https://attack.mitre.org/software/S0450) has the ability to upload and download files.(Citation: TrendMicro POWERSTATS V3 June 2019)","relationship_id":"relationship--8f0afd2b-8cb3-4b5b-b19f-39887602fe95","references":[{"source_name":"TrendMicro POWERSTATS V3 June 2019","description":"Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/muddywater-resurfaces-uses-multi-stage-backdoor-powerstats-v3-and-new-post-exploitation-tools/"}]},{"id":"S0451","name":"LoudMiner","url":"https://attack.mitre.org/software/S0451","kind":"malware","description":"[LoudMiner](https://attack.mitre.org/software/S0451) used SCP to update the miner from the C2.(Citation: ESET LoudMiner June 2019)","relationship_id":"relationship--8f43b5c3-883a-40b7-b9b2-a96ba8c7001b","references":[{"source_name":"ESET LoudMiner June 2019","description":"Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.","url":"https://www.welivesecurity.com/2019/06/20/loudminer-mining-cracked-vst-software/"}]},{"id":"S0453","name":"Pony","url":"https://attack.mitre.org/software/S0453","kind":"malware","description":"[Pony](https://attack.mitre.org/software/S0453) can download additional files onto the infected system.(Citation: Malwarebytes Pony April 2016)\t","relationship_id":"relationship--3ea6e72b-3d19-4864-aebd-cc31dad7d519","references":[{"source_name":"Malwarebytes Pony April 2016","description":"hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020.","url":"https://blog.malwarebytes.com/threat-analysis/2015/11/no-money-but-pony-from-a-mail-to-a-trojan-horse/"}]},{"id":"S0455","name":"Metamorfo","url":"https://attack.mitre.org/software/S0455","kind":"malware","description":"[Metamorfo](https://attack.mitre.org/software/S0455) has used MSI files to download additional files to execute.(Citation: Medium Metamorfo Apr 2020)(Citation: FireEye Metamorfo Apr 2018)(Citation: Fortinet Metamorfo Feb 2020)(Citation: ESET Casbaneiro Oct 2019) ","relationship_id":"relationship--de745ef4-59a0-470c-95c9-5043a717dc54","references":[{"source_name":"Medium Metamorfo Apr 2020","description":"Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.","url":"https://medium.com/@chenerlich/the-avast-abuser-metamorfo-banking-malware-hides-by-abusing-avast-executable-ac9b8b392767"},{"source_name":"FireEye Metamorfo Apr 2018","description":"Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.","url":"https://www.fireeye.com/blog/threat-research/2018/04/metamorfo-campaign-targeting-brazilian-users.html"},{"source_name":"Fortinet Metamorfo Feb 2020","description":"Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.","url":"https://www.fortinet.com/blog/threat-research/another-metamorfo-variant-targeting-customers-of-financial-institutions"},{"source_name":"ESET Casbaneiro Oct 2019","description":"ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.","url":"https://www.welivesecurity.com/2019/10/03/casbaneiro-trojan-dangerous-cooking/"}]},{"id":"S0456","name":"Aria-body","url":"https://attack.mitre.org/software/S0456","kind":"malware","description":"[Aria-body](https://attack.mitre.org/software/S0456) has the ability to download additional payloads from C2.(Citation: CheckPoint Naikon May 2020)","relationship_id":"relationship--cbb686ae-3dc8-4e91-80fc-075209505425","references":[{"source_name":"CheckPoint Naikon May 2020","description":"CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.","url":"https://research.checkpoint.com/2020/naikon-apt-cyber-espionage-reloaded/"}]},{"id":"S0457","name":"Netwalker","url":"https://attack.mitre.org/software/S0457","kind":"malware","description":"Operators deploying [Netwalker](https://attack.mitre.org/software/S0457) have used psexec and certutil to retrieve the [Netwalker](https://attack.mitre.org/software/S0457) payload.(Citation: Sophos Netwalker May 2020)","relationship_id":"relationship--ed0e96e6-6b71-468a-9e76-477ed3765ca4","references":[{"source_name":"Sophos Netwalker May 2020","description":"Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.","url":"https://news.sophos.com/en-us/2020/05/27/netwalker-ransomware-tools-give-insight-into-threat-actor/"}]},{"id":"S0459","name":"MechaFlounder","url":"https://attack.mitre.org/software/S0459","kind":"malware","description":"[MechaFlounder](https://attack.mitre.org/software/S0459) has the ability to upload and download files to and from a compromised host.(Citation: Unit 42 MechaFlounder March 2019)","relationship_id":"relationship--b96089fa-ebca-4d3c-9290-473cb98ad577","references":[{"source_name":"Unit 42 MechaFlounder March 2019","description":"Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.","url":"https://unit42.paloaltonetworks.com/new-python-based-payload-mechaflounder-used-by-chafer/"}]},{"id":"S0461","name":"SDBbot","url":"https://attack.mitre.org/software/S0461","kind":"malware","description":"[SDBbot](https://attack.mitre.org/software/S0461) has the ability to download a DLL from C2 to a compromised host.(Citation: Proofpoint TA505 October 2019)","relationship_id":"relationship--7ef04aca-4890-4035-8c0b-69d9a78e8029","references":[{"source_name":"Proofpoint TA505 October 2019","description":"Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.","url":"https://www.proofpoint.com/us/threat-insight/post/ta505-distributes-new-sdbbot-remote-access-trojan-get2-downloader"}]},{"id":"S0462","name":"CARROTBAT","url":"https://attack.mitre.org/software/S0462","kind":"malware","description":"[CARROTBAT](https://attack.mitre.org/software/S0462) has the ability to download and execute a remote file via [certutil](https://attack.mitre.org/software/S0160).(Citation: Unit 42 CARROTBAT November 2018)","relationship_id":"relationship--9e81f24e-6f72-44eb-9f19-2a3e7dca14ad","references":[{"source_name":"Unit 42 CARROTBAT November 2018","description":"Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"id":"S0465","name":"CARROTBALL","url":"https://attack.mitre.org/software/S0465","kind":"tool","description":"[CARROTBALL](https://attack.mitre.org/software/S0465) has the ability to download and install a remote payload.(Citation: Unit 42 CARROTBAT January 2020)","relationship_id":"relationship--6d5221c3-2efa-4374-8842-8c955fda112b","references":[{"source_name":"Unit 42 CARROTBAT January 2020","description":"McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.","url":"https://unit42.paloaltonetworks.com/the-fractured-statue-campaign-u-s-government-targeted-in-spear-phishing-attacks/"}]},{"id":"S0468","name":"Skidmap","url":"https://attack.mitre.org/software/S0468","kind":"malware","description":"[Skidmap](https://attack.mitre.org/software/S0468) has the ability to download files on an infected host.(Citation: Trend Micro Skidmap) ","relationship_id":"relationship--1eb0fe9c-86e9-4c8c-8a24-c7b139559971","references":[{"source_name":"Trend Micro Skidmap","description":"Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/skidmap-linux-malware-uses-rootkit-capabilities-to-hide-cryptocurrency-mining-payload/"}]},{"id":"S0469","name":"ABK","url":"https://attack.mitre.org/software/S0469","kind":"malware","description":"[ABK](https://attack.mitre.org/software/S0469) has the ability to download files from C2.(Citation: Trend Micro Tick November 2019)","relationship_id":"relationship--9ffa4f56-8fe5-4439-897d-df432bccb52d","references":[{"source_name":"Trend Micro Tick November 2019","description":"Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.","url":"https://documents.trendmicro.com/assets/pdf/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf"}]},{"id":"S0470","name":"BBK","url":"https://attack.mitre.org/software/S0470","kind":"malware","description":"[BBK](https://attack.mitre.org/software/S0470) has the ability to download files from C2 to the infected host.(Citation: Trend Micro Tick November 2019)","relationship_id":"relationship--576db5e8-7371-4dea-ada9-599cc231e727","references":[{"source_name":"Trend Micro Tick November 2019","description":"Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.","url":"https://documents.trendmicro.com/assets/pdf/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf"}]},{"id":"S0471","name":"build_downer","url":"https://attack.mitre.org/software/S0471","kind":"malware","description":"[build_downer](https://attack.mitre.org/software/S0471) has the ability to download files from C2 to the infected host.(Citation: Trend Micro Tick November 2019)","relationship_id":"relationship--d870ed48-a7df-4aee-af06-c58ee59432e7","references":[{"source_name":"Trend Micro Tick November 2019","description":"Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.","url":"https://documents.trendmicro.com/assets/pdf/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf"}]},{"id":"S0472","name":"down_new","url":"https://attack.mitre.org/software/S0472","kind":"malware","description":"[down_new](https://attack.mitre.org/software/S0472) has the ability to download files to the compromised host.(Citation: Trend Micro Tick November 2019)","relationship_id":"relationship--0efece7a-dc3a-46e1-b56c-7db9e3b61149","references":[{"source_name":"Trend Micro Tick November 2019","description":"Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.","url":"https://documents.trendmicro.com/assets/pdf/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf"}]},{"id":"S0473","name":"Avenger","url":"https://attack.mitre.org/software/S0473","kind":"malware","description":"[Avenger](https://attack.mitre.org/software/S0473) has the ability to download files from C2 to a compromised host.(Citation: Trend Micro Tick November 2019)","relationship_id":"relationship--96c91811-fec3-43a6-890f-08921e543325","references":[{"source_name":"Trend Micro Tick November 2019","description":"Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.","url":"https://documents.trendmicro.com/assets/pdf/Operation-ENDTRADE-TICK-s-Multi-Stage-Backdoors-for-Attacking-Industries-and-Stealing-Classified-Data.pdf"}]},{"id":"S0475","name":"BackConfig","url":"https://attack.mitre.org/software/S0475","kind":"malware","description":"[BackConfig](https://attack.mitre.org/software/S0475) can download and execute additional payloads on a compromised host.(Citation: Unit 42 BackConfig May 2020)","relationship_id":"relationship--197ade21-6787-4ed3-a3ce-ff4b59b2f15c","references":[{"source_name":"Unit 42 BackConfig May 2020","description":"Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.","url":"https://unit42.paloaltonetworks.com/updated-backconfig-malware-targeting-government-and-military-organizations/"}]},{"id":"S0476","name":"Valak","url":"https://attack.mitre.org/software/S0476","kind":"malware","description":"[Valak](https://attack.mitre.org/software/S0476) has downloaded a variety of modules and payloads to the compromised host, including [IcedID](https://attack.mitre.org/software/S0483) and NetSupport Manager RAT-based malware.(Citation: Unit 42 Valak July 2020)(Citation: Cybereason Valak May 2020)","relationship_id":"relationship--86ce6e35-bf83-4d55-a3c8-3ac2e2d2f872","references":[{"source_name":"Unit 42 Valak July 2020","description":"Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.","url":"https://unit42.paloaltonetworks.com/valak-evolution/"},{"source_name":"Cybereason Valak May 2020","description":"Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.","url":"https://www.cybereason.com/blog/valak-more-than-meets-the-eye"}]},{"id":"S0482","name":"Bundlore","url":"https://attack.mitre.org/software/S0482","kind":"malware","description":"[Bundlore](https://attack.mitre.org/software/S0482) can download and execute new versions of itself.(Citation: MacKeeper Bundlore Apr 2019)","relationship_id":"relationship--6b69d848-b3d9-4f8f-96dc-381e1dd793d4","references":[{"source_name":"MacKeeper Bundlore Apr 2019","description":"Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.","url":"https://mackeeper.com/blog/post/610-macos-bundlore-adware-analysis/"}]},{"id":"S0483","name":"IcedID","url":"https://attack.mitre.org/software/S0483","kind":"malware","description":"[IcedID](https://attack.mitre.org/software/S0483) has the ability to download additional modules and a configuration file from C2.(Citation: IBM IcedID November 2017)(Citation: Juniper IcedID June 2020)(Citation: DFIR_Quantum_Ransomware)(Citation: Latrodectus APR 2024)","relationship_id":"relationship--a8484e9d-ad08-4d2c-8328-24552dd22f35","references":[{"source_name":"DFIR_Quantum_Ransomware","description":"DFIR. (2022, April 25). Quantum Ransomware. Retrieved July 26, 2024.","url":"https://thedfirreport.com/2022/04/25/quantum-ransomware/"},{"source_name":"IBM IcedID November 2017","description":"Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020.","url":"https://securityintelligence.com/new-banking-trojan-icedid-discovered-by-ibm-x-force-research/"},{"source_name":"Juniper IcedID June 2020","description":"Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.","url":"https://blogs.juniper.net/en-us/threat-research/covid-19-and-fmla-campaigns-used-to-install-new-icedid-banking-malware"},{"source_name":"Latrodectus APR 2024","description":"Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.","url":"https://www.proofpoint.com/us/blog/threat-insight/latrodectus-spider-bytes-ice"}]},{"id":"S0484","name":"Carberp","url":"https://attack.mitre.org/software/S0484","kind":"malware","description":"[Carberp](https://attack.mitre.org/software/S0484) can download and execute new plugins from the C2 server. (Citation: Prevx Carberp March 2011)(Citation: Trusteer Carberp October 2010)","relationship_id":"relationship--320966af-53db-41e3-aaf0-f5fd68bce8ca","references":[{"source_name":"Prevx Carberp March 2011","description":"Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.","url":"https://web.archive.org/web/20231227000328/http://pxnow.prevx.com/content/blog/carberp-a_modular_information_stealing_trojan.pdf"},{"source_name":"Trusteer Carberp October 2010","description":"Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.","url":"https://web.archive.org/web/20111004014029/http://www.trusteer.com/sites/default/files/Carberp_Analysis.pdf"}]},{"id":"S0486","name":"Bonadan","url":"https://attack.mitre.org/software/S0486","kind":"malware","description":"[Bonadan](https://attack.mitre.org/software/S0486) can download additional modules from the C2 server.(Citation: ESET ForSSHe December 2018)","relationship_id":"relationship--db2b0471-38e9-4c50-bf96-1c498f38223c","references":[{"source_name":"ESET ForSSHe December 2018","description":"Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf"}]},{"id":"S0487","name":"Kessel","url":"https://attack.mitre.org/software/S0487","kind":"malware","description":"[Kessel](https://attack.mitre.org/software/S0487) can download additional modules from the C2 server.(Citation: ESET ForSSHe December 2018)","relationship_id":"relationship--25f5e7b1-4f7f-48e1-b647-16a4ac018357","references":[{"source_name":"ESET ForSSHe December 2018","description":"Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf"}]},{"id":"S0491","name":"StrongPity","url":"https://attack.mitre.org/software/S0491","kind":"malware","description":"[StrongPity](https://attack.mitre.org/software/S0491) can download files to specified targets.(Citation: Bitdefender StrongPity June 2020)","relationship_id":"relationship--c7cf767a-fa78-4ca7-9bd1-612d51d0c098","references":[{"source_name":"Bitdefender StrongPity June 2020","description":"Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/353/Bitdefender-Whitepaper-StrongPity-APT.pdf"}]},{"id":"S0492","name":"CookieMiner","url":"https://attack.mitre.org/software/S0492","kind":"malware","description":"[CookieMiner](https://attack.mitre.org/software/S0492) can download additional scripts from a web server.(Citation: Unit42 CookieMiner Jan 2019)","relationship_id":"relationship--7f249ef4-8a3c-4ab5-998f-256ac8ecf588","references":[{"source_name":"Unit42 CookieMiner Jan 2019","description":"Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020.","url":"https://unit42.paloaltonetworks.com/mac-malware-steals-cryptocurrency-exchanges-cookies/"}]},{"id":"S0493","name":"GoldenSpy","url":"https://attack.mitre.org/software/S0493","kind":"malware","description":"[GoldenSpy](https://attack.mitre.org/software/S0493) constantly attempts to download and execute files from the remote C2, including [GoldenSpy](https://attack.mitre.org/software/S0493) itself if not found on the system.(Citation: Trustwave GoldenSpy June 2020)\t","relationship_id":"relationship--b6d77871-1b71-4b65-b04b-9ee1d4b80a9c","references":[{"source_name":"Trustwave GoldenSpy June 2020","description":"Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.","url":"https://www.trustwave.com/en-us/resources/library/documents/the-golden-tax-department-and-the-emergence-of-goldenspy-malware/"}]},{"id":"S0495","name":"RDAT","url":"https://attack.mitre.org/software/S0495","kind":"malware","description":"[RDAT](https://attack.mitre.org/software/S0495) can download files via DNS.(Citation: Unit42 RDAT July 2020)\t","relationship_id":"relationship--abca8fe1-0303-43a8-b469-a7921358a3f1","references":[{"source_name":"Unit42 RDAT July 2020","description":"Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.","url":"https://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/"}]},{"id":"S0496","name":"REvil","url":"https://attack.mitre.org/software/S0496","kind":"malware","description":"[REvil](https://attack.mitre.org/software/S0496) can download a copy of itself from an attacker controlled IP address to the victim machine.(Citation: Talos Sodinokibi April 2019)(Citation: McAfee Sodinokibi October 2019)(Citation: Picus Sodinokibi January 2020)","relationship_id":"relationship--a910e0f8-1548-4dd6-a0eb-19430a5f75b0","references":[{"source_name":"Talos Sodinokibi April 2019","description":"Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.","url":"https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html"},{"source_name":"McAfee Sodinokibi October 2019","description":"McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.","url":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/"},{"source_name":"Picus Sodinokibi January 2020","description":"Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.","url":"https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware"}]},{"id":"S0497","name":"Dacls","url":"https://attack.mitre.org/software/S0497","kind":"malware","description":"[Dacls](https://attack.mitre.org/software/S0497) can download its payload from a C2 server.(Citation: SentinelOne Lazarus macOS July 2020)(Citation: TrendMicro macOS Dacls May 2020)","relationship_id":"relationship--38affc70-544f-4211-be66-0d09f7882edb","references":[{"source_name":"SentinelOne Lazarus macOS July 2020","description":"Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.","url":"https://www.sentinelone.com/blog/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/"},{"source_name":"TrendMicro macOS Dacls May 2020","description":"Mabutas, G. (2020, May 11). New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability. Retrieved August 10, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/new-macos-dacls-rat-backdoor-show-lazarus-multi-platform-attack-capability/"}]},{"id":"S0498","name":"Cryptoistic","url":"https://attack.mitre.org/software/S0498","kind":"malware","description":"[Cryptoistic](https://attack.mitre.org/software/S0498) has the ability to send and receive files.(Citation: SentinelOne Lazarus macOS July 2020)","relationship_id":"relationship--dc802d43-a21f-4871-a281-4896817b9bc1","references":[{"source_name":"SentinelOne Lazarus macOS July 2020","description":"Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.","url":"https://www.sentinelone.com/blog/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/"}]},{"id":"S0499","name":"Hancitor","url":"https://attack.mitre.org/software/S0499","kind":"malware","description":"[Hancitor](https://attack.mitre.org/software/S0499) has the ability to download additional files from C2.(Citation: Threatpost Hancitor)","relationship_id":"relationship--3d902953-306b-48d4-be7b-f08030ecb62e","references":[{"source_name":"Threatpost Hancitor","description":"Tom Spring. (2017, January 11). Spammers Revive Hancitor Downloader Campaigns. Retrieved August 13, 2020.","url":"https://threatpost.com/spammers-revive-hancitor-downloader-campaigns/123011/"}]},{"id":"S0500","name":"MCMD","url":"https://attack.mitre.org/software/S0500","kind":"tool","description":"[MCMD](https://attack.mitre.org/software/S0500) can upload additional files to a compromised host.(Citation: Secureworks MCMD July 2019)","relationship_id":"relationship--ceaf4145-f168-4bba-8480-d3650bcc657f","references":[{"source_name":"Secureworks MCMD July 2019","description":"Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.","url":"https://www.secureworks.com/research/mcmd-malware-analysis"}]},{"id":"S0501","name":"PipeMon","url":"https://attack.mitre.org/software/S0501","kind":"malware","description":"[PipeMon](https://attack.mitre.org/software/S0501) can install additional modules via C2 commands.(Citation: ESET PipeMon May 2020)","relationship_id":"relationship--3e18f486-1e6f-49fa-8b99-4daf615d3e8d","references":[{"source_name":"ESET PipeMon May 2020","description":"Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.","url":"https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/"}]},{"id":"S0502","name":"Drovorub","url":"https://attack.mitre.org/software/S0502","kind":"malware","description":"[Drovorub](https://attack.mitre.org/software/S0502) can download files to a compromised host.(Citation: NSA/FBI Drovorub August 2020)","relationship_id":"relationship--f3b7dbe2-1dd5-4d57-a5ef-1764775d5c99","references":[{"source_name":"NSA/FBI Drovorub August 2020","description":"NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.","url":"https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF"}]},{"id":"S0504","name":"Anchor","url":"https://attack.mitre.org/software/S0504","kind":"malware","description":"[Anchor](https://attack.mitre.org/software/S0504) can download additional payloads.(Citation: Cyberreason Anchor December 2019)(Citation: Medium Anchor DNS July 2020)","relationship_id":"relationship--116996cd-b855-4730-814d-869fd90e7ce1","references":[{"source_name":"Cyberreason Anchor December 2019","description":"Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.","url":"https://www.cybereason.com/blog/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware"},{"source_name":"Medium Anchor DNS July 2020","description":"Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.","url":"https://medium.com/stage-2-security/anchor-dns-malware-family-goes-cross-platform-d807ba13ca30"}]},{"id":"S0511","name":"RegDuke","url":"https://attack.mitre.org/software/S0511","kind":"malware","description":"[RegDuke](https://attack.mitre.org/software/S0511) can download files from C2.(Citation: ESET Dukes October 2019)","relationship_id":"relationship--342b69ad-118b-467d-838e-33ffa931af29","references":[{"source_name":"ESET Dukes October 2019","description":"Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf"}]},{"id":"S0513","name":"LiteDuke","url":"https://attack.mitre.org/software/S0513","kind":"malware","description":"[LiteDuke](https://attack.mitre.org/software/S0513) has the ability to download files.(Citation: ESET Dukes October 2019)","relationship_id":"relationship--a34352d8-8dc9-4721-9e73-ae56f5a886e7","references":[{"source_name":"ESET Dukes October 2019","description":"Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf"}]},{"id":"S0514","name":"WellMess","url":"https://attack.mitre.org/software/S0514","kind":"malware","description":"[WellMess](https://attack.mitre.org/software/S0514) can write files to a compromised host.(Citation: PWC WellMess July 2020)(Citation: CISA WellMess July 2020)","relationship_id":"relationship--6204f142-a2a7-406f-9874-af8f3bb9dca9","references":[{"source_name":"PWC WellMess July 2020","description":"PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.","url":"https://www.pwc.co.uk/issues/cyber-security-services/insights/cleaning-up-after-wellmess.html"},{"source_name":"CISA WellMess July 2020","description":"CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-198b"}]},{"id":"S0515","name":"WellMail","url":"https://attack.mitre.org/software/S0515","kind":"malware","description":"[WellMail](https://attack.mitre.org/software/S0515) can receive data and executable scripts from C2.(Citation: CISA WellMail July 2020)","relationship_id":"relationship--05dc9f8c-a1ea-4cdf-ae86-e98af40d5bd7","references":[{"source_name":"CISA WellMail July 2020","description":"CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-198c"}]},{"id":"S0516","name":"SoreFang","url":"https://attack.mitre.org/software/S0516","kind":"malware","description":"[SoreFang](https://attack.mitre.org/software/S0516) can download additional payloads from C2.(Citation: CISA SoreFang July 2016)(Citation: NCSC APT29 July 2020)","relationship_id":"relationship--0aebf9e4-9730-45ce-877d-f78432c13fad","references":[{"source_name":"CISA SoreFang July 2016","description":"CISA. (2020, July 16). MAR-10296782-1.v1 – SOREFANG. Retrieved September 29, 2020.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-198a"},{"source_name":"NCSC APT29 July 2020","description":"National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.","url":"https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf"}]},{"id":"S0518","name":"PolyglotDuke","url":"https://attack.mitre.org/software/S0518","kind":"malware","description":"[PolyglotDuke](https://attack.mitre.org/software/S0518) can retrieve payloads from the C2 server.(Citation: ESET Dukes October 2019)","relationship_id":"relationship--28d3336f-108b-40fb-b3d7-9ec4311931c4","references":[{"source_name":"ESET Dukes October 2019","description":"Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf"}]},{"id":"S0520","name":"BLINDINGCAN","url":"https://attack.mitre.org/software/S0520","kind":"malware","description":"[BLINDINGCAN](https://attack.mitre.org/software/S0520) has downloaded files to a victim machine.(Citation: US-CERT BLINDINGCAN Aug 2020)","relationship_id":"relationship--1c33c9cd-afac-490a-b487-bd97c93a14cc","references":[{"source_name":"US-CERT BLINDINGCAN Aug 2020","description":"US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-232a"}]},{"id":"S0526","name":"KGH_SPY","url":"https://attack.mitre.org/software/S0526","kind":"malware","description":"[KGH_SPY](https://attack.mitre.org/software/S0526) has the ability to download and execute code from remote servers.(Citation: Cybereason Kimsuky November 2020)","relationship_id":"relationship--8f55bbbb-7404-4872-9832-c884297cdbe9","references":[{"source_name":"Cybereason Kimsuky November 2020","description":"Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.","url":"https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite"}]},{"id":"S0527","name":"CSPY Downloader","url":"https://attack.mitre.org/software/S0527","kind":"tool","description":"[CSPY Downloader](https://attack.mitre.org/software/S0527) can download additional tools to a compromised host.(Citation: Cybereason Kimsuky November 2020)","relationship_id":"relationship--6213e3cf-c18e-47de-b281-07aa3c3179db","references":[{"source_name":"Cybereason Kimsuky November 2020","description":"Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.","url":"https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite"}]},{"id":"S0528","name":"Javali","url":"https://attack.mitre.org/software/S0528","kind":"malware","description":"[Javali](https://attack.mitre.org/software/S0528) can download payloads from remote C2 servers.(Citation: Securelist Brazilian Banking Malware July 2020)","relationship_id":"relationship--fe518957-8722-498f-8da0-4b5eca466cef","references":[{"source_name":"Securelist Brazilian Banking Malware July 2020","description":"GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.","url":"https://securelist.com/the-tetrade-brazilian-banking-malware/97779/"}]},{"id":"S0530","name":"Melcoz","url":"https://attack.mitre.org/software/S0530","kind":"malware","description":"[Melcoz](https://attack.mitre.org/software/S0530) has the ability to download additional files to a compromised host.(Citation: Securelist Brazilian Banking Malware July 2020)","relationship_id":"relationship--57ad2c1a-785c-46ad-bdf1-2f9afe2389e8","references":[{"source_name":"Securelist Brazilian Banking Malware July 2020","description":"GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.","url":"https://securelist.com/the-tetrade-brazilian-banking-malware/97779/"}]},{"id":"S0531","name":"Grandoreiro","url":"https://attack.mitre.org/software/S0531","kind":"malware","description":"[Grandoreiro](https://attack.mitre.org/software/S0531) can download its second stage from a hardcoded URL within the loader's code.(Citation: IBM Grandoreiro April 2020)(Citation: ESET Grandoreiro April 2020)","relationship_id":"relationship--213522ec-117d-4ac8-82c7-b297fe7c26b4","references":[{"source_name":"IBM Grandoreiro April 2020","description":"Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.","url":"https://securityintelligence.com/posts/grandoreiro-malware-now-targeting-banks-in-spain/"},{"source_name":"ESET Grandoreiro April 2020","description":"ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.","url":"https://www.welivesecurity.com/2020/04/28/grandoreiro-how-engorged-can-exe-get/"}]},{"id":"S0532","name":"Lucifer","url":"https://attack.mitre.org/software/S0532","kind":"malware","description":"[Lucifer](https://attack.mitre.org/software/S0532) can download and execute a replica of itself using [certutil](https://attack.mitre.org/software/S0160).(Citation: Unit 42 Lucifer June 2020)","relationship_id":"relationship--322a78a2-1765-414f-9b07-29a1360e1134","references":[{"source_name":"Unit 42 Lucifer June 2020","description":"Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.","url":"https://unit42.paloaltonetworks.com/lucifer-new-cryptojacking-and-ddos-hybrid-malware/"}]},{"id":"S0533","name":"SLOTHFULMEDIA","url":"https://attack.mitre.org/software/S0533","kind":"malware","description":"[SLOTHFULMEDIA](https://attack.mitre.org/software/S0533) has downloaded files onto a victim machine.(Citation: CISA MAR SLOTHFULMEDIA October 2020)","relationship_id":"relationship--99f5f421-c462-472c-9aa8-29a4316c3f5e","references":[{"source_name":"CISA MAR SLOTHFULMEDIA October 2020","description":"DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-275a"}]},{"id":"S0534","name":"Bazar","url":"https://attack.mitre.org/software/S0534","kind":"malware","description":"[Bazar](https://attack.mitre.org/software/S0534) can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as [Cobalt Strike](https://attack.mitre.org/software/S0154).(Citation: Cybereason Bazar July 2020)(Citation: Zscaler Bazar September 2020)(Citation: NCC Group Team9 June 2020)(Citation: CrowdStrike Wizard Spider October 2020)","relationship_id":"relationship--c646d6ed-e0f6-48b0-a4a3-d52b0a21f250","references":[{"source_name":"Cybereason Bazar July 2020","description":"Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.","url":"https://www.cybereason.com/blog/a-bazar-of-tricks-following-team9s-development-cycles"},{"source_name":"Zscaler Bazar September 2020","description":"Sadique, M. and Singh, A. (2020, September 29). Spear Phishing Campaign Delivers Buer and Bazar Malware. Retrieved November 19, 2020.","url":"https://www.zscaler.com/blogs/research/spear-phishing-campaign-delivers-buer-and-bazar-malware"},{"source_name":"NCC Group Team9 June 2020","description":"Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.","url":"https://research.nccgroup.com/2020/06/02/in-depth-analysis-of-the-new-team9-malware-family/"},{"source_name":"CrowdStrike Wizard Spider October 2020","description":"Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.","url":"https://www.crowdstrike.com/blog/wizard-spider-adversary-update/"}]},{"id":"S0546","name":"SharpStage","url":"https://attack.mitre.org/software/S0546","kind":"malware","description":"[SharpStage](https://attack.mitre.org/software/S0546) has the ability to download and execute additional payloads via a DropBox API.(Citation: Cybereason Molerats Dec 2020)(Citation: BleepingComputer Molerats Dec 2020)","relationship_id":"relationship--72babf5f-f117-4a1c-a453-6e6c16c355c4","references":[{"source_name":"Cybereason Molerats Dec 2020","description":"Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.","url":"https://www.cybereason.com/hubfs/dam/collateral/reports/Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf"},{"source_name":"BleepingComputer Molerats Dec 2020","description":"Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.","url":"https://www.bleepingcomputer.com/news/security/hacking-group-s-new-malware-abuses-google-and-facebook-services/"}]},{"id":"S0547","name":"DropBook","url":"https://attack.mitre.org/software/S0547","kind":"malware","description":"[DropBook](https://attack.mitre.org/software/S0547) can download and execute additional files.(Citation: Cybereason Molerats Dec 2020)(Citation: BleepingComputer Molerats Dec 2020)","relationship_id":"relationship--867a1701-c263-4582-ad1c-7c0baae2cf23","references":[{"source_name":"Cybereason Molerats Dec 2020","description":"Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.","url":"https://www.cybereason.com/hubfs/dam/collateral/reports/Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf"},{"source_name":"BleepingComputer Molerats Dec 2020","description":"Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.","url":"https://www.bleepingcomputer.com/news/security/hacking-group-s-new-malware-abuses-google-and-facebook-services/"}]},{"id":"S0553","name":"MoleNet","url":"https://attack.mitre.org/software/S0553","kind":"malware","description":"[MoleNet](https://attack.mitre.org/software/S0553) can download additional payloads from the C2.(Citation: Cybereason Molerats Dec 2020) ","relationship_id":"relationship--cca578fe-fe2d-44ef-bc55-9518f83f1443","references":[{"source_name":"Cybereason Molerats Dec 2020","description":"Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.","url":"https://www.cybereason.com/hubfs/dam/collateral/reports/Molerats-in-the-Cloud-New-Malware-Arsenal-Abuses-Cloud-Platforms-in-Middle-East-Espionage-Campaign.pdf"}]},{"id":"S0554","name":"Egregor","url":"https://attack.mitre.org/software/S0554","kind":"malware","description":"[Egregor](https://attack.mitre.org/software/S0554) has the ability to download files from its C2 server.(Citation: Cybereason Egregor Nov 2020)(Citation: Intrinsec Egregor Nov 2020)","relationship_id":"relationship--87182fef-ddbc-466e-b55b-989f10592d0c","references":[{"source_name":"Cybereason Egregor Nov 2020","description":"Rochberger, L. (2020, November 26). Cybereason vs. Egregor Ransomware. Retrieved December 30, 2020.","url":"https://www.cybereason.com/blog/cybereason-vs-egregor-ransomware"},{"source_name":"Intrinsec Egregor Nov 2020","description":"Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.","url":"https://www.intrinsec.com/egregor-prolock/?cn-reloaded=1"}]},{"id":"S0559","name":"SUNBURST","url":"https://attack.mitre.org/software/S0559","kind":"malware","description":"[SUNBURST](https://attack.mitre.org/software/S0559) delivered different payloads, including [TEARDROP](https://attack.mitre.org/software/S0560) in at least one instance.(Citation: FireEye SUNBURST Backdoor December 2020)","relationship_id":"relationship--e83fb711-3ce0-4c6a-a8b2-0efb96551b99","references":[{"source_name":"FireEye SUNBURST Backdoor December 2020","description":"FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.","url":"https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html"}]},{"id":"S0561","name":"GuLoader","url":"https://attack.mitre.org/software/S0561","kind":"malware","description":"[GuLoader](https://attack.mitre.org/software/S0561) can download further malware for execution on the victim's machine.(Citation: Medium Eli Salem GuLoader April 2021)","relationship_id":"relationship--9bd2274b-95bc-4b7f-93f5-0b658d256217","references":[{"source_name":"Medium Eli Salem GuLoader April 2021","description":"Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.","url":"https://elis531989.medium.com/dancing-with-shellcodes-cracking-the-latest-version-of-guloader-75083fb15cb4"}]},{"id":"S0564","name":"BlackMould","url":"https://attack.mitre.org/software/S0564","kind":"malware","description":"[BlackMould](https://attack.mitre.org/software/S0564) has the ability to download files to the victim's machine.(Citation: Microsoft GALLIUM December 2019)","relationship_id":"relationship--ba8145fd-61d3-4729-a7c8-96216d2e6078","references":[{"source_name":"Microsoft GALLIUM December 2019","description":"MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.","url":"https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/"}]},{"id":"S0567","name":"Dtrack","url":"https://attack.mitre.org/software/S0567","kind":"malware","description":"[Dtrack](https://attack.mitre.org/software/S0567)’s can download and upload a file to the victim’s computer.(Citation: Securelist Dtrack)(Citation: CyberBit Dtrack)","relationship_id":"relationship--ef463100-ac00-44ab-805b-75e4c8886699","references":[{"source_name":"Securelist Dtrack","description":"Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021.","url":"https://securelist.com/my-name-is-dtrack/93338/"},{"source_name":"CyberBit Dtrack","description":"Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.","url":"https://www.cyberbit.com/blog/endpoint-security/dtrack-apt-malware-found-in-nuclear-power-plant/"}]},{"id":"S0568","name":"EVILNUM","url":"https://attack.mitre.org/software/S0568","kind":"malware","description":"[EVILNUM](https://attack.mitre.org/software/S0568) can download and upload files to the victim's computer.(Citation: ESET EvilNum July 2020)(Citation: Prevailion EvilNum May 2020)","relationship_id":"relationship--b3b6e98e-8d0f-4262-ae61-26c171bf20c6","references":[{"source_name":"Prevailion EvilNum May 2020","description":"Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20221209052853/https://www.prevailion.com/phantom-in-the-command-shell-2/"},{"source_name":"ESET EvilNum July 2020","description":"Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.","url":"https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/"}]},{"id":"S0569","name":"Explosive","url":"https://attack.mitre.org/software/S0569","kind":"malware","description":"[Explosive](https://attack.mitre.org/software/S0569) has a function to download a file to the infected system.(Citation: CheckPoint Volatile Cedar March 2015) ","relationship_id":"relationship--a4e88205-c591-4bad-9daa-0bf8f6049c57","references":[{"source_name":"CheckPoint Volatile Cedar March 2015","description":"Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021.","url":"https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2015/03/20082004/volatile-cedar-technical-report.pdf"}]},{"id":"S0572","name":"Caterpillar WebShell","url":"https://attack.mitre.org/software/S0572","kind":"malware","description":"[Caterpillar WebShell](https://attack.mitre.org/software/S0572) has a module to download and upload files to the system.(Citation: ClearSky Lebanese Cedar Jan 2021) ","relationship_id":"relationship--d4dc5fe6-fbfb-4718-8a7f-cd1eca70db61","references":[{"source_name":"ClearSky Lebanese Cedar Jan 2021","description":"ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.","url":"https://www.clearskysec.com/wp-content/uploads/2021/01/Lebanese-Cedar-APT.pdf"}]},{"id":"S0574","name":"BendyBear","url":"https://attack.mitre.org/software/S0574","kind":"malware","description":"[BendyBear](https://attack.mitre.org/software/S0574) is designed to download an implant from a C2 server.(Citation: Unit42 BendyBear Feb 2021)","relationship_id":"relationship--0f55c28a-835f-4a85-a733-8fac5b819dcf","references":[{"source_name":"Unit42 BendyBear Feb 2021","description":"Harbison, M. (2021, February 9). BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech. Retrieved February 16, 2021.","url":"https://unit42.paloaltonetworks.com/bendybear-shellcode-blacktech/"}]},{"id":"S0579","name":"Waterbear","url":"https://attack.mitre.org/software/S0579","kind":"malware","description":"[Waterbear](https://attack.mitre.org/software/S0579) can receive and load executables from remote C2 servers.(Citation: Trend Micro Waterbear December 2019)","relationship_id":"relationship--5c3a903f-5934-48ec-84da-e88e0d1b4e68","references":[{"source_name":"Trend Micro Waterbear December 2019","description":"Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.","url":"https://www.trendmicro.com/en_us/research/19/l/waterbear-is-back-uses-api-hooking-to-evade-security-product-detection.html"}]},{"id":"S0585","name":"Kerrdown","url":"https://attack.mitre.org/software/S0585","kind":"malware","description":"[Kerrdown](https://attack.mitre.org/software/S0585) can download specific payloads to a compromised host based on OS architecture.(Citation: Unit 42 KerrDown February 2019)","relationship_id":"relationship--9f57a541-c6d1-490f-bd15-1dee6280365b","references":[{"source_name":"Unit 42 KerrDown February 2019","description":"Ray, V. and Hayashi, K. (2019, February 1). Tracking OceanLotus’ new Downloader, KerrDown. Retrieved October 1, 2021.","url":"https://unit42.paloaltonetworks.com/tracking-oceanlotus-new-downloader-kerrdown/"}]},{"id":"S0586","name":"TAINTEDSCRIBE","url":"https://attack.mitre.org/software/S0586","kind":"malware","description":"[TAINTEDSCRIBE](https://attack.mitre.org/software/S0586) can download additional modules from its C2 server.(Citation: CISA MAR-10288834-2.v1  TAINTEDSCRIBE MAY 2020)","relationship_id":"relationship--98557068-7d60-40d4-8294-01469aadf6fe","references":[{"source_name":"CISA MAR-10288834-2.v1  TAINTEDSCRIBE MAY 2020","description":"USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar20-133b"}]},{"id":"S0587","name":"Penquin","url":"https://attack.mitre.org/software/S0587","kind":"malware","description":"[Penquin](https://attack.mitre.org/software/S0587) can execute the command code <code>do_download</code> to retrieve remote files from C2.(Citation: Leonardo Turla Penquin May 2020)","relationship_id":"relationship--729f4b9b-2d25-4e69-9a9b-adaa62c2ee31","references":[{"source_name":"Leonardo Turla Penquin May 2020","description":"Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021.","url":"https://www.leonardo.com/documents/20142/10868623/Malware+Technical+Insight+_Turla+%E2%80%9CPenquin_x64%E2%80%9D.pdf"}]},{"id":"S0588","name":"GoldMax","url":"https://attack.mitre.org/software/S0588","kind":"malware","description":"[GoldMax](https://attack.mitre.org/software/S0588) can download and execute additional files.(Citation: MSTIC NOBELIUM Mar 2021)(Citation: FireEye SUNSHUTTLE Mar 2021)","relationship_id":"relationship--bb1a7fc8-bec0-4655-bbfe-0c786e237452","references":[{"source_name":"MSTIC NOBELIUM Mar 2021","description":"Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.","url":"https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/"},{"source_name":"FireEye SUNSHUTTLE Mar 2021","description":"Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.","url":"https://www.fireeye.com/blog/threat-research/2021/03/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html"}]},{"id":"S0589","name":"Sibot","url":"https://attack.mitre.org/software/S0589","kind":"malware","description":"[Sibot](https://attack.mitre.org/software/S0589) can download and execute a payload onto a compromised system.(Citation: MSTIC NOBELIUM Mar 2021)","relationship_id":"relationship--8fe424be-6873-4b25-a87e-88b2de005d7f","references":[{"source_name":"MSTIC NOBELIUM Mar 2021","description":"Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.","url":"https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/"}]},{"id":"S0592","name":"RemoteUtilities","url":"https://attack.mitre.org/software/S0592","kind":"tool","description":"[RemoteUtilities](https://attack.mitre.org/software/S0592) can upload and download files to and from a target machine.(Citation: Trend Micro Muddy Water March 2021)","relationship_id":"relationship--e39a9d68-162f-45a3-b7c2-5914dd900b73","references":[{"source_name":"Trend Micro Muddy Water March 2021","description":"Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.","url":"https://www.trendmicro.com/en_us/research/21/c/earth-vetala---muddywater-continues-to-target-organizations-in-t.html"}]},{"id":"S0595","name":"ThiefQuest","url":"https://attack.mitre.org/software/S0595","kind":"malware","description":"[ThiefQuest](https://attack.mitre.org/software/S0595) can download and execute payloads in-memory or from disk.(Citation: wardle evilquest partii)","relationship_id":"relationship--ea4871e2-8754-4002-9e76-a2c1c0ed7e2f","references":[{"source_name":"wardle evilquest partii","description":"Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.","url":"https://objective-see.com/blog/blog_0x60.html"}]},{"id":"S0596","name":"ShadowPad","url":"https://attack.mitre.org/software/S0596","kind":"malware","description":"[ShadowPad](https://attack.mitre.org/software/S0596) has downloaded code from a C2 server.(Citation: Securelist ShadowPad Aug 2017)","relationship_id":"relationship--f72ffc5a-c872-4b28-b40e-2a3ec85bddcc","references":[{"source_name":"Securelist ShadowPad Aug 2017","description":"GReAT. (2017, August 15). ShadowPad in corporate networks. Retrieved March 22, 2021.","url":"https://securelist.com/shadowpad-in-corporate-networks/81432/"}]},{"id":"S0598","name":"P.A.S. Webshell","url":"https://attack.mitre.org/software/S0598","kind":"malware","description":"[P.A.S. Webshell](https://attack.mitre.org/software/S0598) can upload and download files to and from compromised hosts.(Citation: ANSSI Sandworm January 2021)","relationship_id":"relationship--f77760d0-35c1-4e91-98b9-2ac57ba183d5","references":[{"source_name":"ANSSI Sandworm January 2021","description":"ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.","url":"https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf"}]},{"id":"S0599","name":"Kinsing","url":"https://attack.mitre.org/software/S0599","kind":"malware","description":"[Kinsing](https://attack.mitre.org/software/S0599) has downloaded additional lateral movement scripts from C2.(Citation: Aqua Kinsing April 2020)","relationship_id":"relationship--dd39f1a9-8eb4-4818-8597-ed228d7dba83","references":[{"source_name":"Aqua Kinsing April 2020","description":"Singer, G. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved April 1, 2021.","url":"https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability"}]},{"id":"S0600","name":"Doki","url":"https://attack.mitre.org/software/S0600","kind":"malware","description":"[Doki](https://attack.mitre.org/software/S0600) has downloaded scripts from C2.(Citation: Intezer Doki July 20)","relationship_id":"relationship--6a556d19-33f1-4b6e-bec3-00ca32dd5df7","references":[{"source_name":"Intezer Doki July 20","description":"Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.","url":"https://www.intezer.com/blog/cloud-security/watch-your-containers-doki-infecting-docker-servers-in-the-cloud/"}]},{"id":"S0601","name":"Hildegard","url":"https://attack.mitre.org/software/S0601","kind":"malware","description":"[Hildegard](https://attack.mitre.org/software/S0601) has downloaded additional scripts that build and run Monero cryptocurrency miners.(Citation: Unit 42 Hildegard Malware)","relationship_id":"relationship--cdd9ae58-bed9-4cce-ad46-d4e96a789ded","references":[{"source_name":"Unit 42 Hildegard Malware","description":"Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.","url":"https://unit42.paloaltonetworks.com/hildegard-malware-teamtnt/"}]},{"id":"S0604","name":"Industroyer","url":"https://attack.mitre.org/software/S0604","kind":"malware","description":"[Industroyer](https://attack.mitre.org/software/S0604) downloads a shellcode payload from a remote C2 server and loads it into memory.(Citation: ESET Industroyer)","relationship_id":"relationship--4f90d1a5-4903-46d9-95b2-73bb118f8cb9","references":[{"source_name":"ESET Industroyer","description":"Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.","url":"https://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf"}]},{"id":"S0608","name":"Conficker","url":"https://attack.mitre.org/software/S0608","kind":"malware","description":"[Conficker](https://attack.mitre.org/software/S0608) downloads an HTTP server to the infected machine.(Citation: SANS Conficker)","relationship_id":"relationship--fa443fec-23f0-40dd-8a94-06cd19f4eb86","references":[{"source_name":"SANS Conficker","description":"Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.","url":"https://web.archive.org/web/20200125132645/https://www.sans.org/security-resources/malwarefaq/conficker-worm"}]},{"id":"S0610","name":"SideTwist","url":"https://attack.mitre.org/software/S0610","kind":"malware","description":"[SideTwist](https://attack.mitre.org/software/S0610) has the ability to download additional files.(Citation: Check Point APT34 April 2021)","relationship_id":"relationship--6b47884a-47ac-4f0a-9d5b-3c6eb0efd761","references":[{"source_name":"Check Point APT34 April 2021","description":"Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.","url":"https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/"}]},{"id":"S0613","name":"PS1","url":"https://attack.mitre.org/software/S0613","kind":"malware","description":"[CostaBricks](https://attack.mitre.org/software/S0614) can download additional payloads onto a compromised host.(Citation: BlackBerry CostaRicto November 2020)","relationship_id":"relationship--107f8870-4adf-4f63-acf2-d28677905235","references":[{"source_name":"BlackBerry CostaRicto November 2020","description":"The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.","url":"https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced"}]},{"id":"S0614","name":"CostaBricks","url":"https://attack.mitre.org/software/S0614","kind":"malware","description":"[CostaBricks](https://attack.mitre.org/software/S0614) has been used to load [SombRAT](https://attack.mitre.org/software/S0615) onto a compromised host.(Citation: BlackBerry CostaRicto November 2020)","relationship_id":"relationship--48652244-02b0-4a80-82a9-b99fca669d85","references":[{"source_name":"BlackBerry CostaRicto November 2020","description":"The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.","url":"https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced"}]},{"id":"S0615","name":"SombRAT","url":"https://attack.mitre.org/software/S0615","kind":"malware","description":"[SombRAT](https://attack.mitre.org/software/S0615) has the ability to download and execute additional payloads.(Citation: BlackBerry CostaRicto November 2020)(Citation: FireEye FiveHands April 2021)(Citation: CISA AR21-126A FIVEHANDS May 2021)","relationship_id":"relationship--5e6f5555-f7dd-462d-b110-afc28f021be5","references":[{"source_name":"BlackBerry CostaRicto November 2020","description":"The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.","url":"https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced"},{"source_name":"FireEye FiveHands April 2021","description":"McLellan, T.  and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.","url":"https://www.fireeye.com/blog/threat-research/2021/04/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html"},{"source_name":"CISA AR21-126A FIVEHANDS May 2021","description":"CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.","url":"https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a"}]},{"id":"S0616","name":"DEATHRANSOM","url":"https://attack.mitre.org/software/S0616","kind":"malware","description":"[DEATHRANSOM](https://attack.mitre.org/software/S0616) can download files to a compromised host.(Citation: FireEye FiveHands April 2021)","relationship_id":"relationship--7bf6a452-db06-4b7a-b177-678fdf841fbf","references":[{"source_name":"FireEye FiveHands April 2021","description":"McLellan, T.  and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.","url":"https://www.fireeye.com/blog/threat-research/2021/04/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html"}]},{"id":"S0624","name":"Ecipekac","url":"https://attack.mitre.org/software/S0624","kind":"malware","description":"[Ecipekac](https://attack.mitre.org/software/S0624) can download additional payloads to a compromised host.(Citation: Securelist APT10 March 2021)","relationship_id":"relationship--eda15dd3-2e7d-470c-8b1d-227c7d877e67","references":[{"source_name":"Securelist APT10 March 2021","description":"GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.","url":"https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/"}]},{"id":"S0625","name":"Cuba","url":"https://attack.mitre.org/software/S0625","kind":"malware","description":"[Cuba](https://attack.mitre.org/software/S0625) can download files from its C2 server.(Citation: McAfee Cuba April 2021)","relationship_id":"relationship--633959b9-383c-486d-9e36-520e5afc502d","references":[{"source_name":"McAfee Cuba April 2021","description":"Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021.","url":"https://www.mcafee.com/enterprise/en-us/assets/reports/rp-cuba-ransomware.pdf"}]},{"id":"S0626","name":"P8RAT","url":"https://attack.mitre.org/software/S0626","kind":"malware","description":"[P8RAT](https://attack.mitre.org/software/S0626) can download additional payloads to a target system.(Citation: Securelist APT10 March 2021)","relationship_id":"relationship--96b018b8-701c-4658-b58b-716ba632fd72","references":[{"source_name":"Securelist APT10 March 2021","description":"GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.","url":"https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/"}]},{"id":"S0627","name":"SodaMaster","url":"https://attack.mitre.org/software/S0627","kind":"malware","description":"[SodaMaster](https://attack.mitre.org/software/S0627) has the ability to download additional payloads from C2 to the targeted system.(Citation: Securelist APT10 March 2021)","relationship_id":"relationship--035dca04-cf9e-45ac-a037-f171b06078e6","references":[{"source_name":"Securelist APT10 March 2021","description":"GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.","url":"https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/"}]},{"id":"S0628","name":"FYAnti","url":"https://attack.mitre.org/software/S0628","kind":"malware","description":"[FYAnti](https://attack.mitre.org/software/S0628) can download additional payloads to a compromised host.(Citation: Securelist APT10 March 2021)\t ","relationship_id":"relationship--3b4dc8f1-51c3-41bb-82a7-a877e5618ab7","references":[{"source_name":"Securelist APT10 March 2021","description":"GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.","url":"https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/"}]},{"id":"S0629","name":"RainyDay","url":"https://attack.mitre.org/software/S0629","kind":"malware","description":"[RainyDay](https://attack.mitre.org/software/S0629) can download files to a compromised host.(Citation: Bitdefender Naikon April 2021)","relationship_id":"relationship--2d3a8912-53fd-416b-bef8-f6ad980ae7c0","references":[{"source_name":"Bitdefender Naikon April 2021","description":"Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/396/Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN.pdf"}]},{"id":"S0630","name":"Nebulae","url":"https://attack.mitre.org/software/S0630","kind":"malware","description":"[Nebulae](https://attack.mitre.org/software/S0630) can download files from C2.(Citation: Bitdefender Naikon April 2021)","relationship_id":"relationship--156d46b3-538e-4481-ad53-b85de891f6d5","references":[{"source_name":"Bitdefender Naikon April 2021","description":"Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/396/Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN.pdf"}]},{"id":"S0631","name":"Chaes","url":"https://attack.mitre.org/software/S0631","kind":"malware","description":"[Chaes](https://attack.mitre.org/software/S0631) can download additional files onto an infected machine.(Citation: Cybereason Chaes Nov 2020)","relationship_id":"relationship--e3a516b0-fa02-43dc-8247-0545a53693b1","references":[{"source_name":"Cybereason Chaes Nov 2020","description":"Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.","url":"https://www.cybereason.com/hubfs/dam/collateral/reports/11-2020-Chaes-e-commerce-malware-research.pdf"}]},{"id":"S0632","name":"GrimAgent","url":"https://attack.mitre.org/software/S0632","kind":"malware","description":"[GrimAgent](https://attack.mitre.org/software/S0632) has the ability to download and execute additional payloads.(Citation: Group IB GrimAgent July 2021)","relationship_id":"relationship--494255a0-7672-4302-9e1b-bf3767cb8384","references":[{"source_name":"Group IB GrimAgent July 2021","description":"Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.","url":"https://www.group-ib.com/blog/grimagent/"}]},{"id":"S0633","name":"Sliver","url":"https://attack.mitre.org/software/S0633","kind":"tool","description":"[Sliver](https://attack.mitre.org/software/S0633) can download additional content and files from the [Sliver](https://attack.mitre.org/software/S0633) server to the client residing on the victim machine using the <code>upload</code> command.(Citation: GitHub Sliver Upload)(Citation: Cybereason Sliver Undated)","relationship_id":"relationship--94ea901d-3904-4d84-9b0f-7df943683cd7","references":[{"source_name":"GitHub Sliver Upload","description":"BishopFox. (n.d.). Sliver Upload. Retrieved September 16, 2021.","url":"https://github.com/BishopFox/sliver/blob/ea329226636ab8e470086a17f13aa8d330baad22/client/command/filesystem/upload.go"},{"source_name":"Cybereason Sliver Undated","description":"Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025.","url":"https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors"}]},{"id":"S0635","name":"BoomBox","url":"https://attack.mitre.org/software/S0635","kind":"malware","description":"[BoomBox](https://attack.mitre.org/software/S0635) has the ability to download next stage malware components to a compromised system.(Citation: MSTIC Nobelium Toolset May 2021)","relationship_id":"relationship--33eb06fa-5983-47d8-9f7f-d594f311a008","references":[{"source_name":"MSTIC Nobelium Toolset May 2021","description":"MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.","url":"https://www.microsoft.com/security/blog/2021/05/28/breaking-down-nobeliums-latest-early-stage-toolset/"}]},{"id":"S0636","name":"VaporRage","url":"https://attack.mitre.org/software/S0636","kind":"malware","description":"[VaporRage](https://attack.mitre.org/software/S0636) has the ability to download malicious shellcode to compromised systems.(Citation: MSTIC Nobelium Toolset May 2021)","relationship_id":"relationship--8972de3e-d073-47ec-9665-a10896601e12","references":[{"source_name":"MSTIC Nobelium Toolset May 2021","description":"MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.","url":"https://www.microsoft.com/security/blog/2021/05/28/breaking-down-nobeliums-latest-early-stage-toolset/"}]},{"id":"S0639","name":"Seth-Locker","url":"https://attack.mitre.org/software/S0639","kind":"malware","description":"[Seth-Locker](https://attack.mitre.org/software/S0639) has the ability to download and execute files on a compromised host.(Citation: Trend Micro Ransomware February 2021)","relationship_id":"relationship--1715a3b2-1c13-403e-8add-e8709fc7f92c","references":[{"source_name":"Trend Micro Ransomware February 2021","description":"Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.","url":"https://www.trendmicro.com/en_us/research/21/b/new-in-ransomware.html"}]},{"id":"S0642","name":"BADFLICK","url":"https://attack.mitre.org/software/S0642","kind":"malware","description":"[BADFLICK](https://attack.mitre.org/software/S0642) has download files from its C2 server.(Citation: Accenture MUDCARP March 2019)","relationship_id":"relationship--c07e24ea-bf70-4f9c-a45e-73dfc0ede007","references":[{"source_name":"Accenture MUDCARP March 2019","description":"Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.","url":"https://www.accenture.com/us-en/blogs/cyber-defense/mudcarps-focus-on-submarine-technologies"}]},{"id":"S0643","name":"Peppy","url":"https://attack.mitre.org/software/S0643","kind":"malware","description":"[Peppy](https://attack.mitre.org/software/S0643) can download and execute remote files.(Citation: Proofpoint Operation Transparent Tribe March 2016)","relationship_id":"relationship--2bfc128f-2bc9-436b-abe0-4206b9e35727","references":[{"source_name":"Proofpoint Operation Transparent Tribe March 2016","description":"Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.","url":"https://www.proofpoint.com/sites/default/files/proofpoint-operation-transparent-tribe-threat-insight-en.pdf"}]},{"id":"S0646","name":"SpicyOmelette","url":"https://attack.mitre.org/software/S0646","kind":"malware","description":"[SpicyOmelette](https://attack.mitre.org/software/S0646) can download malicious files from threat actor controlled AWS URL's.(Citation: Secureworks GOLD KINGSWOOD September 2018)","relationship_id":"relationship--7f7f05aa-a246-48ce-89d2-48035cac5ffa","references":[{"source_name":"Secureworks GOLD KINGSWOOD September 2018","description":"CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.","url":"https://www.secureworks.com/blog/cybercriminals-increasingly-trying-to-ensnare-the-big-financial-fish"}]},{"id":"S0647","name":"Turian","url":"https://attack.mitre.org/software/S0647","kind":"malware","description":"[Turian](https://attack.mitre.org/software/S0647) can download additional files and tools from its C2.(Citation: ESET BackdoorDiplomacy Jun 2021)","relationship_id":"relationship--bfab83a2-934e-4e3c-b2c9-626d88231497","references":[{"source_name":"ESET BackdoorDiplomacy Jun 2021","description":"Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021","url":"https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/"}]},{"id":"S0648","name":"JSS Loader","url":"https://attack.mitre.org/software/S0648","kind":"malware","description":"[JSS Loader](https://attack.mitre.org/software/S0648) has the ability to download malicious executables to a compromised host.(Citation: CrowdStrike Carbon Spider August 2021)","relationship_id":"relationship--f4e1e921-1436-4fdc-88bc-f3321383e96a","references":[{"source_name":"CrowdStrike Carbon Spider August 2021","description":"Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.","url":"https://www.crowdstrike.com/blog/carbon-spider-embraces-big-game-hunting-part-1/"}]},{"id":"S0649","name":"SMOKEDHAM","url":"https://attack.mitre.org/software/S0649","kind":"malware","description":"[SMOKEDHAM](https://attack.mitre.org/software/S0649) has used Powershell to download UltraVNC and [ngrok](https://attack.mitre.org/software/S0508) from third-party file sharing sites.(Citation: FireEye SMOKEDHAM June 2021)","relationship_id":"relationship--452e340a-df31-4ae9-a801-d26c57d491ea","references":[{"source_name":"FireEye SMOKEDHAM June 2021","description":"FireEye. (2021, June 16). Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise. Retrieved September 22, 2021.","url":"https://www.fireeye.com/blog/threat-research/2021/06/darkside-affiliate-supply-chain-software-compromise.html"}]},{"id":"S0650","name":"QakBot","url":"https://attack.mitre.org/software/S0650","kind":"malware","description":"[QakBot](https://attack.mitre.org/software/S0650) has the ability to download additional components and malware.(Citation: Trend Micro Qakbot May 2020)(Citation: Crowdstrike Qakbot October 2020)(Citation: Trend Micro Qakbot December 2020)(Citation: Cyberint Qakbot May 2021)(Citation: Kaspersky QakBot September 2021)(Citation: Group IB Ransomware September 2020)","relationship_id":"relationship--aa444f15-777c-4bf6-819b-f03476d59401","references":[{"source_name":"Crowdstrike Qakbot October 2020","description":"CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.","url":"https://www.crowdstrike.com/blog/duck-hunting-with-falcon-complete-qakbot-zip-based-campaign/"},{"source_name":"Cyberint Qakbot May 2021","description":"Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.","url":"https://blog.cyberint.com/qakbot-banking-trojan"},{"source_name":"Group IB Ransomware September 2020","description":"Group IB. (2020, September). LOCK LIKE  A PRO. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20220119114433/https://groupib.pathfactory.com/ransomware-reports/prolock_wp"},{"source_name":"Kaspersky QakBot September 2021","description":"Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.","url":"https://securelist.com/qakbot-technical-analysis/103931/"},{"source_name":"Trend Micro Qakbot May 2020","description":"Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.","url":"https://www.trendmicro.com/vinfo/ph/security/news/cybercrime-and-digital-threats/qakbot-resurges-spreads-through-vbs-files"},{"source_name":"Trend Micro Qakbot December 2020","description":"Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.","url":"https://success.trendmicro.com/en-US/solution/KA-0011282"}]},{"id":"S0651","name":"BoxCaon","url":"https://attack.mitre.org/software/S0651","kind":"malware","description":"[BoxCaon](https://attack.mitre.org/software/S0651) can download files.(Citation: Checkpoint IndigoZebra July 2021)","relationship_id":"relationship--237429d4-808b-478f-ab0f-a01bff89834e","references":[{"source_name":"Checkpoint IndigoZebra July 2021","description":"CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.","url":"https://research.checkpoint.com/2021/indigozebra-apt-continues-to-attack-central-asia-with-evolving-tools/"}]},{"id":"S0652","name":"MarkiRAT","url":"https://attack.mitre.org/software/S0652","kind":"malware","description":"[MarkiRAT](https://attack.mitre.org/software/S0652) can download additional files and tools from its C2 server, including through the use of [BITSAdmin](https://attack.mitre.org/software/S0190).(Citation: Kaspersky Ferocious Kitten Jun 2021)","relationship_id":"relationship--2f4684b2-728f-46c5-9c91-98731c935b28","references":[{"source_name":"Kaspersky Ferocious Kitten Jun 2021","description":"GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.","url":"https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/"}]},{"id":"S0653","name":"xCaon","url":"https://attack.mitre.org/software/S0653","kind":"malware","description":"[xCaon](https://attack.mitre.org/software/S0653) has a command to download files to the victim's machine.(Citation: Checkpoint IndigoZebra July 2021)","relationship_id":"relationship--ae7cd450-60bc-426b-92df-14d9d1be279b","references":[{"source_name":"Checkpoint IndigoZebra July 2021","description":"CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.","url":"https://research.checkpoint.com/2021/indigozebra-apt-continues-to-attack-central-asia-with-evolving-tools/"}]},{"id":"S0657","name":"BLUELIGHT","url":"https://attack.mitre.org/software/S0657","kind":"malware","description":"[BLUELIGHT](https://attack.mitre.org/software/S0657) can download additional files onto the host.(Citation: Volexity InkySquid BLUELIGHT August 2021) ","relationship_id":"relationship--2161578b-44ef-4c44-90ad-2ee8920a3db8","references":[{"source_name":"Volexity InkySquid BLUELIGHT August 2021","description":"Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.","url":"https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/"}]},{"id":"S0658","name":"XCSSET","url":"https://attack.mitre.org/software/S0658","kind":"malware","description":"[XCSSET](https://attack.mitre.org/software/S0658) downloads browser specific AppleScript modules using a constructed URL with the <code>curl</code> command, <code>https://\" & domain & \"/agent/scripts/\" & moduleName & \".applescript</code>.(Citation: trendmicro xcsset xcode project 2020)","relationship_id":"relationship--30e190f8-2f7d-4795-9bed-90576fafdd0b","references":[{"source_name":"trendmicro xcsset xcode project 2020","description":"Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.","url":"https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"}]},{"id":"S0659","name":"Diavol","url":"https://attack.mitre.org/software/S0659","kind":"malware","description":"[Diavol](https://attack.mitre.org/software/S0659) can receive configuration updates and additional payloads including wscpy.exe from C2.(Citation: Fortinet Diavol July 2021)","relationship_id":"relationship--d55ab651-738b-4bbc-9438-57fc76be8f52","references":[{"source_name":"Fortinet Diavol July 2021","description":"Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.","url":"https://www.fortinet.com/blog/threat-research/diavol-new-ransomware-used-by-wizard-spider"}]},{"id":"S0661","name":"FoggyWeb","url":"https://attack.mitre.org/software/S0661","kind":"malware","description":"[FoggyWeb](https://attack.mitre.org/software/S0661) can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.(Citation: MSTIC FoggyWeb September 2021)","relationship_id":"relationship--998c449f-ef46-4f42-a6a4-bd025338584e","references":[{"source_name":"MSTIC FoggyWeb September 2021","description":"Ramin Nafisi. (2021, September 27). FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor. Retrieved October 4, 2021.","url":"https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/"}]},{"id":"S0662","name":"RCSession","url":"https://attack.mitre.org/software/S0662","kind":"malware","description":"[RCSession](https://attack.mitre.org/software/S0662) has the ability to drop additional files to an infected machine.(Citation: Profero APT27 December 2020)","relationship_id":"relationship--6758c87e-d187-46df-b02a-1e093b3054cc","references":[{"source_name":"Profero APT27 December 2020","description":"Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.","url":"https://web.archive.org/web/20210104144857/https://shared-public-reports.s3-eu-west-1.amazonaws.com/APT27+turns+to+ransomware.pdf"}]},{"id":"S0663","name":"SysUpdate","url":"https://attack.mitre.org/software/S0663","kind":"malware","description":"[SysUpdate](https://attack.mitre.org/software/S0663) has the ability to download files to a compromised host.(Citation: Trend Micro Iron Tiger April 2021)(Citation: Lunghi Iron Tiger Linux)","relationship_id":"relationship--759ce6e8-da01-4cd6-9d03-9b0a1edde9be","references":[{"source_name":"Lunghi Iron Tiger Linux","description":"Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.","url":"https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html"},{"source_name":"Trend Micro Iron Tiger April 2021","description":"Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.","url":"https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html"}]},{"id":"S0664","name":"Pandora","url":"https://attack.mitre.org/software/S0664","kind":"malware","description":"[Pandora](https://attack.mitre.org/software/S0664) can load additional drivers and files onto a victim machine.(Citation: Trend Micro Iron Tiger April 2021)","relationship_id":"relationship--0110e04e-5812-4b69-9700-037b52d3ebb4","references":[{"source_name":"Trend Micro Iron Tiger April 2021","description":"Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.","url":"https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html"}]},{"id":"S0665","name":"ThreatNeedle","url":"https://attack.mitre.org/software/S0665","kind":"malware","description":"[ThreatNeedle](https://attack.mitre.org/software/S0665) can download additional tools to enable lateral movement.(Citation: Kaspersky ThreatNeedle Feb 2021)","relationship_id":"relationship--4e49358b-43d4-4fc6-8ad0-72882de328b4","references":[{"source_name":"Kaspersky ThreatNeedle Feb 2021","description":"Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.","url":"https://securelist.com/lazarus-threatneedle/100803/"}]},{"id":"S0666","name":"Gelsemium","url":"https://attack.mitre.org/software/S0666","kind":"malware","description":"[Gelsemium](https://attack.mitre.org/software/S0666) can download additional plug-ins to a compromised host.(Citation: ESET Gelsemium June 2021)","relationship_id":"relationship--9548ed41-931a-4d95-8256-b3fcad5914ad","references":[{"source_name":"ESET Gelsemium June 2021","description":"Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.","url":"https://www.welivesecurity.com/wp-content/uploads/2021/06/eset_gelsemium.pdf"}]},{"id":"S0667","name":"Chrommme","url":"https://attack.mitre.org/software/S0667","kind":"malware","description":"[Chrommme](https://attack.mitre.org/software/S0667) can download its code from C2.(Citation: ESET Gelsemium June 2021)","relationship_id":"relationship--4253a9ab-fddb-4c2f-b4c7-c4bc8182d9a4","references":[{"source_name":"ESET Gelsemium June 2021","description":"Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.","url":"https://www.welivesecurity.com/wp-content/uploads/2021/06/eset_gelsemium.pdf"}]},{"id":"S0668","name":"TinyTurla","url":"https://attack.mitre.org/software/S0668","kind":"malware","description":"[TinyTurla](https://attack.mitre.org/software/S0668) has the ability to act as a second-stage dropper used to infect the system with additional malware.(Citation: Talos TinyTurla September 2021)","relationship_id":"relationship--72ec975a-43b4-4766-a2f4-385b6112858d","references":[{"source_name":"Talos TinyTurla September 2021","description":"Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.","url":"https://blog.talosintelligence.com/2021/09/tinyturla.html"}]},{"id":"S0669","name":"KOCTOPUS","url":"https://attack.mitre.org/software/S0669","kind":"malware","description":"[KOCTOPUS](https://attack.mitre.org/software/S0669) has executed a PowerShell command to download a file to the system.(Citation: MalwareBytes LazyScripter Feb 2021)","relationship_id":"relationship--63eceedb-657b-47a0-a437-983aad5d82e0","references":[{"source_name":"MalwareBytes LazyScripter Feb 2021","description":"Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20211003035156/https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf"}]},{"id":"S0670","name":"WarzoneRAT","url":"https://attack.mitre.org/software/S0670","kind":"malware","description":"[WarzoneRAT](https://attack.mitre.org/software/S0670) can download and execute additional files.(Citation: Check Point Warzone Feb 2020)","relationship_id":"relationship--2f081501-0c5c-4662-b7b4-3dc5a8a3b1af","references":[{"source_name":"Check Point Warzone Feb 2020","description":"Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.","url":"https://research.checkpoint.com/2020/warzone-behind-the-enemy-lines/"}]},{"id":"S0671","name":"Tomiris","url":"https://attack.mitre.org/software/S0671","kind":"malware","description":"[Tomiris](https://attack.mitre.org/software/S0671) can download files and execute them on a victim's system.(Citation: Kaspersky Tomiris Sep 2021)","relationship_id":"relationship--9e0bef30-edc0-4a18-9033-a1f487e35b76","references":[{"source_name":"Kaspersky Tomiris Sep 2021","description":"Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.","url":"https://securelist.com/darkhalo-after-solarwinds-the-tomiris-connection/104311/"}]},{"id":"S0672","name":"Zox","url":"https://attack.mitre.org/software/S0672","kind":"malware","description":"[Zox](https://attack.mitre.org/software/S0672) can download files to a compromised machine.(Citation: Novetta-Axiom)","relationship_id":"relationship--55d5ccb4-b794-467b-b734-fa3763bbdf99","references":[{"source_name":"Novetta-Axiom","description":"Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.","url":"https://web.archive.org/web/20230115144216/http://www.novetta.com/wp-content/uploads/2014/11/Executive_Summary-Final_1.pdf"}]},{"id":"S0674","name":"CharmPower","url":"https://attack.mitre.org/software/S0674","kind":"malware","description":"[CharmPower](https://attack.mitre.org/software/S0674) has the ability to download additional modules to a compromised host.(Citation: Check Point APT35 CharmPower January 2022)","relationship_id":"relationship--e0a7e8ca-a199-4909-a4da-302bcc6216e6","references":[{"source_name":"Check Point APT35 CharmPower January 2022","description":"Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.","url":"https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit/"}]},{"id":"S0680","name":"LitePower","url":"https://attack.mitre.org/software/S0680","kind":"malware","description":"[LitePower](https://attack.mitre.org/software/S0680) has the ability to download payloads containing system commands to a compromised host.(Citation: Kaspersky WIRTE November 2021)","relationship_id":"relationship--3593e540-dfc0-4995-8640-db52961b3666","references":[{"source_name":"Kaspersky WIRTE November 2021","description":"Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.","url":"https://securelist.com/wirtes-campaign-in-the-middle-east-living-off-the-land-since-at-least-2019/105044"}]},{"id":"S0681","name":"Lizar","url":"https://attack.mitre.org/software/S0681","kind":"malware","description":"[Lizar](https://attack.mitre.org/software/S0681) can download additional plugins, files, and tools.(Citation: BiZone Lizar May 2021)(Citation: SekoiaBourhis_DiceLoader_Feb2024)(Citation: Cocomazzi FIN7 Reboot)","relationship_id":"relationship--a19231c9-e6b4-4d3f-9c9d-f4e85cba5e3a","references":[{"source_name":"BiZone Lizar May 2021","description":"BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.","url":"https://bi-zone.medium.com/from-pentest-to-apt-attack-cybercriminal-group-fin7-disguises-its-malware-as-an-ethical-hackers-c23c9a75e319"},{"source_name":"SekoiaBourhis_DiceLoader_Feb2024","description":"Bourhis, P., Sekoia TDR. (2024, February 1). Unveiling the intricacies of DiceLoader. Retrieved May 14, 2025.","url":"https://blog.sekoia.io/unveiling-the-intricacies-of-diceloader/"},{"source_name":"Cocomazzi FIN7 Reboot","description":"Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.","url":"https://www.sentinelone.com/labs/fin7-reboot-cybercrime-gang-enhances-ops-with-new-edr-bypasses-and-automated-attacks/"}]},{"id":"S0685","name":"PowerPunch","url":"https://attack.mitre.org/software/S0685","kind":"malware","description":"[PowerPunch](https://attack.mitre.org/software/S0685) can download payloads from adversary infrastructure.(Citation: Microsoft Actinium February 2022)","relationship_id":"relationship--87b69ac6-d50d-4bbf-ac8b-7ad81b4e9ee8","references":[{"source_name":"Microsoft Actinium February 2022","description":"Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.","url":"https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/"}]},{"id":"S0686","name":"QuietSieve","url":"https://attack.mitre.org/software/S0686","kind":"malware","description":"[QuietSieve](https://attack.mitre.org/software/S0686) can download and execute payloads on a target host.(Citation: Microsoft Actinium February 2022)","relationship_id":"relationship--16446d10-cf55-4e1e-bbf8-7ce6b8a2fb2b","references":[{"source_name":"Microsoft Actinium February 2022","description":"Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.","url":"https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/"}]},{"id":"S0687","name":"Cyclops Blink","url":"https://attack.mitre.org/software/S0687","kind":"malware","description":"[Cyclops Blink](https://attack.mitre.org/software/S0687) has the ability to download files to target systems.(Citation: NCSC Cyclops Blink February 2022)(Citation: Trend Micro Cyclops Blink March 2022)","relationship_id":"relationship--ca7d9090-d5ff-4a10-b403-015daa559e84","references":[{"source_name":"Trend Micro Cyclops Blink March 2022","description":"Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.","url":"https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html"},{"source_name":"NCSC Cyclops Blink February 2022","description":"NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.","url":"https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf"}]},{"id":"S0688","name":"Meteor","url":"https://attack.mitre.org/software/S0688","kind":"malware","description":"[Meteor](https://attack.mitre.org/software/S0688) has the ability to download additional files for execution on the victim's machine.(Citation: Check Point Meteor Aug 2021)","relationship_id":"relationship--201f9d85-be41-4aeb-984f-6ece40d4177d","references":[{"source_name":"Check Point Meteor Aug 2021","description":"Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.","url":"https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/"}]},{"id":"S0689","name":"WhisperGate","url":"https://attack.mitre.org/software/S0689","kind":"malware","description":"[WhisperGate](https://attack.mitre.org/software/S0689) can download additional stages of malware from a Discord CDN channel.(Citation: Microsoft WhisperGate January 2022)(Citation: Unit 42 WhisperGate January 2022)(Citation: Cisco Ukraine Wipers January 2022)(Citation: Medium S2W WhisperGate January 2022)","relationship_id":"relationship--f099adef-7e4e-4b52-b4fa-27f7db8389f3","references":[{"source_name":"Cisco Ukraine Wipers January 2022","description":"Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.","url":"https://blog.talosintelligence.com/2022/01/ukraine-campaign-delivers-defacement.html"},{"source_name":"Unit 42 WhisperGate January 2022","description":"Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.","url":"https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/#whispergate-malware-family"},{"source_name":"Microsoft WhisperGate January 2022","description":"MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.","url":"https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/"},{"source_name":"Medium S2W WhisperGate January 2022","description":"S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.","url":"https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3"}]},{"id":"S0691","name":"Neoichor","url":"https://attack.mitre.org/software/S0691","kind":"malware","description":"[Neoichor](https://attack.mitre.org/software/S0691) can download additional files onto a compromised host.(Citation: Microsoft NICKEL December 2021)","relationship_id":"relationship--22a59466-1502-431a-a2c7-a8cb09928a74","references":[{"source_name":"Microsoft NICKEL December 2021","description":"MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.","url":"https://www.microsoft.com/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe"}]},{"id":"S0692","name":"SILENTTRINITY","url":"https://attack.mitre.org/software/S0692","kind":"tool","description":"[SILENTTRINITY](https://attack.mitre.org/software/S0692) can load additional files and tools, including [Mimikatz](https://attack.mitre.org/software/S0002).(Citation: GitHub SILENTTRINITY Modules July 2019)","relationship_id":"relationship--1b16de68-c627-4f38-a85f-bbba2fef7e20","references":[{"source_name":"GitHub SILENTTRINITY Modules July 2019","description":"Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.","url":"https://github.com/byt3bl33d3r/SILENTTRINITY/tree/master/silenttrinity/core/teamserver/modules/boo"}]},{"id":"S0694","name":"DRATzarus","url":"https://attack.mitre.org/software/S0694","kind":"malware","description":"[DRATzarus](https://attack.mitre.org/software/S0694) can deploy additional tools onto an infected machine.(Citation: ClearSky Lazarus Aug 2020)","relationship_id":"relationship--6684ebb4-cab6-4443-a539-f71bdddbf15c","references":[{"source_name":"ClearSky Lazarus Aug 2020","description":"ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.","url":"https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf"}]},{"id":"S0695","name":"Donut","url":"https://attack.mitre.org/software/S0695","kind":"tool","description":"[Donut](https://attack.mitre.org/software/S0695) can download and execute previously staged shellcode payloads.(Citation: Donut Github)","relationship_id":"relationship--c720f9ab-106c-47ce-b327-83727be6d35a","references":[{"source_name":"Donut Github","description":"TheWover. (2019, May 9). donut. Retrieved March 25, 2022.","url":"https://github.com/TheWover/donut"}]},{"id":"S0696","name":"Flagpro","url":"https://attack.mitre.org/software/S0696","kind":"malware","description":"[Flagpro](https://attack.mitre.org/software/S0696) can download additional malware from the C2 server.(Citation: NTT Security Flagpro new December 2021)","relationship_id":"relationship--82ce210f-a994-4541-b62f-40ead02ad202","references":[{"source_name":"NTT Security Flagpro new December 2021","description":"Hada, H. (2021, December 28).  Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.","url":"https://insight-jp.nttsecurity.com/post/102hf3q/flagpro-the-new-malware-used-by-blacktech"}]},{"id":"S1012","name":"PowerLess","url":"https://attack.mitre.org/software/S1012","kind":"malware","description":"[PowerLess](https://attack.mitre.org/software/S1012) can download additional payloads to a compromised host.(Citation: Cybereason PowerLess February 2022)","relationship_id":"relationship--4bd59ceb-eb44-45c0-b775-3eaea3307455","references":[{"source_name":"Cybereason PowerLess February 2022","description":"Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.","url":"https://www.cybereason.com/blog/research/powerless-trojan-iranian-apt-phosphorus-adds-new-powershell-backdoor-for-espionage"}]},{"id":"S1013","name":"ZxxZ","url":"https://attack.mitre.org/software/S1013","kind":"malware","description":"[ZxxZ](https://attack.mitre.org/software/S1013) can download and execute additional files.(Citation: Cisco Talos Bitter Bangladesh May 2022)","relationship_id":"relationship--0bde7434-49de-40c4-906c-fc5f3bfc6d16","references":[{"source_name":"Cisco Talos Bitter Bangladesh May 2022","description":"Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.","url":"https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html"}]},{"id":"S1014","name":"DanBot","url":"https://attack.mitre.org/software/S1014","kind":"malware","description":"[DanBot](https://attack.mitre.org/software/S1014) can download additional files to a targeted system.(Citation: SecureWorks August 2019)","relationship_id":"relationship--6bfbee18-c771-4260-b460-8058dbc5c08a","references":[{"source_name":"SecureWorks August 2019","description":"SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19 ","url":"https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign"}]},{"id":"S1015","name":"Milan","url":"https://attack.mitre.org/software/S1015","kind":"malware","description":"[Milan](https://attack.mitre.org/software/S1015) has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.(Citation: ClearSky Siamesekitten August 2021)","relationship_id":"relationship--4e39da36-f7e0-4e26-b354-ca34fb801e33","references":[{"source_name":"ClearSky Siamesekitten August 2021","description":"ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.","url":"https://www.clearskysec.com/siamesekitten/"}]},{"id":"S1016","name":"MacMa","url":"https://attack.mitre.org/software/S1016","kind":"malware","description":"[MacMa](https://attack.mitre.org/software/S1016) has downloaded additional files, including an exploit for used privilege escalation.(Citation: ESET DazzleSpy Jan 2022)(Citation: Objective-See MacMa Nov 2021)","relationship_id":"relationship--e132f8f8-c15d-4423-8794-8571d37a3998","references":[{"source_name":"ESET DazzleSpy Jan 2022","description":"M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.","url":"https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/"},{"source_name":"Objective-See MacMa Nov 2021","description":"Wardle, P. (2021, November 11). OSX.CDDS (OSX.MacMa). Retrieved June 30, 2022.","url":"https://objective-see.org/blog/blog_0x69.html"}]},{"id":"S1017","name":"OutSteel","url":"https://attack.mitre.org/software/S1017","kind":"malware","description":"[OutSteel](https://attack.mitre.org/software/S1017) can download files from its C2 server.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )","relationship_id":"relationship--e12c4451-5d26-4eea-a7e9-fcdfd517e77d","references":[{"source_name":"Palo Alto Unit 42 OutSteel SaintBot February 2022 ","description":"Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.","url":"https://unit42.paloaltonetworks.com/ukraine-targeted-outsteel-saintbot/"}]},{"id":"S1018","name":"Saint Bot","url":"https://attack.mitre.org/software/S1018","kind":"malware","description":"[Saint Bot](https://attack.mitre.org/software/S1018) can download additional files onto a compromised host.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )","relationship_id":"relationship--3a9e3914-2503-41e7-a9cb-57dd30f97a8a","references":[{"source_name":"Palo Alto Unit 42 OutSteel SaintBot February 2022 ","description":"Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.","url":"https://unit42.paloaltonetworks.com/ukraine-targeted-outsteel-saintbot/"}]},{"id":"S1019","name":"Shark","url":"https://attack.mitre.org/software/S1019","kind":"malware","description":"[Shark](https://attack.mitre.org/software/S1019)  can download additional files from its C2 via HTTP or DNS.(Citation: ClearSky Siamesekitten August 2021)(Citation: Accenture Lyceum Targets November 2021)","relationship_id":"relationship--03d6c33c-22d4-484f-8f16-8d49c307da80","references":[{"source_name":"Accenture Lyceum Targets November 2021","description":"Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.","url":"https://www.accenture.com/us-en/blogs/cyber-defense/iran-based-lyceum-campaigns"},{"source_name":"ClearSky Siamesekitten August 2021","description":"ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.","url":"https://www.clearskysec.com/siamesekitten/"}]},{"id":"S1020","name":"Kevin","url":"https://attack.mitre.org/software/S1020","kind":"malware","description":"[Kevin](https://attack.mitre.org/software/S1020) can download files to the compromised host.(Citation: Kaspersky Lyceum October 2021)","relationship_id":"relationship--3fadfbe5-6ed1-4d6d-a5ed-a355506431ba","references":[{"source_name":"Kaspersky Lyceum October 2021","description":"Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.","url":"https://vblocalhost.com/uploads/VB2021-Kayal-etal.pdf"}]},{"id":"S1021","name":"DnsSystem","url":"https://attack.mitre.org/software/S1021","kind":"malware","description":"[DnsSystem](https://attack.mitre.org/software/S1021) can download files to compromised systems after receiving a command with the string `downloaddd`.(Citation: Zscaler Lyceum DnsSystem June 2022)","relationship_id":"relationship--607ae633-8e47-457a-9507-511d1e28f470","references":[{"source_name":"Zscaler Lyceum DnsSystem June 2022","description":"Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022.","url":"https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor"}]},{"id":"S1023","name":"CreepyDrive","url":"https://attack.mitre.org/software/S1023","kind":"malware","description":"[CreepyDrive](https://attack.mitre.org/software/S1023) can download files to the compromised host.(Citation: Microsoft POLONIUM June 2022)","relationship_id":"relationship--ac5bf8d9-900b-4aa4-8f97-81566666cd26","references":[{"source_name":"Microsoft POLONIUM June 2022","description":"Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.","url":"https://www.microsoft.com/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/"}]},{"id":"S1025","name":"Amadey","url":"https://attack.mitre.org/software/S1025","kind":"malware","description":"[Amadey](https://attack.mitre.org/software/S1025) can download and execute files to further infect a host machine with additional malware.(Citation: BlackBerry Amadey 2020)","relationship_id":"relationship--a2b97730-39f9-4ba6-b481-d27f883ff26f","references":[{"source_name":"BlackBerry Amadey 2020","description":"Kasuya, M. (2020, January 8). Threat Spotlight: Amadey Bot Targets Non-Russian Users. Retrieved July 14, 2022.","url":"https://blogs.blackberry.com/en/2020/01/threat-spotlight-amadey-bot"}]},{"id":"S1026","name":"Mongall","url":"https://attack.mitre.org/software/S1026","kind":"malware","description":"[Mongall](https://attack.mitre.org/software/S1026) can download files to targeted systems.(Citation: SentinelOne Aoqin Dragon June 2022)","relationship_id":"relationship--ac062b78-400d-4d9a-9c5b-95c7a1b6dd42","references":[{"source_name":"SentinelOne Aoqin Dragon June 2022","description":"Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.","url":"https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years/"}]},{"id":"S1028","name":"Action RAT","url":"https://attack.mitre.org/software/S1028","kind":"malware","description":"[Action RAT](https://attack.mitre.org/software/S1028) has the ability to download additional payloads onto an infected machine.(Citation: MalwareBytes SideCopy Dec 2021)","relationship_id":"relationship--0e7cace2-18db-4068-8a99-3dc66ed24741","references":[{"source_name":"MalwareBytes SideCopy Dec 2021","description":"Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.","url":"https://www.malwarebytes.com/blog/news/2021/12/sidecopy-apt-connecting-lures-to-victims-payloads-to-infrastructure"}]},{"id":"S1030","name":"Squirrelwaffle","url":"https://attack.mitre.org/software/S1030","kind":"malware","description":"[Squirrelwaffle](https://attack.mitre.org/software/S1030) has downloaded and executed additional encoded payloads.(Citation: ZScaler Squirrelwaffle Sep 2021)(Citation: Netskope Squirrelwaffle Oct 2021)","relationship_id":"relationship--66794b81-fc1e-4a28-9a52-7e67d64cbed6","references":[{"source_name":"ZScaler Squirrelwaffle Sep 2021","description":"Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.","url":"https://www.zscaler.com/blogs/security-research/squirrelwaffle-new-loader-delivering-cobalt-strike"},{"source_name":"Netskope Squirrelwaffle Oct 2021","description":"Palazolo, G. (2021, October 7). SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot. Retrieved August 9, 2022.","url":"https://www.netskope.com/blog/squirrelwaffle-new-malware-loader-delivering-cobalt-strike-and-qakbot"}]},{"id":"S1034","name":"StrifeWater","url":"https://attack.mitre.org/software/S1034","kind":"malware","description":"[StrifeWater](https://attack.mitre.org/software/S1034) can download updates and auxiliary modules.(Citation: Cybereason StrifeWater Feb 2022)","relationship_id":"relationship--f12643cb-1ff8-49b9-a57e-38246a46c428","references":[{"source_name":"Cybereason StrifeWater Feb 2022","description":"Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.","url":"https://www.cybereason.com/blog/research/strifewater-rat-iranian-apt-moses-staff-adds-new-trojan-to-ransomware-operations"}]},{"id":"S1035","name":"Small Sieve","url":"https://attack.mitre.org/software/S1035","kind":"malware","description":"[Small Sieve](https://attack.mitre.org/software/S1035) has the ability to download files.(Citation: NCSC GCHQ Small Sieve Jan 2022)","relationship_id":"relationship--2ffd84e6-b76d-4c0c-9c76-ef8e55446546","references":[{"source_name":"NCSC GCHQ Small Sieve Jan 2022","description":"NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.","url":"https://www.ncsc.gov.uk/files/NCSC-Malware-Analysis-Report-Small-Sieve.pdf"}]},{"id":"S1039","name":"Bumblebee","url":"https://attack.mitre.org/software/S1039","kind":"malware","description":"[Bumblebee](https://attack.mitre.org/software/S1039) can download and execute additional payloads including through the use of a `Dex` command.(Citation: Google EXOTIC LILY March 2022)(Citation: Proofpoint Bumblebee April 2022)(Citation: Symantec Bumblebee June 2022)","relationship_id":"relationship--7065f730-96fc-4a33-b6fb-101af568b74b","references":[{"source_name":"Symantec Bumblebee June 2022","description":"Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.","url":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime"},{"source_name":"Proofpoint Bumblebee April 2022","description":"Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.","url":"https://www.proofpoint.com/us/blog/threat-insight/bumblebee-is-still-transforming"},{"source_name":"Google EXOTIC LILY March 2022","description":"Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.","url":"https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/"}]},{"id":"S1044","name":"FunnyDream","url":"https://attack.mitre.org/software/S1044","kind":"malware","description":"[FunnyDream](https://attack.mitre.org/software/S1044) can download additional files onto a compromised host.(Citation: Bitdefender FunnyDream Campaign November 2020)","relationship_id":"relationship--9c2ed616-647a-4cf5-9f43-b0b78f9fdcd1","references":[{"source_name":"Bitdefender FunnyDream Campaign November 2020","description":"Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/379/Bitdefender-Whitepaper-Chinese-APT.pdf"}]},{"id":"S1048","name":"macOS.OSAMiner","url":"https://attack.mitre.org/software/S1048","kind":"malware","description":"[macOS.OSAMiner](https://attack.mitre.org/software/S1048) has used `curl` to download a [Stripped Payloads](https://attack.mitre.org/techniques/T1027/008) from a public facing adversary-controlled webpage. ","relationship_id":"relationship--0a8e3f80-f415-450c-9976-feb917facd8a","references":[]},{"id":"S1059","name":"metaMain","url":"https://attack.mitre.org/software/S1059","kind":"malware","description":"[metaMain](https://attack.mitre.org/software/S1059) can download files onto compromised systems.(Citation: SentinelLabs Metador Sept 2022)(Citation: SentinelLabs Metador Technical Appendix Sept 2022)","relationship_id":"relationship--bd2c2f6f-5bc1-4150-b618-3b53b037670f","references":[{"source_name":"SentinelLabs Metador Sept 2022","description":"Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.","url":"https://assets.sentinelone.com/sentinellabs22/metador#page=1"},{"source_name":"SentinelLabs Metador Technical Appendix Sept 2022","description":"SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.","url":"https://docs.google.com/document/d/1e9ZTW9b71YwFWS_18ZwDAxa-cYbV8q1wUefmKZLYVsA/edit#heading=h.lmnbtht1ikzm"}]},{"id":"S1060","name":"Mafalda","url":"https://attack.mitre.org/software/S1060","kind":"malware","description":"[Mafalda](https://attack.mitre.org/software/S1060) can download additional files onto the compromised host.(Citation: SentinelLabs Metador Technical Appendix Sept 2022)","relationship_id":"relationship--995aaffc-947a-4674-825f-9b6d53b7aefc","references":[{"source_name":"SentinelLabs Metador Technical Appendix Sept 2022","description":"SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.","url":"https://docs.google.com/document/d/1e9ZTW9b71YwFWS_18ZwDAxa-cYbV8q1wUefmKZLYVsA/edit#heading=h.lmnbtht1ikzm"}]},{"id":"S1063","name":"Brute Ratel C4","url":"https://attack.mitre.org/software/S1063","kind":"tool","description":"\n[Brute Ratel C4](https://attack.mitre.org/software/S1063) can download files to compromised hosts.(Citation: Palo Alto Brute Ratel July 2022)(Citation: Rapid7 Fake W2 July 2024)","relationship_id":"relationship--d723027c-349b-48f8-af77-808ee2f7d92f","references":[{"source_name":"Rapid7 Fake W2 July 2024","description":"Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.","url":"https://www.rapid7.com/blog/post/2024/07/24/malware-campaign-lures-users-with-fake-w2-form/"},{"source_name":"Palo Alto Brute Ratel July 2022","description":"Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.","url":"https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/"}]},{"id":"S1064","name":"SVCReady","url":"https://attack.mitre.org/software/S1064","kind":"malware","description":"[SVCReady](https://attack.mitre.org/software/S1064) has the ability to download additional tools such as the RedLine Stealer to an infected host.(Citation: HP SVCReady Jun 2022)","relationship_id":"relationship--3f491de8-7a45-413d-8e80-5c74b38e0fc1","references":[{"source_name":"HP SVCReady Jun 2022","description":"Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.","url":"https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/"}]},{"id":"S1065","name":"Woody RAT","url":"https://attack.mitre.org/software/S1065","kind":"malware","description":"[Woody RAT](https://attack.mitre.org/software/S1065) can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`.(Citation: MalwareBytes WoodyRAT Aug 2022) ","relationship_id":"relationship--88e52860-d4cc-485a-b23f-ad2cda301727","references":[{"source_name":"MalwareBytes WoodyRAT Aug 2022","description":"MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022.","url":"https://www.malwarebytes.com/blog/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild"}]},{"id":"S1066","name":"DarkTortilla","url":"https://attack.mitre.org/software/S1066","kind":"malware","description":"[DarkTortilla](https://attack.mitre.org/software/S1066) can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as [Agent Tesla](https://attack.mitre.org/software/S0331), AsyncRat, [NanoCore](https://attack.mitre.org/software/S0336), RedLine, [Cobalt Strike](https://attack.mitre.org/software/S0154), and Metasploit.(Citation: Secureworks DarkTortilla Aug 2022)","relationship_id":"relationship--02c8a28f-c188-47a9-ab93-d9abb862abab","references":[{"source_name":"Secureworks DarkTortilla Aug 2022","description":"Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.","url":"https://www.secureworks.com/research/darktortilla-malware-analysis"}]},{"id":"S1074","name":"ANDROMEDA","url":"https://attack.mitre.org/software/S1074","kind":"malware","description":"[ANDROMEDA](https://attack.mitre.org/software/S1074) can download additional payloads from C2.(Citation: Mandiant Suspected Turla Campaign February 2023)","relationship_id":"relationship--0b15b2f4-ba30-4393-88ec-08235206bfac","references":[{"source_name":"Mandiant Suspected Turla Campaign February 2023","description":"Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.","url":"https://www.mandiant.com/resources/blog/turla-galaxy-opportunity"}]},{"id":"S1081","name":"BADHATCH","url":"https://attack.mitre.org/software/S1081","kind":"malware","description":"[BADHATCH](https://attack.mitre.org/software/S1081) has the ability to load a second stage malicious DLL file onto a compromised machine.(Citation: Gigamon BADHATCH Jul 2019) ","relationship_id":"relationship--785e8778-84d2-46a5-b96a-ea71b1adc650","references":[{"source_name":"Gigamon BADHATCH Jul 2019","description":"Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8's Tooling. Retrieved September 8, 2021.","url":"https://blog.gigamon.com/2019/07/23/abadbabe-8badf00d-discovering-badhatch-and-a-detailed-look-at-fin8s-tooling/"}]},{"id":"S1085","name":"Sardonic","url":"https://attack.mitre.org/software/S1085","kind":"malware","description":"[Sardonic](https://attack.mitre.org/software/S1085) has the ability to upload additional malicious files to a compromised machine.(Citation: Bitdefender Sardonic Aug 2021)","relationship_id":"relationship--49f54bdd-564c-43b0-95d7-5300f20d994f","references":[{"source_name":"Bitdefender Sardonic Aug 2021","description":"Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.","url":"https://www.bitdefender.com/files/News/CaseStudies/study/401/Bitdefender-PR-Whitepaper-FIN8-creat5619-en-EN.pdf"}]},{"id":"S1086","name":"Snip3","url":"https://attack.mitre.org/software/S1086","kind":"malware","description":"[Snip3](https://attack.mitre.org/software/S1086) can download additional payloads to compromised systems.(Citation: Morphisec Snip3 May 2021)(Citation: Telefonica Snip3 December 2021)","relationship_id":"relationship--992be3b6-caea-497f-ae2b-256197433cc8","references":[{"source_name":"Telefonica Snip3 December 2021","description":"Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023.","url":"https://telefonicatech.com/blog/snip3-investigacion-malware"},{"source_name":"Morphisec Snip3 May 2021","description":"Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.","url":"https://blog.morphisec.com/revealing-the-snip3-crypter-a-highly-evasive-rat-loader"}]},{"id":"S1087","name":"AsyncRAT","url":"https://attack.mitre.org/software/S1087","kind":"tool","description":"[AsyncRAT](https://attack.mitre.org/software/S1087) has the ability to download files including over SFTP.(Citation: AsyncRAT GitHub)(Citation: ESET MirrorFace 2025)","relationship_id":"relationship--ca31e6ec-8cf9-4e5e-907a-895c3d19543f","references":[{"source_name":"ESET MirrorFace 2025","description":" Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.","url":"https://www.welivesecurity.com/en/eset-research/operation-akairyu-mirrorface-invites-europe-expo-2025-revives-anel-backdoor/"},{"source_name":"AsyncRAT GitHub","description":"Nyan-x-Cat. (n.d.). NYAN-x-CAT / AsyncRAT-C-Sharp. Retrieved October 3, 2023.","url":"https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/README.md"}]},{"id":"S1088","name":"Disco","url":"https://attack.mitre.org/software/S1088","kind":"malware","description":"[Disco](https://attack.mitre.org/software/S1088) can download files to targeted systems via SMB.(Citation: MoustachedBouncer ESET August 2023)","relationship_id":"relationship--128afec2-d9a5-4433-89d9-0cc65abf15bd","references":[{"source_name":"MoustachedBouncer ESET August 2023","description":"Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.","url":"https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/"}]},{"id":"S1089","name":"SharpDisco","url":"https://attack.mitre.org/software/S1089","kind":"malware","description":"[SharpDisco](https://attack.mitre.org/software/S1089) has been used to download a Python interpreter to `C:\\Users\\Public\\WinTN\\WinTN.exe` as well as other plugins from external sources.(Citation: MoustachedBouncer ESET August 2023)","relationship_id":"relationship--f02fafab-e905-48a4-953d-6238f740cc77","references":[{"source_name":"MoustachedBouncer ESET August 2023","description":"Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.","url":"https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/"}]},{"id":"S1090","name":"NightClub","url":"https://attack.mitre.org/software/S1090","kind":"malware","description":"[NightClub](https://attack.mitre.org/software/S1090) can load multiple additional plugins on an infected host.(Citation: MoustachedBouncer ESET August 2023)","relationship_id":"relationship--a881d020-95c1-4123-98d0-c31cb8d2ff4e","references":[{"source_name":"MoustachedBouncer ESET August 2023","description":"Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.","url":"https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/"}]},{"id":"S1099","name":"Samurai","url":"https://attack.mitre.org/software/S1099","kind":"malware","description":"[Samurai](https://attack.mitre.org/software/S1099) has been used to deploy other malware including [Ninja](https://attack.mitre.org/software/S1100).(Citation: Kaspersky ToddyCat June 2022)","relationship_id":"relationship--62435a47-3830-4518-9c9f-1f0d25711907","references":[{"source_name":"Kaspersky ToddyCat June 2022","description":"Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.","url":"https://securelist.com/toddycat/106799/"}]},{"id":"S1110","name":"SLIGHTPULSE","url":"https://attack.mitre.org/software/S1110","kind":"malware","description":"[RAPIDPULSE](https://attack.mitre.org/software/S1113) can transfer files to and from compromised hosts.(Citation: Mandiant Pulse Secure Update May 2021)","relationship_id":"relationship--5de10f34-9796-499d-a3e4-3977f2eb7154","references":[{"source_name":"Mandiant Pulse Secure Update May 2021","description":"Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.","url":"https://www.mandiant.com/resources/blog/updates-on-chinese-apt-compromising-pulse-secure-vpn-devices"}]},{"id":"S1111","name":"DarkGate","url":"https://attack.mitre.org/software/S1111","kind":"malware","description":"[DarkGate](https://attack.mitre.org/software/S1111) retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server.(Citation: Ensilo Darkgate 2018) [DarkGate](https://attack.mitre.org/software/S1111) uses Windows Batch scripts executing the <code>curl</code> command to retrieve follow-on payloads.(Citation: Trellix Darkgate 2023) [DarkGate](https://attack.mitre.org/software/S1111) has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\\FileZilla\\` if present.(Citation: Rapid7 BlackBasta 2024) ","relationship_id":"relationship--89006d46-811b-4ad7-9b27-cf9f563418a2","references":[{"source_name":"Ensilo Darkgate 2018","description":"Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.","url":"https://www.fortinet.com/blog/threat-research/enter-the-darkgate-new-cryptocurrency-mining-and-ransomware-campaign"},{"source_name":"Trellix Darkgate 2023","description":"Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.","url":"https://www.trellix.com/blogs/research/the-continued-evolution-of-the-darkgate-malware-as-a-service/"},{"source_name":"Rapid7 BlackBasta 2024","description":"McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.","url":"https://www.rapid7.com/blog/post/2024/12/04/black-basta-ransomware-campaign-drops-zbot-darkgate-and-custom-malware/"}]},{"id":"S1112","name":"STEADYPULSE","url":"https://attack.mitre.org/software/S1112","kind":"malware","description":"[STEADYPULSE](https://attack.mitre.org/software/S1112) can add lines to a Perl script on a targeted server to import additional Perl modules.(Citation: Mandiant Pulse Secure Zero-Day April 2021)","relationship_id":"relationship--ef96fb44-5139-4547-9660-2ba64e6635d9","references":[{"source_name":"Mandiant Pulse Secure Zero-Day April 2021","description":"Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.","url":"https://www.mandiant.com/resources/blog/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day"}]},{"id":"S1114","name":"ZIPLINE","url":"https://attack.mitre.org/software/S1114","kind":"malware","description":"[ZIPLINE](https://attack.mitre.org/software/S1114) can download files to be saved on the compromised system.(Citation: Mandiant Cutting Edge January 2024)(Citation: Mandiant Cutting Edge Part 2 January 2024)","relationship_id":"relationship--e34a0e21-1db1-4c11-8e71-07bae802d8b9","references":[{"source_name":"Mandiant Cutting Edge Part 2 January 2024","description":"Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.","url":"https://www.mandiant.com/resources/blog/investigating-ivanti-zero-day-exploitation"},{"source_name":"Mandiant Cutting Edge January 2024","description":"McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.","url":"https://www.mandiant.com/resources/blog/suspected-apt-targets-ivanti-zero-day"}]},{"id":"S1115","name":"WIREFIRE","url":"https://attack.mitre.org/software/S1115","kind":"malware","description":"[WIREFIRE](https://attack.mitre.org/software/S1115) has the ability to download files to compromised devices.(Citation: Mandiant Cutting Edge January 2024)","relationship_id":"relationship--3c295abc-714f-4c14-82dd-554761b4a0b2","references":[{"source_name":"Mandiant Cutting Edge January 2024","description":"McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.","url":"https://www.mandiant.com/resources/blog/suspected-apt-targets-ivanti-zero-day"}]},{"id":"S1118","name":"BUSHWALK","url":"https://attack.mitre.org/software/S1118","kind":"malware","description":"[BUSHWALK](https://attack.mitre.org/software/S1118) can write malicious payloads sent through a web request’s command parameter.(Citation: Mandiant Cutting Edge Part 2 January 2024)(Citation: Mandiant Cutting Edge Part 3 February 2024)","relationship_id":"relationship--01d9bce9-9ae9-4167-b279-0f0ee4e6b263","references":[{"source_name":"Mandiant Cutting Edge Part 3 February 2024","description":"Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.","url":"https://www.mandiant.com/resources/blog/investigating-ivanti-exploitation-persistence"},{"source_name":"Mandiant Cutting Edge Part 2 January 2024","description":"Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.","url":"https://www.mandiant.com/resources/blog/investigating-ivanti-zero-day-exploitation"}]},{"id":"S1124","name":"SocGholish","url":"https://attack.mitre.org/software/S1124","kind":"malware","description":"[SocGholish](https://attack.mitre.org/software/S1124) can download additional malware to infected hosts.(Citation: Red Canary SocGholish March 2024)(Citation: Secureworks Gold Prelude Profile)","relationship_id":"relationship--446e3bf2-9a37-4d22-a7ca-ede547e5e16e","references":[{"source_name":"Red Canary SocGholish March 2024","description":"Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.","url":"https://redcanary.com/threat-detection-report/threats/socgholish/"},{"source_name":"Secureworks Gold Prelude Profile","description":"Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.","url":"https://www.secureworks.com/research/threat-profiles/gold-prelude"}]},{"id":"S1130","name":"Raspberry Robin","url":"https://attack.mitre.org/software/S1130","kind":"malware","description":"[Raspberry Robin](https://attack.mitre.org/software/S1130) retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's <code>%AppData%</code> folder.(Citation: HP RaspberryRobin 2024)(Citation: RedCanary RaspberryRobin 2022)","relationship_id":"relationship--538697e9-2dda-43cb-ba43-208402f62f9d","references":[{"source_name":"RedCanary RaspberryRobin 2022","description":"Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.","url":"https://redcanary.com/blog/threat-intelligence/raspberry-robin/"},{"source_name":"HP RaspberryRobin 2024","description":"Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.","url":"https://threatresearch.ext.hp.com/raspberry-robin-now-spreading-through-windows-script-files/"}]},{"id":"S1138","name":"Gootloader","url":"https://attack.mitre.org/software/S1138","kind":"malware","description":"[Gootloader](https://attack.mitre.org/software/S1138) can fetch second stage code from hardcoded web domains.(Citation: Sophos Gootloader)(Citation: SentinelOne Gootloader June 2021)","relationship_id":"relationship--d27bfd8a-f9f3-4dbf-86a2-b12ac9ea3de8","references":[{"source_name":"SentinelOne Gootloader June 2021","description":"Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.","url":"https://www.sentinelone.com/labs/gootloader-initial-access-as-a-service-platform-expands-its-search-for-high-value-targets/"},{"source_name":"Sophos Gootloader","description":"Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.","url":"https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/"}]},{"id":"S1140","name":"Spica","url":"https://attack.mitre.org/software/S1140","kind":"malware","description":"[Spica](https://attack.mitre.org/software/S1140) can upload and download files to and from compromised hosts.(Citation: Google TAG COLDRIVER January 2024)","relationship_id":"relationship--598500a6-dbb0-435c-a022-67150d6d11e8","references":[{"source_name":"Google TAG COLDRIVER January 2024","description":"Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.","url":"https://blog.google/threat-analysis-group/google-tag-coldriver-russian-phishing-malware/"}]},{"id":"S1148","name":"Raccoon Stealer","url":"https://attack.mitre.org/software/S1148","kind":"malware","description":"[Raccoon Stealer](https://attack.mitre.org/software/S1148) downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.(Citation: S2W Racoon 2022)(Citation: Sekoia Raccoon2 2022)","relationship_id":"relationship--688a4ea0-c9ff-4bb1-a6ab-fc565cea1461","references":[{"source_name":"Sekoia Raccoon2 2022","description":"Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.","url":"https://blog.sekoia.io/raccoon-stealer-v2-part-2-in-depth-analysis/"},{"source_name":"S2W Racoon 2022","description":"S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.","url":"https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d"}]},{"id":"S1149","name":"CHIMNEYSWEEP","url":"https://attack.mitre.org/software/S1149","kind":"malware","description":"[CHIMNEYSWEEP](https://attack.mitre.org/software/S1149) can download additional files from C2.(Citation: Mandiant ROADSWEEP August 2022)","relationship_id":"relationship--23b98d85-7ae7-4611-80a4-36441c2462e3","references":[{"source_name":"Mandiant ROADSWEEP August 2022","description":"Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against/"}]},{"id":"S1152","name":"IMAPLoader","url":"https://attack.mitre.org/software/S1152","kind":"malware","description":"[IMAPLoader](https://attack.mitre.org/software/S1152) is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.(Citation: PWC Yellow Liderc 2023)","relationship_id":"relationship--e54309eb-8865-452a-8a87-55168264612a","references":[{"source_name":"PWC Yellow Liderc 2023","description":"PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.","url":"https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/yellow-liderc-ships-its-scripts-delivers-imaploader-malware.html"}]},{"id":"S1159","name":"DUSTTRAP","url":"https://attack.mitre.org/software/S1159","kind":"malware","description":"[DUSTTRAP](https://attack.mitre.org/software/S1159) can retrieve and load additional payloads.(Citation: Google Cloud APT41 2024)","relationship_id":"relationship--7a0da394-d797-4649-b9bf-1b5822ca3467","references":[{"source_name":"Google Cloud APT41 2024","description":"Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/apt41-arisen-from-dust"}]},{"id":"S1160","name":"Latrodectus","url":"https://attack.mitre.org/software/S1160","kind":"malware","description":"[Latrodectus](https://attack.mitre.org/software/S1160) can download and execute PEs, DLLs, and shellcode from C2.(Citation: Latrodectus APR 2024)(Citation: Elastic Latrodectus May 2024)(Citation: Bitsight Latrodectus June 2024)","relationship_id":"relationship--70d06758-46ce-47b9-a3af-ff341d210a4a","references":[{"source_name":"Bitsight Latrodectus June 2024","description":"Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.","url":"https://www.bitsight.com/blog/latrodectus-are-you-coming-back"},{"source_name":"Latrodectus APR 2024","description":"Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.","url":"https://www.proofpoint.com/us/blog/threat-insight/latrodectus-spider-bytes-ice"},{"source_name":"Elastic Latrodectus May 2024","description":"Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.","url":"https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus"}]},{"id":"S1166","name":"Solar","url":"https://attack.mitre.org/software/S1166","kind":"malware","description":"[Solar](https://attack.mitre.org/software/S1166) has the ability to download and execute files.(Citation: ESET OilRig Campaigns Sep 2023)","relationship_id":"relationship--3c6b31af-c6aa-4254-87f9-b9fdd473b40a","references":[{"source_name":"ESET OilRig Campaigns Sep 2023","description":"Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/"}]},{"id":"S1168","name":"SampleCheck5000","url":"https://attack.mitre.org/software/S1168","kind":"malware","description":"[SampleCheck5000](https://attack.mitre.org/software/S1168) can download additional payloads to compromised hosts.(Citation: ESET OilRig Campaigns Sep 2023)(Citation: ESET OilRig Downloaders DEC 2023)","relationship_id":"relationship--53afb9f9-366b-4f0c-b348-05cd430f809a","references":[{"source_name":"ESET OilRig Downloaders DEC 2023","description":"Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/"},{"source_name":"ESET OilRig Campaigns Sep 2023","description":"Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/"}]},{"id":"S1170","name":"ODAgent","url":"https://attack.mitre.org/software/S1170","kind":"malware","description":"[ODAgent](https://attack.mitre.org/software/S1170) has the ability to download and execute files on compromised systems.(Citation: ESET OilRig Downloaders DEC 2023)","relationship_id":"relationship--457b0035-c414-4d7e-a708-ca07a5696deb","references":[{"source_name":"ESET OilRig Downloaders DEC 2023","description":"Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/"}]},{"id":"S1171","name":"OilCheck","url":"https://attack.mitre.org/software/S1171","kind":"malware","description":"[OilCheck](https://attack.mitre.org/software/S1171) can download staged payloads from an actor-controlled infrastructure.(Citation: ESET OilRig Downloaders DEC 2023)","relationship_id":"relationship--8523250e-25c3-4eb0-ae89-397965b9712e","references":[{"source_name":"ESET OilRig Downloaders DEC 2023","description":"Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/"}]},{"id":"S1172","name":"OilBooster","url":"https://attack.mitre.org/software/S1172","kind":"malware","description":"[OilBooster](https://attack.mitre.org/software/S1172) can download and execute files from an actor-controlled OneDrive account.(Citation: ESET OilRig Downloaders DEC 2023)","relationship_id":"relationship--9dbe8924-bf0a-4b76-98ff-04f6f442ae8b","references":[{"source_name":"ESET OilRig Downloaders DEC 2023","description":"Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.","url":"https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/"}]},{"id":"S1173","name":"PowerExchange","url":"https://attack.mitre.org/software/S1173","kind":"malware","description":"[PowerExchange](https://attack.mitre.org/software/S1173) can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.(Citation: Symantec Crambus OCT 2023)","relationship_id":"relationship--1632dc5e-5ec9-4c93-9fc3-e4496879dfab","references":[{"source_name":"Symantec Crambus OCT 2023","description":"Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.","url":"https://www.security.com/threat-intelligence/crambus-middle-east-government"}]},{"id":"S1182","name":"MagicRAT","url":"https://attack.mitre.org/software/S1182","kind":"malware","description":"[MagicRAT](https://attack.mitre.org/software/S1182) can import and execute additional payloads.(Citation: Cisco MagicRAT 2022)","relationship_id":"relationship--1918de84-79d9-447f-9bef-0b8fa601758a","references":[{"source_name":"Cisco MagicRAT 2022","description":"Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024.","url":"https://blog.talosintelligence.com/lazarus-magicrat/"}]},{"id":"S1183","name":"StrelaStealer","url":"https://attack.mitre.org/software/S1183","kind":"malware","description":"[StrelaStealer](https://attack.mitre.org/software/S1183) installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.(Citation: IBM StrelaStealer 2024)","relationship_id":"relationship--d40cf993-60c2-4b5f-8af8-fb8975b43ebf","references":[{"source_name":"IBM StrelaStealer 2024","description":"Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.","url":"https://securityintelligence.com/x-force/strela-stealer-todays-invoice-tomorrows-phish/"}]},{"id":"S1185","name":"LightSpy","url":"https://attack.mitre.org/software/S1185","kind":"malware","description":"On macOS, [LightSpy](https://attack.mitre.org/software/S1185) downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. [LightSpy](https://attack.mitre.org/software/S1185) retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. [LightSpy](https://attack.mitre.org/software/S1185) also imports open-source libraries to manage socket connections.(Citation: Huntress LightSpy macOS 2024)","relationship_id":"relationship--343c91aa-d902-409b-804d-e751d6715f1a","references":[{"source_name":"Huntress LightSpy macOS 2024","description":"Stuart Ashenbrenner, Alden Schmidt. (2024, April 25). LightSpy Malware Variant Targeting macOS. Retrieved January 3, 2025.","url":"https://www.huntress.com/blog/lightspy-malware-variant-targeting-macos"}]},{"id":"S1187","name":"reGeorg","url":"https://attack.mitre.org/software/S1187","kind":"malware","description":"[reGeorg](https://attack.mitre.org/software/S1187) has the ability to download files to targeted systems.(Citation: GitHub Neo-reGeorg 2019)","relationship_id":"relationship--5df789ae-1df2-4be4-9844-6c26b7c6d697","references":[{"source_name":"GitHub Neo-reGeorg 2019","description":"L-Codes. (2019). Neo-reGeorg. Retrieved December 4, 2024.","url":"https://github.com/L-codes/Neo-reGeorg/blob/master/README-en.md"}]},{"id":"S1189","name":"Neo-reGeorg","url":"https://attack.mitre.org/software/S1189","kind":"malware","description":"[Neo-reGeorg](https://attack.mitre.org/software/S1189) has the ability to download files to targeted systems.(Citation: GitHub Neo-reGeorg 2019)","relationship_id":"relationship--0dc7c2ef-bbeb-4d0a-be04-4f2d8c57be6f","references":[{"source_name":"GitHub Neo-reGeorg 2019","description":"L-Codes. (2019). Neo-reGeorg. Retrieved December 4, 2024.","url":"https://github.com/L-codes/Neo-reGeorg/blob/master/README-en.md"}]},{"id":"S1192","name":"NICECURL","url":"https://attack.mitre.org/software/S1192","kind":"malware","description":"[NICECURL](https://attack.mitre.org/software/S1192) has the ability to download additional content onto an infected machine, e.g. by using `curl`.(Citation: Mandiant APT42-untangling) ","relationship_id":"relationship--f3e042f4-e641-4d7e-8c8d-40d17851eeda","references":[{"source_name":"Mandiant APT42-untangling","description":"Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations"}]},{"id":"S1193","name":"TAMECAT","url":"https://attack.mitre.org/software/S1193","kind":"malware","description":"[TAMECAT](https://attack.mitre.org/software/S1193) has used `wget` and `curl` to download additional content.(Citation: Mandiant APT42-untangling) ","relationship_id":"relationship--2a587f38-6625-4949-ae69-ed456f088d8b","references":[{"source_name":"Mandiant APT42-untangling","description":"Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations"}]},{"id":"S1211","name":"Hannotog","url":"https://attack.mitre.org/software/S1211","kind":"malware","description":"[Hannotog](https://attack.mitre.org/software/S1211) can download additional files to the victim machine.(Citation: Symantec Bilbug 2022)","relationship_id":"relationship--db526d10-c127-476d-9d97-668c139f6c05","references":[{"source_name":"Symantec Bilbug 2022","description":"Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.","url":"https://www.security.com/threat-intelligence/espionage-asia-governments-cert-authority"}]},{"id":"S1217","name":"VIRTUALPITA","url":"https://attack.mitre.org/software/S1217","kind":"malware","description":"[VIRTUALPITA](https://attack.mitre.org/software/S1217) has the ability to upload and download files.(Citation: Google Cloud Threat Intelligence ESXi VIBs 2022)","relationship_id":"relationship--6ebaf47d-862d-4522-83d4-71590ac9f7f6","references":[{"source_name":"Google Cloud Threat Intelligence ESXi VIBs 2022","description":"Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.","url":"https://cloud.google.com/blog/topics/threat-intelligence/esxi-hypervisors-malware-persistence"}]},{"id":"S1222","name":"RIFLESPINE","url":"https://attack.mitre.org/software/S1222","kind":"malware","description":"[RIFLESPINE](https://attack.mitre.org/software/S1222) can download and execute files.(Citation: Google Cloud Mandiant UNC3886 2024)","relationship_id":"relationship--4fc2c8ef-7c54-419a-af32-20fcd9770cfc","references":[{"source_name":"Google Cloud Mandiant UNC3886 2024","description":" Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/uncovering-unc3886-espionage-operations"}]},{"id":"S1224","name":"CASTLETAP","url":"https://attack.mitre.org/software/S1224","kind":"malware","description":"[CASTLETAP](https://attack.mitre.org/software/S1224) can transfer files to compromised network devices.(Citation: Mandiant Fortinet Zero Day)","relationship_id":"relationship--2798addb-2787-4573-9380-9b2449dd3c94","references":[{"source_name":"Mandiant Fortinet Zero Day","description":"Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.","url":"https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem"}]},{"id":"S1228","name":"PUBLOAD","url":"https://attack.mitre.org/software/S1228","kind":"malware","description":"[PUBLOAD](https://attack.mitre.org/software/S1228) has acted as a stager that can download the next-stage payload from its C2 server.(Citation: Lab52 MUSTANG PANDA PUBLOAD MAY 2023)(Citation: IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025)(Citation: 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA)(Citation: 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload)(Citation: Palo Alto Networks, Unit 42) [PUBLOAD](https://attack.mitre.org/software/S1228) has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.(Citation: Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024)","relationship_id":"relationship--01c84feb-9dcf-455f-8900-fba08e8e7bc3","references":[{"source_name":"Lab52 MUSTANG PANDA PUBLOAD MAY 2023","description":"Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025.","url":"https://lab52.io/blog/new-mustang-pandas-campaing-against-australia/"},{"source_name":"IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025","description":"Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.","url":"https://www.ibm.com/think/x-force/hive0154-mustang-panda-shifts-focus-tibetan-community-deploy-pubload-backdoor"},{"source_name":"2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA","description":"Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.","url":"https://www.ibm.com/think/x-force/hive0154-targeting-us-philippines-pakistan-taiwan"},{"source_name":"Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024","description":"Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.","url":"https://www.trendmicro.com/en_us/research/24/i/earth-preta-new-malware-and-strategies.html"},{"source_name":"2022 November_TrendMicro_Earth Preta_Toneshell_Pubload","description":"Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.","url":"https://www.trendmicro.com/en_us/research/22/k/earth-preta-spear-phishing-governments-worldwide.html"},{"source_name":"Palo Alto Networks, Unit 42","description":"Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.","url":"https://unit42.paloaltonetworks.com/stately-taurus-uses-bookworm-malware/"}]},{"id":"S1229","name":"Havoc","url":"https://attack.mitre.org/software/S1229","kind":"malware","description":"[Havoc](https://attack.mitre.org/software/S1229) has the ability to upload files to infected systems.(Citation: Havoc Framework Documentation)(Citation: Immersive Labs Havoc C2 APR 2024)","relationship_id":"relationship--55488927-0c46-4dfc-98f6-ceb530026578","references":[{"source_name":"Immersive Labs Havoc C2 APR 2024","description":"Immersive Content Team. (2024, April 9). Havoc C2 Framework – A Defensive Operator’s Guide. Retrieved August 13, 2025.","url":"https://www.immersivelabs.com/resources/blog/havoc-c2-framework-a-defensive-operators-guide"},{"source_name":"Havoc Framework Documentation","description":"Ungur, P. (n.d.). HAVOC. Retrieved August 4, 2025.","url":"https://havocframework.com/docs/welcome"}]},{"id":"S1239","name":"TONESHELL","url":"https://attack.mitre.org/software/S1239","kind":"malware","description":"[TONESHELL](https://attack.mitre.org/software/S1239) has the ability to download additional files to the victim device.(Citation: Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023)","relationship_id":"relationship--5560a545-7bc2-482a-bb85-eaf4e2ed773b","references":[{"source_name":"Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023","description":"Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.","url":"https://unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-government/"}]},{"id":"S1240","name":"RedLine Stealer","url":"https://attack.mitre.org/software/S1240","kind":"malware","description":"[RedLine Stealer](https://attack.mitre.org/software/S1240) has the ability download additional payloads.(Citation: Kroll RedLine Stealer August 2024)(Citation: Veriti RedLine Stealer MAAS April 2023)","relationship_id":"relationship--94813c25-e3ba-4f51-ba49-f0fc5e486e8a","references":[{"source_name":"Kroll RedLine Stealer August 2024","description":"George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.","url":"https://www.kroll.com/en/publications/cyber/redlinestealer-malware"},{"source_name":"Veriti RedLine Stealer MAAS April 2023","description":"Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025.","url":"https://veriti.ai/blog/veriti-research/from-chatgpt-to-redline-stealer-the-dark-side-of-openai-and-google-bard/"}]},{"id":"S1245","name":"InvisibleFerret","url":"https://attack.mitre.org/software/S1245","kind":"malware","description":"[InvisibleFerret](https://attack.mitre.org/software/S1245) has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment.(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025) [InvisibleFerret](https://attack.mitre.org/software/S1245) has also been configured to download additional payloads using a command which calls to the /bow URI.(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)","relationship_id":"relationship--497ebc9c-e993-4097-9cb0-11b5a13b0bb5","references":[{"source_name":"ESET Contagious Interview BeaverTail InvisibleFerret February 2025","description":"Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.","url":"https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/"},{"source_name":"Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024","description":"Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.","url":"https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west"},{"source_name":"PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023","description":"Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.","url":"https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/"}]},{"id":"S1246","name":"BeaverTail","url":"https://attack.mitre.org/software/S1246","kind":"malware","description":"[BeaverTail](https://attack.mitre.org/software/S1246) has been used to download a malicious payload to include Python based malware [InvisibleFerret](https://attack.mitre.org/software/S1245).(Citation: Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024)(Citation: Socket BeaverTail XORIndex HexEval Contagious Interview July 2025)(Citation: Socket HexEval BeaverTail Contagious Interview June 2025)(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023)(Citation: PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024)","relationship_id":"relationship--af861bf5-a686-4661-8613-c3f1c6972723","references":[{"source_name":"Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024","description":"eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.","url":"https://www.esentire.com/blog/bored-beavertail-invisibleferret-yacht-club-a-lazarus-lure-pt-2"},{"source_name":"Socket BeaverTail XORIndex HexEval Contagious Interview July 2025","description":"Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.","url":"https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages"},{"source_name":"Socket HexEval BeaverTail Contagious Interview June 2025","description":"Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.","url":"https://socket.dev/blog/north-korean-contagious-interview-campaign-drops-35-new-malicious-npm-packages"},{"source_name":"ESET Contagious Interview BeaverTail InvisibleFerret February 2025","description":"Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.","url":"https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/"},{"source_name":"PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023","description":"Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.","url":"https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/"},{"source_name":"PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024","description":"Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.","url":"https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/"}]},{"id":"S1248","name":"XORIndex Loader","url":"https://attack.mitre.org/software/S1248","kind":"malware","description":"[XORIndex Loader](https://attack.mitre.org/software/S1248) has been used to download a malicious payload to include [BeaverTail](https://attack.mitre.org/software/S1246).(Citation: Socket BeaverTail XORIndex HexEval Contagious Interview July 2025)","relationship_id":"relationship--a8195876-514d-49b7-9b9c-30c75eaff089","references":[{"source_name":"Socket BeaverTail XORIndex HexEval Contagious Interview July 2025","description":"Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.","url":"https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages"}]},{"id":"S1249","name":"HexEval Loader","url":"https://attack.mitre.org/software/S1249","kind":"malware","description":"[HexEval Loader](https://attack.mitre.org/software/S1249) has been used to download a malicious payload to include [BeaverTail](https://attack.mitre.org/software/S1246).(Citation: Socket Contagious Interview NPM April 2025)(Citation: Socket BeaverTail XORIndex HexEval Contagious Interview July 2025)(Citation: Socket HexEval BeaverTail Contagious Interview June 2025)","relationship_id":"relationship--2dc59875-4281-45f2-acfb-5e36428e812d","references":[{"source_name":"Socket Contagious Interview NPM April 2025","description":"Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.","url":"https://socket.dev/blog/lazarus-expands-malicious-npm-campaign-11-new-packages-add-malware-loaders-and-bitbucket"},{"source_name":"Socket BeaverTail XORIndex HexEval Contagious Interview July 2025","description":"Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.","url":"https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages"},{"source_name":"Socket HexEval BeaverTail Contagious Interview June 2025","description":"Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.","url":"https://socket.dev/blog/north-korean-contagious-interview-campaign-drops-35-new-malicious-npm-packages"}]},{"id":"S9001","name":"SystemBC","url":"https://attack.mitre.org/software/S9001","kind":"malware","description":"[SystemBC](https://attack.mitre.org/software/S9001) has downloaded additional files for execution on the victim’s machine.(Citation: SophosGnGal_SystemBC_Dec2020)(Citation: TrumanKroll_SYSTEMBCServer_Jan2024) The server component of [SystemBC](https://attack.mitre.org/software/S9001) has the ability to send additional files to victim machines.(Citation: TrumanKroll_SYSTEMBCServer_Jan2024)","relationship_id":"relationship--2eb1f662-5901-4bbe-b45b-54c8dfc5e20e","references":[{"source_name":"SophosGnGal_SystemBC_Dec2020","description":"Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.","url":"https://news.sophos.com/en-us/2020/12/16/systembc/"},{"source_name":"TrumanKroll_SYSTEMBCServer_Jan2024","description":"Truman, D. (2024, January 19). Inside the SYSTEMBC Command-and-Control Server. Retrieved June 18, 2025.","url":"https://www.kroll.com/en/publications/cyber/inside-the-systembc-malware-server"}]},{"id":"S9007","name":"HTTPTroy","url":"https://attack.mitre.org/software/S9007","kind":"malware","description":"[HTTPTroy](https://attack.mitre.org/software/S9007) has the ability to download files from C2 using the `down <FILENAME>` command.(Citation: Gen Digital Kimsuky HTTPTroy October 2025)","relationship_id":"relationship--0f164983-ed7d-44cc-b6db-90b141e271ff","references":[{"source_name":"Gen Digital Kimsuky HTTPTroy October 2025","description":"Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.","url":"https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis"}]},{"id":"S9008","name":"Shai-Hulud","url":"https://attack.mitre.org/software/S9008","kind":"malware","description":"[Shai-Hulud](https://attack.mitre.org/software/S9008) has downloaded packages from code repositories.(Citation: Aikido Shai-Hulud September 2025)(Citation: Wiz Shai-Hulud September 2025)(Citation: Socket Shai-Hulud November 2025)(Citation: Socket Shai-Hulud Trufflehog September 2025) [Shai-Hulud](https://attack.mitre.org/software/S9008) has also downloaded and executed the secrets-discovery tool [TruffleHog](https://attack.mitre.org/software/S9009) to gather sensitive data.(Citation: Netskope Shai-Hulud November 2025)(Citation: Wiz Shai-Hulud September 2025)(Citation: Microsoft Shai-Hulud December 2025)(Citation: Socket Shai-Hulud November 2025)(Citation: Socket Shai-Hulud Trufflehog September 2025)","relationship_id":"relationship--472255be-4ec3-41ad-b66d-3cede330abbc","references":[{"source_name":"Aikido Shai-Hulud September 2025","description":"Charlie Eriksen. (2025, September 16). S1ngularity/nx attackers strike again. Retrieved April 9, 2026.","url":"https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again"},{"source_name":"Netskope Shai-Hulud November 2025","description":"Gianpietro Cutolo. (2025, November 26). Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading. Retrieved April 9, 2026.","url":"https://www.netskope.com/blog/shai-hulud-2-0-aggressive-automated-one-of-fastest-spreading-npm-supply-chain-attacks-ever-observed"},{"source_name":"Wiz Shai-Hulud September 2025","description":"Merav Bar, Rami McCarthy, Barak Sharoni. (2025, September 16). Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware. Retrieved April 9, 2026.","url":"https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack"},{"source_name":"Microsoft Shai-Hulud December 2025","description":"Microsoft Defender Security Team. (n.d.). Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack. Retrieved April 9, 2026.","url":"https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/"},{"source_name":"Socket Shai-Hulud November 2025","description":"Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.","url":"https://socket.dev/blog/shai-hulud-strikes-again-v2"},{"source_name":"Socket Shai-Hulud Trufflehog September 2025","description":"Socket Research Team. (2025, September 15). Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages. Retrieved April 9, 2026.","url":"https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages"}]},{"id":"S9010","name":"GlassWorm","url":"https://attack.mitre.org/software/S9010","kind":"malware","description":"[GlassWorm](https://attack.mitre.org/software/S9010) has downloaded additional payloads from C2.(Citation: Koi Glassworm New Tricks December 2025)(Citation: Koi Glassworm Extensions November 2025)(Citation: Socket GlassWorm January 2026)(Citation: Koi GlassWorm Rust December 2025)","relationship_id":"relationship--d8613097-6ef1-4b84-8641-0951cab8376f","references":[{"source_name":"Koi Glassworm New Tricks December 2025","description":"Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.","url":"https://www.koi.ai/blog/glassworm-goes-mac-fresh-infrastructure-new-tricks"},{"source_name":"Koi Glassworm Extensions November 2025","description":"Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026.","url":"https://www.koi.ai/blog/glassworm-returns-new-wave-openvsx-malware-expose-attacker-infrastructure"},{"source_name":"Socket GlassWorm January 2026","description":"Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.","url":"https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise"},{"source_name":"Koi GlassWorm Rust December 2025","description":"Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.","url":"https://www.koi.ai/blog/glassworm-goes-native-same-infrastructure-hardened-delivery"}]},{"id":"S9014","name":"PHASEJAM","url":"https://attack.mitre.org/software/S9014","kind":"malware","description":"[PHASEJAM](https://attack.mitre.org/software/S9014) has the ability to upload files onto the compromised appliance.(Citation: Google UNC5221 Ivanti January 2025)","relationship_id":"relationship--761a260b-5392-43a9-94fe-249ad77b75db","references":[{"source_name":"Google UNC5221 Ivanti January 2025","description":"John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.","url":"https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day"}]},{"id":"S9015","name":"BRICKSTORM","url":"https://attack.mitre.org/software/S9015","kind":"malware","description":"[BRICKSTORM](https://attack.mitre.org/software/S9015) has the ability to download files from the Adversaries C2 server to the compromised system.(Citation: CISA BRICKSTORM UNC5221 AR25-338A February 2026)(Citation: Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024)(Citation: NVISO BRICKSTORM April 2025)(Citation: Google BRICKSTORM September 2025)","relationship_id":"relationship--c4973466-b155-40e6-8eff-1888cd50b61c","references":[{"source_name":"CISA BRICKSTORM UNC5221 AR25-338A February 2026","description":"DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.","url":"https://www.cisa.gov/news-events/analysis-reports/ar25-338a"},{"source_name":"Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024","description":"Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.","url":"https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement"},{"source_name":"NVISO BRICKSTORM April 2025","description":"NVISO Incident Response. (2025, April 1). BRICKSTORM  Backdoor Analysis: A Persistent Espionage Threat  to European Industries. Retrieved April 16, 2026.","url":"https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf"},{"source_name":"Google BRICKSTORM September 2025","description":"Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.","url":"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign"}]},{"id":"S9016","name":"Caminho","url":"https://attack.mitre.org/software/S9016","kind":"malware","description":"[Caminho](https://attack.mitre.org/software/S9016) has the ability to download files onto compromised hosts.(Citation: Zscaler BlindEagle DEC 2025)","relationship_id":"relationship--ae3003a7-3d6d-4dbc-8da9-65c947243cd5","references":[{"source_name":"Zscaler BlindEagle DEC 2025","description":"Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.","url":"https://www.zscaler.com/blogs/security-research/blindeagle-targets-colombian-government-agency-caminho-and-dcrat"}]},{"id":"S9019","name":"PureCrypter","url":"https://attack.mitre.org/software/S9019","kind":"malware","description":"[PureCrypter](https://attack.mitre.org/software/S9019) can download additional payloads for execution on the compromised host.(Citation: Zscaler PureCrypter JUN 2022)(Citation: Check Point Blind Eagle MAR 2025)","relationship_id":"relationship--aa736843-16e9-4872-827a-41d24782cdb7","references":[{"source_name":"Check Point Blind Eagle MAR 2025","description":"Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.","url":"https://research.checkpoint.com/2025/blind-eagle-and-justice-for-all/"},{"source_name":"Zscaler PureCrypter JUN 2022","description":"Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.","url":"https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter"}]},{"id":"S9020","name":"LODEINFO","url":"https://attack.mitre.org/software/S9020","kind":"malware","description":"[LODEINFO](https://attack.mitre.org/software/S9020) has the ability to download additional files from the C2.(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: ITOCHU LODEINFO JAN 2024)","relationship_id":"relationship--392dbbcb-92e8-4ccc-8b1d-73c8577fc487","references":[{"source_name":"ESET MirrorFace DEC 2022","description":"Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.","url":"https://www.welivesecurity.com/2022/12/14/unmasking-mirrorface-operation-liberalface-targeting-japanese-political-entities/"},{"source_name":"Kaspersky LODEINFO Part II OCT 2022","description":"Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.","url":"https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-ii/107745/"},{"source_name":"ITOCHU LODEINFO JAN 2024","description":"ITOCHU. (2024, January 24). The Endless Struggle Against APT10: Insights from LODEINFO v0.6.6 - v0.7.3 Analysis. Retrieved April 17, 2026.","url":"https://blog-en.itochuci.co.jp/entry/2024/01/24/134100"}]},{"id":"S9021","name":"DOWNIISSA","url":"https://attack.mitre.org/software/S9021","kind":"malware","description":"[DOWNIISSA](https://attack.mitre.org/software/S9021) can download files to the compromised host.(Citation: Kaspersky LODEINFO OCT 2022)","relationship_id":"relationship--526929a7-d746-477b-a34b-fe41e2e2e16a","references":[{"source_name":"Kaspersky LODEINFO OCT 2022","description":"Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.","url":"https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/"}]},{"id":"S9023","name":"HiddenFace","url":"https://attack.mitre.org/software/S9023","kind":"malware","description":"[HiddenFace](https://attack.mitre.org/software/S9023) can download files from the C2 to victim systems.(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: JPCERT MirrorFace JUL 2024)","relationship_id":"relationship--630c1788-f3b9-40f2-acf9-95ae8c12d322","references":[{"source_name":"JPCERT MirrorFace JUL 2024","description":"Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.","url":"https://blogs.jpcert.or.jp/en/2024/07/mirrorface-attack-against-japanese-organisations.html"},{"source_name":"Trend Micro Earth Kasha NOV 2024","description":"Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.","url":"https://www.trendmicro.com/en_us/research/24/k/lodeinfo-campaign-of-earth-kasha.html"}]},{"id":"S9028","name":"PHPsert","url":"https://attack.mitre.org/software/S9028","kind":"malware","description":"[PHPsert](https://attack.mitre.org/software/S9028) has the ability to retrieve remote payloads.(Citation: sentinelone operationDigitalEye Dec 2024)","relationship_id":"relationship--631156f6-a414-4856-81b0-e4bd727e77ba","references":[{"source_name":"sentinelone operationDigitalEye Dec 2024","description":"Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.","url":"https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/"}]},{"id":"S9031","name":"AshTag","url":"https://attack.mitre.org/software/S9031","kind":"malware","description":"The [AshTag](https://attack.mitre.org/software/S9031) stager component can retrieve and execute the main payload.(Citation: Palo Alto Ashen Lepus DEC 2025)","relationship_id":"relationship--b2cbfcbd-5200-41ef-9338-ac9b0b0eb9df","references":[{"source_name":"Palo Alto Ashen Lepus DEC 2025","description":"Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.","url":"https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/"}]},{"id":"S9032","name":"MuddyViper","url":"https://attack.mitre.org/software/S9032","kind":"malware","description":"[MuddyViper](https://attack.mitre.org/software/S9032) has the ability to download files from the C2 server. Additionally, [MuddyViper](https://attack.mitre.org/software/S9032) has the ability to download a file in chunks with sleep time between each chunk.(Citation: ESET_MuddyWater_Dec2025)     ","relationship_id":"relationship--25725116-788a-429a-b026-a6345bbd7f25","references":[{"source_name":"ESET_MuddyWater_Dec2025","description":"ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.","url":"https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/"}]},{"id":"S9034","name":"Tsundere Botnet","url":"https://attack.mitre.org/software/S9034","kind":"malware","description":"[Tsundere Botnet](https://attack.mitre.org/software/S9034)’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.(Citation: SecureListUbiedo_Tsundere_Nov2025)","relationship_id":"relationship--54a96733-eb51-43ba-a080-3b4adbcbc915","references":[{"source_name":"SecureListUbiedo_Tsundere_Nov2025","description":"Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.","url":"https://securelist.com/tsundere-node-js-botnet-uses-ethereum-blockchain/117979/"}]},{"id":"S9041","name":"TeamPCP Cloud Stealer","url":"https://attack.mitre.org/software/S9041","kind":"malware","description":"[TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) has the ability to download additional payloads to targeted systems.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)","relationship_id":"relationship--28bdfde8-ff79-44b9-a515-88d230f23aae","references":[{"source_name":"Aqua Security Blog Trivy Compromise APR 2026","description":"Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.","url":"https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know"},{"source_name":"Wiz Trivy Compromise MAR 2026","description":"McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.","url":"https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack"},{"source_name":"Wiz TeamPCP KICS MAR 2026","description":"McCarthy, R., Haughom, J., Read, B. (2026, March 23). KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack. Retrieved July 1, 2026.","url":"https://www.wiz.io/blog/teampcp-attack-kics-github-action"},{"source_name":"Palo Alto TeamPCP MAR 2026","description":"Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.","url":"https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/"}]},{"id":"S9042","name":"CanisterWorm","url":"https://attack.mitre.org/software/S9042","kind":"malware","description":"[CanisterWorm](https://attack.mitre.org/software/S9042) has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes.(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026) [CanisterWorm](https://attack.mitre.org/software/S9042) has also downloaded kubectl to compromised environments if it was not already installed.(Citation: Aikido CanisterWorm MAR 2026)","relationship_id":"relationship--3a4f7d04-6c45-4a96-9ce7-bd951d350a1f","references":[{"source_name":"Aikido TeamPCP Trivy MAR 2026","description":"Eriksen, C. (2026, March 20). TeamPCP deploys CanisterWorm on NPM following Trivy compromise. Retrieved July 27, 2026.","url":"https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise"},{"source_name":"Aikido CanisterWorm MAR 2026","description":"Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026.","url":"https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran"}]},{"id":"S9043","name":"Mini Shai-Hulud","url":"https://attack.mitre.org/software/S9043","kind":"malware","description":"[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) has the ability to download additional payloads from adversary controlled or compromised infrastructure.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)","relationship_id":"relationship--83874b9c-91ee-400d-bc46-529ad159e083","references":[{"source_name":"Hunt.io TeamPCP Toolkit MAY 2026","description":"Hunt.io. (2026, May 14). How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account. Retrieved July 16, 2026.","url":"https://hunt.io/blog/teampcp-python-toolkit-firescale-github-c2-takedown"},{"source_name":"Wiz Mini Shai-Hulud MAY 2026","description":"McCarthy, R., Cohen, A., and Read, B. (2026, May 12). Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised. Retrieved July 16, 2026.","url":"https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised"},{"source_name":"Phoenix TeamPCP 20 MAY 2026","description":"Webb, M. (2026, May 20). TeamPCP Wave Four: GitHub Breach via Poisoned VS Code Extension, durabletask PyPI Worm, and ~4,000 Internal Repositories Exfiltrated. Retrieved July 16, 2026.","url":"https://phoenix.security/teampcp-github-breach-durabletask-pypi-supply-chain-wave-four-2026/"}]}],"actors":[{"id":"G0004","name":"Ke3chang","url":"https://attack.mitre.org/groups/G0004","kind":"intrusion-set","description":"[Ke3chang](https://attack.mitre.org/groups/G0004) has used tools to download files to compromised machines.(Citation: Microsoft NICKEL December 2021)","relationship_id":"relationship--1525d82a-05a7-4027-9d2d-02f8039d68b5","references":[{"source_name":"Microsoft NICKEL December 2021","description":"MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.","url":"https://www.microsoft.com/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe"}]},{"id":"G0007","name":"APT28","url":"https://attack.mitre.org/groups/G0007","kind":"intrusion-set","description":"[APT28](https://attack.mitre.org/groups/G0007) has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.(Citation: Bitdefender APT28 Dec 2015)(Citation: Unit 42 Playbook Dec 2017)(Citation: Accenture SNAKEMACKEREL Nov 2018)(Citation: TrendMicro Pawn Storm Dec 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021)","relationship_id":"relationship--644b6c21-90f0-43b7-8da4-7f6f24ddabb6","references":[{"source_name":"Accenture SNAKEMACKEREL Nov 2018","description":"Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.","url":"https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf#zoom=50"},{"source_name":"Bitdefender APT28 Dec 2015","description":"Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.","url":"https://download.bitdefender.com/resources/media/materials/white-papers/en/Bitdefender_In-depth_analysis_of_APT28%E2%80%93The_Political_Cyber-Espionage.pdf"},{"source_name":"TrendMicro Pawn Storm Dec 2020","description":"Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.","url":"https://www.trendmicro.com/en_us/research/20/l/pawn-storm-lack-of-sophistication-as-a-strategy.html"},{"source_name":"Cybersecurity Advisory GRU Brute Force Campaign July 2021","description":"NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.","url":"https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF"},{"source_name":"Unit 42 Playbook Dec 2017","description":"Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.","url":"https://web.archive.org/web/20230702043312/https://pan-unit42.github.io/playbook_viewer/"}]},{"id":"G0010","name":"Turla","url":"https://attack.mitre.org/groups/G0010","kind":"intrusion-set","description":"[Turla](https://attack.mitre.org/groups/G0010) has used shellcode to download Meterpreter after compromising a victim.(Citation: ESET Turla Mosquito May 2018)","relationship_id":"relationship--20b90b04-4ce1-4e9a-9dbb-9fc93569d3e1","references":[{"source_name":"ESET Turla Mosquito May 2018","description":"ESET Research. (2018, May 22). Turla Mosquito: A shift towards more generic tools. Retrieved July 3, 2018.","url":"https://www.welivesecurity.com/2018/05/22/turla-mosquito-shift-towards-generic-tools/"}]},{"id":"G0012","name":"Darkhotel","url":"https://attack.mitre.org/groups/G0012","kind":"intrusion-set","description":"[Darkhotel](https://attack.mitre.org/groups/G0012) has used first-stage payloads that download additional malware from C2 servers.(Citation: Microsoft DUBNIUM June 2016)","relationship_id":"relationship--cdfe5f64-0a34-483c-b921-feaf18357354","references":[{"source_name":"Microsoft DUBNIUM June 2016","description":"Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.","url":"https://www.microsoft.com/security/blog/2016/06/09/reverse-engineering-dubnium-2/"}]},{"id":"G0016","name":"APT29","url":"https://attack.mitre.org/groups/G0016","kind":"intrusion-set","description":"[APT29](https://attack.mitre.org/groups/G0016) has downloaded additional tools and malware onto compromised networks.(Citation: Mandiant No Easy Breach)(Citation: PWC WellMess July 2020)(Citation: F-Secure The Dukes)(Citation: Mandiant APT29 Eye Spy Email Nov 22)","relationship_id":"relationship--3c89c7b8-facc-4225-94ba-4a5126a31adc","references":[{"source_name":"Mandiant No Easy Breach","description":"Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved September 12, 2024.","url":"https://www.slideshare.net/slideshow/no-easy-breach-derby-con-2016/66447908"},{"source_name":"F-Secure The Dukes","description":"F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.","url":"https://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf"},{"source_name":"Mandiant APT29 Eye Spy Email Nov 22","description":"Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.","url":"https://www.mandiant.com/resources/blog/unc3524-eye-spy-email"},{"source_name":"PWC WellMess July 2020","description":"PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.","url":"https://www.pwc.co.uk/issues/cyber-security-services/insights/cleaning-up-after-wellmess.html"}]},{"id":"G0021","name":"Molerats","url":"https://attack.mitre.org/groups/G0021","kind":"intrusion-set","description":"[Molerats](https://attack.mitre.org/groups/G0021) used executables to download malicious files from different sources.(Citation: Kaspersky MoleRATs April 2019)(Citation: Unit42 Molerat Mar 2020) ","relationship_id":"relationship--2fd0b80f-d053-4679-a350-1bb45b32ab49","references":[{"source_name":"Kaspersky MoleRATs April 2019","description":"GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.","url":"https://securelist.com/gaza-cybergang-group1-operation-sneakypastes/90068/"},{"source_name":"Unit42 Molerat Mar 2020","description":"Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.","url":"https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/"}]},{"id":"G0022","name":"APT3","url":"https://attack.mitre.org/groups/G0022","kind":"intrusion-set","description":"[APT3](https://attack.mitre.org/groups/G0022) has a tool that can copy files to remote machines.(Citation: FireEye Clandestine Fox)","relationship_id":"relationship--f661bda3-d524-44b3-aeb0-d8dd8879a569","references":[{"source_name":"FireEye Clandestine Fox","description":"Chen, X., Scott, M., Caselden, D.. (2014, April 26). New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks. Retrieved January 14, 2016.","url":"https://www.fireeye.com/blog/threat-research/2014/04/new-zero-day-exploit-targeting-internet-explorer-versions-9-through-11-identified-in-targeted-attacks.html"}]},{"id":"G0026","name":"APT18","url":"https://attack.mitre.org/groups/G0026","kind":"intrusion-set","description":"[APT18](https://attack.mitre.org/groups/G0026) can upload a file to the victim’s machine.(Citation: PaloAlto DNS Requests May 2016)","relationship_id":"relationship--882c68e3-5f01-4438-a430-ff22692d8910","references":[{"source_name":"PaloAlto DNS Requests May 2016","description":"Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.","url":"https://researchcenter.paloaltonetworks.com/2016/05/unit42-new-wekby-attacks-use-dns-requests-as-command-and-control-mechanism/"}]},{"id":"G0027","name":"Threat Group-3390","url":"https://attack.mitre.org/groups/G0027","kind":"intrusion-set","description":"[Threat Group-3390](https://attack.mitre.org/groups/G0027) has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .(Citation: Dell TG-3390)(Citation: Trend Micro DRBControl February 2020)","relationship_id":"relationship--6a1693a7-1e85-48b6-9097-11339a987099","references":[{"source_name":"Dell TG-3390","description":"Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.","url":"https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-cyberespionage"},{"source_name":"Trend Micro DRBControl February 2020","description":"Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.","url":"https://documents.trendmicro.com/assets/white_papers/wp-uncovering-DRBcontrol.pdf"}]},{"id":"G0032","name":"Lazarus Group","url":"https://attack.mitre.org/groups/G0032","kind":"intrusion-set","description":"[Lazarus Group](https://attack.mitre.org/groups/G0032) has downloaded files, malware, and tools from its C2 onto a compromised host.(Citation: Novetta Blockbuster)(Citation: Novetta Blockbuster Destructive Malware)(Citation: Novetta Blockbuster Loaders)(Citation: SentinelOne Lazarus macOS July 2020)(Citation: TrendMicro macOS Dacls May 2020)(Citation: Kaspersky ThreatNeedle Feb 2021)(Citation: Google TAG Lazarus Jan 2021)(Citation: Lazarus APT January 2022)(Citation: Qualys LolZarus)(Citation: ESET Twitter Ida Pro Nov 2021)","relationship_id":"relationship--115562b8-9d7c-435e-af6e-0be6249742d0","references":[{"source_name":"ESET Twitter Ida Pro Nov 2021","description":"Cherepanov, Anton. (2019, November 10). ESETresearch discovered a trojanized IDA Pro installer. Retrieved September 12, 2024.","url":"https://x.com/ESETresearch/status/1458438155149922312"},{"source_name":"TrendMicro macOS Dacls May 2020","description":"Mabutas, G. (2020, May 11). New MacOS Dacls RAT Backdoor Shows Lazarus’ Multi-Platform Attack Capability. Retrieved August 10, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/new-macos-dacls-rat-backdoor-show-lazarus-multi-platform-attack-capability/"},{"source_name":"Novetta Blockbuster Destructive Malware","description":"Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20160303200515/https:/operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf"},{"source_name":"Novetta Blockbuster Loaders","description":"Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20190508165631/https://operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Loaders-Installers-and-Uninstallers-Report.pdf"},{"source_name":"Novetta Blockbuster","description":"Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.","url":"https://web.archive.org/web/20160226161828/https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf"},{"source_name":"Qualys LolZarus","description":"Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022.","url":"https://blog.qualys.com/vulnerabilities-threat-research/2022/02/08/lolzarus-lazarus-group-incorporating-lolbins-into-campaigns"},{"source_name":"Lazarus APT January 2022","description":"Saini, A. and Hossein, J. (2022, January 27). North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign. Retrieved January 27, 2022.","url":"https://blog.malwarebytes.com/threat-intelligence/2022/01/north-koreas-lazarus-apt-leverages-windows-update-client-github-in-latest-campaign/"},{"source_name":"SentinelOne Lazarus macOS July 2020","description":"Stokes, P. (2020, July 27). Four Distinct Families of Lazarus Malware Target Apple’s macOS Platform. Retrieved August 7, 2020.","url":"https://www.sentinelone.com/blog/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/"},{"source_name":"Kaspersky ThreatNeedle Feb 2021","description":"Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.","url":"https://securelist.com/lazarus-threatneedle/100803/"},{"source_name":"Google TAG Lazarus Jan 2021","description":"Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.","url":"https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/"}]},{"id":"G0034","name":"Sandworm Team","url":"https://attack.mitre.org/groups/G0034","kind":"intrusion-set","description":"[Sandworm Team](https://attack.mitre.org/groups/G0034) has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.(Citation: ESET Telebots Dec 2016)(Citation: US District Court Indictment GRU Unit 74455 October 2020)","relationship_id":"relationship--ea80c942-680d-43b4-9cbf-21f2078977ad","references":[{"source_name":"ESET Telebots Dec 2016","description":"Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.","url":"https://www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/"},{"source_name":"US District Court Indictment GRU Unit 74455 October 2020","description":"Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.","url":"https://www.justice.gov/opa/press-release/file/1328521/download"}]},{"id":"G0035","name":"Dragonfly","url":"https://attack.mitre.org/groups/G0035","kind":"intrusion-set","description":"[Dragonfly](https://attack.mitre.org/groups/G0035) has copied and installed tools for operations once in the victim environment.(Citation: US-CERT TA18-074A)","relationship_id":"relationship--cb54c094-5614-4d45-ab13-c00ab2cdb114","references":[{"source_name":"US-CERT TA18-074A","description":"US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.","url":"https://www.us-cert.gov/ncas/alerts/TA18-074A"}]},{"id":"G0040","name":"Patchwork","url":"https://attack.mitre.org/groups/G0040","kind":"intrusion-set","description":"[Patchwork](https://attack.mitre.org/groups/G0040) payloads download additional files from the C2 server.(Citation: Securelist Dropping Elephant)(Citation: TrendMicro Patchwork Dec 2017)","relationship_id":"relationship--da734f6c-de0d-44f1-9521-6607b800ad43","references":[{"source_name":"Securelist Dropping Elephant","description":"Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016.","url":"https://securelist.com/the-dropping-elephant-actor/75328/"},{"source_name":"TrendMicro Patchwork Dec 2017","description":"Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.","url":"https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-cyberespionage-group.pdf"}]},{"id":"G0044","name":"Winnti Group","url":"https://attack.mitre.org/groups/G0044","kind":"intrusion-set","description":"[Winnti Group](https://attack.mitre.org/groups/G0044) has downloaded an auxiliary program named ff.exe to infected machines.(Citation: Kaspersky Winnti April 2013)","relationship_id":"relationship--c21009bb-5a7b-438d-9aed-1ec85cbd0d75","references":[{"source_name":"Kaspersky Winnti April 2013","description":"Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.","url":"https://securelist.com/winnti-more-than-just-a-game/37029/"}]},{"id":"G0045","name":"menuPass","url":"https://attack.mitre.org/groups/G0045","kind":"intrusion-set","description":"[menuPass](https://attack.mitre.org/groups/G0045) has installed updates and new malware on victims.(Citation: PWC Cloud Hopper April 2017)(Citation: District Court of NY APT10 Indictment December 2018)","relationship_id":"relationship--2cc93cb7-fbe6-4c79-b619-a2eb877de1cf","references":[{"source_name":"PWC Cloud Hopper April 2017","description":"PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.","url":"https://web.archive.org/web/20220224041316/https:/www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report-final-v4.pdf"},{"source_name":"District Court of NY APT10 Indictment December 2018","description":"US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.","url":"https://www.justice.gov/opa/page/file/1122671/download"}]},{"id":"G0046","name":"FIN7","url":"https://attack.mitre.org/groups/G0046","kind":"intrusion-set","description":"[FIN7](https://attack.mitre.org/groups/G0046) has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.(Citation: FireEye FIN7 April 2017)(Citation: DOJ FIN7 Aug 2018)(Citation: Mandiant FIN7 Apr 2022)(Citation: Gemini_FIN7_Jan2022)","relationship_id":"relationship--b077d81d-0449-493f-9b93-23dc0fb0b62d","references":[{"source_name":"Mandiant FIN7 Apr 2022","description":"Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.","url":"https://www.mandiant.com/resources/evolution-of-fin7"},{"source_name":"FireEye FIN7 April 2017","description":"Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.","url":"https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html"},{"source_name":"DOJ FIN7 Aug 2018","description":"Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.","url":"https://www.justice.gov/opa/press-release/file/1084361/download"},{"source_name":"Gemini_FIN7_Jan2022","description":"Gemini Advisory. (2022, January 13). FIN7 Uses Flash Drives to Spread Remote Access Trojan. Retrieved May 14, 2025.","url":"https://geminiadvisory.io/fin7-flash-drives-spread-remote-access-trojan/"}]},{"id":"G0047","name":"Gamaredon Group","url":"https://attack.mitre.org/groups/G0047","kind":"intrusion-set","description":"[Gamaredon Group](https://attack.mitre.org/groups/G0047) has downloaded additional malware and tools onto a compromised host.(Citation: Palo Alto Gamaredon Feb 2017)(Citation: TrendMicro Gamaredon April 2020)(Citation: ESET Gamaredon June 2020)(Citation: Microsoft Actinium February 2022)(Citation: ESET Gamaredon Sept2024)(Citation: VenereCiscoTalos_Gamaredon_Mar2025) For example, [Gamaredon Group](https://attack.mitre.org/groups/G0047) uses a backdoor script to retrieve and decode additional payloads once in victim environments.(Citation: unit42_gamaredon_dec2022) ","relationship_id":"relationship--253b56a5-232f-44bc-af4d-85ccc12a0577","references":[{"source_name":"ESET Gamaredon June 2020","description":"Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.","url":"https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/"},{"source_name":"TrendMicro Gamaredon April 2020","description":"Kakara, H., Maruyama, E. (2020, April 17). Gamaredon APT Group Use Covid-19 Lure in Campaigns. Retrieved May 19, 2020.","url":"https://blog.trendmicro.com/trendlabs-security-intelligence/gamaredon-apt-group-use-covid-19-lure-in-campaigns/"},{"source_name":"Palo Alto Gamaredon Feb 2017","description":"Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.","url":"https://researchcenter.paloaltonetworks.com/2017/02/unit-42-title-gamaredon-group-toolset-evolution/"},{"source_name":"Microsoft Actinium February 2022","description":"Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.","url":"https://www.microsoft.com/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/"},{"source_name":"ESET Gamaredon Sept2024","description":"Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.","url":"https://web-assets.esetstatic.com/wls/en/papers/white-papers/cyberespionage-gamaredon-way.pdf"},{"source_name":"unit42_gamaredon_dec2022","description":"Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.","url":"https://unit42.paloaltonetworks.com/trident-ursa/"},{"source_name":"VenereCiscoTalos_Gamaredon_Mar2025","description":"Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.","url":"https://blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/"}]},{"id":"G0049","name":"OilRig","url":"https://attack.mitre.org/groups/G0049","kind":"intrusion-set","description":"[OilRig](https://attack.mitre.org/groups/G0049) had downloaded remote files onto victim infrastructure.(Citation: FireEye APT34 Dec 2017)(Citation: Trend Micro Earth Simnavaz October 2024)","relationship_id":"relationship--8e9f95f0-4939-4e74-9073-70efddddff50","references":[{"source_name":"Trend Micro Earth Simnavaz October 2024","description":"Fahmy, M. et al. (2024, October 11). Earth Simnavaz (aka APT34) Levies Advanced Cyberattacks Against Middle East. Retrieved November 27, 2024.","url":"https://www.trendmicro.com/en_us/research/24/j/earth-simnavaz-cyberattacks.html"},{"source_name":"FireEye APT34 Dec 2017","description":"Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.","url":"https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html"}]},{"id":"G0050","name":"APT32","url":"https://attack.mitre.org/groups/G0050","kind":"intrusion-set","description":"[APT32](https://attack.mitre.org/groups/G0050) has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.(Citation: Volexity OceanLotus Nov 2017)","relationship_id":"relationship--93f1726f-f172-4705-a13a-d5adaeb4e91b","references":[{"source_name":"Volexity OceanLotus Nov 2017","description":"Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017.","url":"https://www.volexity.com/blog/2017/11/06/oceanlotus-blossoms-mass-digital-surveillance-and-exploitation-of-asean-nations-the-media-human-rights-and-civil-society/"}]},{"id":"G0059","name":"Magic Hound","url":"https://attack.mitre.org/groups/G0059","kind":"intrusion-set","description":"[Magic Hound](https://attack.mitre.org/groups/G0059) has downloaded additional code and files from servers onto victims.(Citation: Unit 42 Magic Hound Feb 2017)(Citation: DFIR Report APT35 ProxyShell March 2022)(Citation: DFIR Phosphorus November 2021)(Citation: Microsoft Iranian Threat Actor Trends November 2021)","relationship_id":"relationship--47f521b8-37e4-489d-b6eb-25f35de80aae","references":[{"source_name":"DFIR Phosphorus November 2021","description":"DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.","url":"https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/"},{"source_name":"DFIR Report APT35 ProxyShell March 2022","description":"DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.","url":"https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell"},{"source_name":"Unit 42 Magic Hound Feb 2017","description":"Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.","url":"https://researchcenter.paloaltonetworks.com/2017/02/unit42-magic-hound-campaign-attacks-saudi-targets/"},{"source_name":"Microsoft Iranian Threat Actor Trends November 2021","description":"MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.","url":"https://www.microsoft.com/en-us/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actor-activity-mstic-presentation-at-cyberwarcon-2021"}]},{"id":"G0060","name":"BRONZE BUTLER","url":"https://attack.mitre.org/groups/G0060","kind":"intrusion-set","description":"[BRONZE BUTLER](https://attack.mitre.org/groups/G0060) has used various tools to download files, including DGet (a similar tool to wget).(Citation: Secureworks BRONZE BUTLER Oct 2017)","relationship_id":"relationship--d7c5e4f4-cede-4a81-b46f-035b9e702e61","references":[{"source_name":"Secureworks BRONZE BUTLER Oct 2017","description":"Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.","url":"https://www.secureworks.com/research/bronze-butler-targets-japanese-businesses"}]},{"id":"G0061","name":"FIN8","url":"https://attack.mitre.org/groups/G0061","kind":"intrusion-set","description":"[FIN8](https://attack.mitre.org/groups/G0061) has used remote code execution to download subsequent payloads.(Citation: FireEye Fin8 May 2016)(Citation: Bitdefender FIN8 July 2021)","relationship_id":"relationship--c3dd754d-3e2b-4761-8d21-2e7a52fc6616","references":[{"source_name":"FireEye Fin8 May 2016","description":"Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.","url":"https://www.fireeye.com/blog/threat-research/2016/05/windows-zero-day-payment-cards.html"},{"source_name":"Bitdefender FIN8 July 2021","description":"Martin Zugec. (2021, July 27). Deep Dive Into a FIN8 Attack - A Forensic Investigation. Retrieved September 1, 2021.","url":"https://businessinsights.bitdefender.com/deep-dive-into-a-fin8-attack-a-forensic-investigation"}]},{"id":"G0064","name":"APT33","url":"https://attack.mitre.org/groups/G0064","kind":"intrusion-set","description":"[APT33](https://attack.mitre.org/groups/G0064) has downloaded additional files and programs from its C2 server.(Citation: Symantec Elfin Mar 2019)(Citation: Microsoft Holmium June 2020)\t\n","relationship_id":"relationship--a06ada98-605a-47c5-9362-41e86c2ada6e","references":[{"source_name":"Symantec Elfin Mar 2019","description":"Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.","url":"https://www.symantec.com/blogs/threat-intelligence/elfin-apt33-espionage"},{"source_name":"Microsoft Holmium June 2020","description":"Microsoft Threat Protection Intelligence Team. (2020, June 18). Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint. Retrieved June 22, 2020.","url":"https://www.microsoft.com/security/blog/2020/06/18/inside-microsoft-threat-protection-mapping-attack-chains-from-cloud-to-endpoint/"}]},{"id":"G0065","name":"Leviathan","url":"https://attack.mitre.org/groups/G0065","kind":"intrusion-set","description":"[Leviathan](https://attack.mitre.org/groups/G0065) has downloaded additional scripts and files from adversary-controlled servers.(Citation: Proofpoint Leviathan Oct 2017)(Citation: FireEye Periscope March 2018)","relationship_id":"relationship--273ad96c-269f-4736-a3de-646713c15b50","references":[{"source_name":"Proofpoint Leviathan Oct 2017","description":"Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.","url":"https://www.proofpoint.com/us/threat-insight/post/leviathan-espionage-actor-spearphishes-maritime-and-defense-targets"},{"source_name":"FireEye Periscope March 2018","description":"FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.","url":"https://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese-espionage-group-targeting-maritime-and-engineering-industries.html"}]},{"id":"G0066","name":"Elderwood","url":"https://attack.mitre.org/groups/G0066","kind":"intrusion-set","description":"The Ritsol backdoor trojan used by [Elderwood](https://attack.mitre.org/groups/G0066) can download files onto a compromised host from a remote location.(Citation: Symantec Ristol May 2012)","relationship_id":"relationship--f0ef3f47-5651-4638-a007-cb585d3174b0","references":[{"source_name":"Symantec Ristol May 2012","description":"Ladley, F. (2012, May 15). Backdoor.Ritsol. Retrieved February 23, 2018.","url":"https://www.symantec.com/security_response/writeup.jsp?docid=2012-051515-3909-99"}]},{"id":"G0067","name":"APT37","url":"https://attack.mitre.org/groups/G0067","kind":"intrusion-set","description":"[APT37](https://attack.mitre.org/groups/G0067) has downloaded second stage malware from compromised websites.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft May 2019)(Citation: Volexity InkySquid BLUELIGHT August 2021)(Citation: Volexity InkySquid RokRAT August 2021)","relationship_id":"relationship--197a0e84-5361-49cc-8e14-24c331665862","references":[{"source_name":"Volexity InkySquid RokRAT August 2021","description":"Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.","url":"https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-inkysquid-deploys-rokrat/"},{"source_name":"Volexity InkySquid BLUELIGHT August 2021","description":"Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.","url":"https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/"},{"source_name":"FireEye APT37 Feb 2018","description":"FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt37-reaper-the-overlooked-north-korean-actor.pdf"},{"source_name":"Securelist ScarCruft May 2019","description":"GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019.","url":"https://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/"}]},{"id":"G0068","name":"PLATINUM","url":"https://attack.mitre.org/groups/G0068","kind":"intrusion-set","description":"[PLATINUM](https://attack.mitre.org/groups/G0068) has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel.(Citation: Microsoft PLATINUM June 2017)","relationship_id":"relationship--1255a34c-e280-4b16-b606-7b03682cd76d","references":[{"source_name":"Microsoft PLATINUM June 2017","description":"Kaplan, D, et al. (2017, June 7). PLATINUM continues to evolve, find ways to maintain invisibility. Retrieved February 19, 2018.","url":"https://cloudblogs.microsoft.com/microsoftsecure/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/?source=mmpc"}]},{"id":"G0069","name":"MuddyWater","url":"https://attack.mitre.org/groups/G0069","kind":"intrusion-set","description":"[MuddyWater](https://attack.mitre.org/groups/G0069) has used malware that can upload additional files to the victim’s machine.(Citation: Securelist MuddyWater Oct 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: Reaqta MuddyWater November 2017)(Citation: Trend Micro Muddy Water March 2021) [MuddyWater](https://attack.mitre.org/groups/G0069) has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.(Citation: NaumaanProofpoint_GlobalClickFix_April2025) ","relationship_id":"relationship--82d8c106-c216-4d3f-9028-5f0b975e6330","references":[{"source_name":"ClearSky MuddyWater Nov 2018","description":"ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.","url":"https://www.clearskysec.com/wp-content/uploads/2018/11/MuddyWater-Operations-in-Lebanon-and-Oman.pdf"},{"source_name":"Securelist MuddyWater Oct 2018","description":"Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018.","url":"https://securelist.com/muddywater/88059/"},{"source_name":"NaumaanProofpoint_GlobalClickFix_April2025","description":"Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.","url":"https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix"},{"source_name":"Trend Micro Muddy Water March 2021","description":"Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.","url":"https://www.trendmicro.com/en_us/research/21/c/earth-vetala---muddywater-continues-to-target-organizations-in-t.html"},{"source_name":"Reaqta MuddyWater November 2017","description":"Reaqta. (2017, November 22). A dive into MuddyWater APT targeting Middle-East. Retrieved May 18, 2020.","url":"https://reaqta.com/2017/11/muddywater-apt-targeting-middle-east/"}]},{"id":"G0075","name":"Rancor","url":"https://attack.mitre.org/groups/G0075","kind":"intrusion-set","description":"[Rancor](https://attack.mitre.org/groups/G0075) has downloaded additional malware, including by using [certutil](https://attack.mitre.org/software/S0160).(Citation: Rancor Unit42 June 2018)","relationship_id":"relationship--74a15877-d310-4be1-813d-4ee9cbd603b7","references":[{"source_name":"Rancor Unit42 June 2018","description":"Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"id":"G0078","name":"Gorgon Group","url":"https://attack.mitre.org/groups/G0078","kind":"intrusion-set","description":"[Gorgon Group](https://attack.mitre.org/groups/G0078) malware can download additional files from C2 servers.(Citation: Unit 42 Gorgon Group Aug 2018)","relationship_id":"relationship--5f73d53f-f543-47b6-ab81-9a2764dabaef","references":[{"source_name":"Unit 42 Gorgon Group Aug 2018","description":"Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.","url":"https://researchcenter.paloaltonetworks.com/2018/08/unit42-gorgon-group-slithering-nation-state-cybercrime/"}]},{"id":"G0080","name":"Cobalt Group","url":"https://attack.mitre.org/groups/G0080","kind":"intrusion-set","description":"[Cobalt Group](https://attack.mitre.org/groups/G0080) has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers.(Citation: PTSecurity Cobalt Group Aug 2017)(Citation: PTSecurity Cobalt Dec 2016) The group's JavaScript backdoor is also capable of downloading files.(Citation: Morphisec Cobalt Gang Oct 2018)","relationship_id":"relationship--07ab4fde-e1fd-4740-863e-c40cc8722d32","references":[{"source_name":"PTSecurity Cobalt Group Aug 2017","description":"Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.","url":"https://www.ptsecurity.com/upload/corporate/ww-en/analytics/Cobalt-2017-eng.pdf"},{"source_name":"PTSecurity Cobalt Dec 2016","description":"Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.","url":"https://www.ptsecurity.com/upload/corporate/ww-en/analytics/Cobalt-Snatch-eng.pdf"},{"source_name":"Morphisec Cobalt Gang Oct 2018","description":"Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.","url":"https://blog.morphisec.com/cobalt-gang-2.0"}]},{"id":"G0081","name":"Tropic Trooper","url":"https://attack.mitre.org/groups/G0081","kind":"intrusion-set","description":"[Tropic Trooper](https://attack.mitre.org/groups/G0081) has used a delivered trojan to download additional files.(Citation: TrendMicro Tropic Trooper May 2020)","relationship_id":"relationship--0f47a6e7-af7e-4e23-a401-4dec08da4e64","references":[{"source_name":"TrendMicro Tropic Trooper May 2020","description":"Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.","url":"https://documents.trendmicro.com/assets/Tech-Brief-Tropic-Trooper-s-Back-USBferry-Attack-Targets-Air-gapped-Environments.pdf"}]},{"id":"G0082","name":"APT38","url":"https://attack.mitre.org/groups/G0082","kind":"intrusion-set","description":"[APT38](https://attack.mitre.org/groups/G0082) used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine.(Citation: FireEye APT38 Oct 2018) Additionally, [APT38](https://attack.mitre.org/groups/G0082) has downloaded other payloads onto a victim’s machine.(Citation: 1 - appv) ","relationship_id":"relationship--559dfd54-de33-4cfc-aeec-617cd545e870","references":[{"source_name":"FireEye APT38 Oct 2018","description":"FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.","url":"https://services.google.com/fh/files/misc/apt38-un-usual-suspects.pdf"},{"source_name":"1 - appv","description":"SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.","url":"https://securelist.com/bluenoroff-methods-bypass-motw/108383/"}]},{"id":"G0087","name":"APT39","url":"https://attack.mitre.org/groups/G0087","kind":"intrusion-set","description":"[APT39](https://attack.mitre.org/groups/G0087) has downloaded tools to compromised hosts.(Citation: Symantec Chafer February 2018)(Citation: FBI FLASH APT39 September 2020)","relationship_id":"relationship--60f1cf34-8c60-47b7-ba9a-88c2575006f9","references":[{"source_name":"Symantec Chafer February 2018","description":"Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.","url":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/chafer-latest-attacks-reveal-heightened-ambitions"},{"source_name":"FBI FLASH APT39 September 2020","description":"FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.","url":"https://www.iranwatch.org/sites/default/files/public-intelligence-alert.pdf"}]},{"id":"G0090","name":"WIRTE","url":"https://attack.mitre.org/groups/G0090","kind":"intrusion-set","description":"[WIRTE](https://attack.mitre.org/groups/G0090) has downloaded PowerShell code from the C2 server to be executed.(Citation: Lab52 WIRTE Apr 2019)","relationship_id":"relationship--cecf4306-a80e-4e65-b701-7e934adc6c42","references":[{"source_name":"Lab52 WIRTE Apr 2019","description":"S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.","url":"https://lab52.io/blog/wirte-group-attacking-the-middle-east/"}]},{"id":"G0091","name":"Silence","url":"https://attack.mitre.org/groups/G0091","kind":"intrusion-set","description":"[Silence](https://attack.mitre.org/groups/G0091) has downloaded additional modules and malware to victim’s machines.(Citation: Group IB Silence Sept 2018)\t","relationship_id":"relationship--948146db-f966-4e0c-bbb2-289e2eae6718","references":[{"source_name":"Group IB Silence Sept 2018","description":"Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.","url":"https://go.group-ib.com/report-silence-en?_gl=1*d1bh3a*_ga*MTIwMzM5Mzc5MS4xNjk4OTI5NzY4*_ga_QMES53K3Y2*MTcwNDcyMjU2OS40LjEuMTcwNDcyMzU1Mi41My4wLjA."}]},{"id":"G0092","name":"TA505","url":"https://attack.mitre.org/groups/G0092","kind":"intrusion-set","description":"[TA505](https://attack.mitre.org/groups/G0092) has downloaded additional malware to execute on victim systems.(Citation: Cybereason TA505 April 2019)(Citation: Deep Instinct TA505 Apr 2019)(Citation: ProofPoint SettingContent-ms July 2018)","relationship_id":"relationship--b3436a7d-81cf-4f79-9c74-e3b2370288d2","references":[{"source_name":"ProofPoint SettingContent-ms July 2018","description":"Proofpoint Staff. (2018, July 19). TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT. Retrieved April 19, 2019.","url":"https://www.proofpoint.com/us/threat-insight/post/ta505-abusing-settingcontent-ms-within-pdf-files-distribute-flawedammyy-rat"},{"source_name":"Cybereason TA505 April 2019","description":"Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.","url":"https://www.cybereason.com/blog/threat-actor-ta505-targets-financial-enterprises-using-lolbins-and-a-new-backdoor-malware"},{"source_name":"Deep Instinct TA505 Apr 2019","description":"Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..","url":"https://www.deepinstinct.com/blog/new-servhelper-variant-employs-excel-4-0-macro-to-drop-signed-payload"}]},{"id":"G0093","name":"GALLIUM","url":"https://attack.mitre.org/groups/G0093","kind":"intrusion-set","description":"[GALLIUM](https://attack.mitre.org/groups/G0093) dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and [HTRAN](https://attack.mitre.org/software/S0040).(Citation: Cybereason Soft Cell June 2019)(Citation: Microsoft GALLIUM December 2019)","relationship_id":"relationship--e1268feb-9326-40e1-b05b-fd8e0068488a","references":[{"source_name":"Cybereason Soft Cell June 2019","description":"Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.","url":"https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers"},{"source_name":"Microsoft GALLIUM December 2019","description":"MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.","url":"https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/"}]},{"id":"G0094","name":"Kimsuky","url":"https://attack.mitre.org/groups/G0094","kind":"intrusion-set","description":"[Kimsuky](https://attack.mitre.org/groups/G0094) has downloaded additional scripts, tools, and malware onto victim systems.(Citation: Talos Kimsuky Nov 2021)(Citation: Crowdstrike GTR2020 Mar 2020)(Citation: Securonix Kimsuky February 2025)(Citation: Aryaka Kimsuky July 2025)","relationship_id":"relationship--2011a4ee-6b40-45a1-8bcf-f19568d16d02","references":[{"source_name":"Talos Kimsuky Nov 2021","description":"An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.","url":"https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html"},{"source_name":"Crowdstrike GTR2020 Mar 2020","description":"Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.","url":"https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf"},{"source_name":"Securonix Kimsuky February 2025","description":"Den Iuzvyk, Tim Peck. (2025, February 13). Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks. Retrieved August 19, 2025.","url":"https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/"},{"source_name":"Aryaka Kimsuky July 2025","description":"Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance  to Control: The Operational Blueprint of Kimsuky APT  for Cyber Espionage. Retrieved April 18, 2026.","url":"https://www.aryaka.com/docs/reports/aryaka-kimsuky-apt-operational-blueprint.pdf"}]},{"id":"G0096","name":"APT41","url":"https://attack.mitre.org/groups/G0096","kind":"intrusion-set","description":"[APT41](https://attack.mitre.org/groups/G0096) used [certutil](https://attack.mitre.org/software/S0160) to download additional files.(Citation: FireEye APT41 March 2020)(Citation: Crowdstrike GTR2020 Mar 2020)(Citation: Group IB APT 41 June 2021) [APT41](https://attack.mitre.org/groups/G0096) downloaded post-exploitation tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) via command shell following initial access.(Citation: Rostovcev APT41 2021) [APT41](https://attack.mitre.org/groups/G0096) has uploaded Procdump   and NATBypass to a staging directory and has used these tools in follow-on activities.(Citation: apt41_dcsocytec_dec2022)","relationship_id":"relationship--b42c23c9-99f4-4b1f-91e2-a945a119fe98","references":[{"source_name":"Crowdstrike GTR2020 Mar 2020","description":"Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.","url":"https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf"},{"source_name":"apt41_dcsocytec_dec2022","description":"DCSO CyTec Blog. (2022, December 24). APT41 — The spy who failed to encrypt me. Retrieved June 13, 2024.","url":"https://medium.com/@DCSO_CyTec/apt41-the-spy-who-failed-to-encrypt-me-24fc0f49cad1"},{"source_name":"FireEye APT41 March 2020","description":"Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.","url":"https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html"},{"source_name":"Rostovcev APT41 2021","description":"Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.","url":"https://www.group-ib.com/blog/apt41-world-tour-2021/"},{"source_name":"Group IB APT 41 June 2021","description":"Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.","url":"https://www.group-ib.com/blog/colunmtk-apt41/"}]},{"id":"G0099","name":"APT-C-36","url":"https://attack.mitre.org/groups/G0099","kind":"intrusion-set","description":"[APT-C-36](https://attack.mitre.org/groups/G0099) has downloaded binary data from a specified domain after the malicious document is opened.(Citation: QiAnXin APT-C-36 Feb2019)","relationship_id":"relationship--c3bedbae-b1e1-4a35-8c59-d181dca093e4","references":[{"source_name":"QiAnXin APT-C-36 Feb2019","description":"QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.","url":"https://web.archive.org/web/20190625182633if_/https://ti.360.net/blog/articles/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en/"}]},{"id":"G0102","name":"Wizard Spider","url":"https://attack.mitre.org/groups/G0102","kind":"intrusion-set","description":"[Wizard Spider](https://attack.mitre.org/groups/G0102) can transfer malicious payloads such as ransomware to compromised machines.(Citation: Mandiant FIN12 Oct 2021)","relationship_id":"relationship--a137a1d7-d40b-4565-8377-98a3065d5fec","references":[{"source_name":"Mandiant FIN12 Oct 2021","description":"Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.","url":"https://web.archive.org/web/20220313061955/https://www.mandiant.com/sites/default/files/2021-10/fin12-group-profile.pdf"}]},{"id":"G0106","name":"Rocke","url":"https://attack.mitre.org/groups/G0106","kind":"intrusion-set","description":"[Rocke](https://attack.mitre.org/groups/G0106) used malware to download additional malicious files to the target system.(Citation: Talos Rocke August 2018)\t","relationship_id":"relationship--3e039f64-08da-4bb3-b8d5-1ed6428980ac","references":[{"source_name":"Talos Rocke August 2018","description":"Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.","url":"https://blog.talosintelligence.com/2018/08/rocke-champion-of-monero-miners.html"}]},{"id":"G0107","name":"Whitefly","url":"https://attack.mitre.org/groups/G0107","kind":"intrusion-set","description":"[Whitefly](https://attack.mitre.org/groups/G0107) has the ability to download additional tools from the C2.(Citation: Symantec Whitefly March 2019)","relationship_id":"relationship--1898925b-236a-4847-8a97-e934c07cdde1","references":[{"source_name":"Symantec Whitefly March 2019","description":"Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.","url":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/whitefly-espionage-singapore"}]},{"id":"G0112","name":"Windshift","url":"https://attack.mitre.org/groups/G0112","kind":"intrusion-set","description":"[Windshift](https://attack.mitre.org/groups/G0112) has used tools to deploy additional payloads to compromised hosts.(Citation: BlackBerry Bahamut)","relationship_id":"relationship--c43ec2e6-3769-4a1c-b99a-2d8988c7a207","references":[{"source_name":"BlackBerry Bahamut","description":"The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.","url":"https://www.blackberry.com/us/en/pdfviewer?file=/content/dam/blackberry-com/asset/enterprise/pdf/direct/report-spark-bahamut.pdf"}]},{"id":"G0114","name":"Chimera","url":"https://attack.mitre.org/groups/G0114","kind":"intrusion-set","description":"[Chimera](https://attack.mitre.org/groups/G0114) has remotely copied tools and malware onto targeted systems.(Citation: Cycraft Chimera April 2020)","relationship_id":"relationship--f94c1c97-ec5d-4703-93c1-91de05761d2a","references":[{"source_name":"Cycraft Chimera April 2020","description":"Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..","url":"https://web.archive.org/web/20231214094657/https://cycraft.com/download/CyCraft-Whitepaper-Chimera_V4.1.pdf"}]},{"id":"G0117","name":"Fox Kitten","url":"https://attack.mitre.org/groups/G0117","kind":"intrusion-set","description":"[Fox Kitten](https://attack.mitre.org/groups/G0117) has downloaded additional tools including [PsExec](https://attack.mitre.org/software/S0029) directly to endpoints.(Citation: CISA AA20-259A Iran-Based Actor September 2020)","relationship_id":"relationship--00de3cf9-73c4-4b04-a074-a5d73e9b61de","references":[{"source_name":"CISA AA20-259A Iran-Based Actor September 2020","description":"CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.","url":"https://us-cert.cisa.gov/ncas/alerts/aa20-259a"}]},{"id":"G0119","name":"Indrik Spider","url":"https://attack.mitre.org/groups/G0119","kind":"intrusion-set","description":"[Indrik Spider](https://attack.mitre.org/groups/G0119) has downloaded additional scripts, malware, and tools onto a compromised host.(Citation: Crowdstrike Indrik November 2018)(Citation: Symantec WastedLocker June 2020)(Citation: Mandiant_UNC2165)","relationship_id":"relationship--d9360852-584e-4980-9f9b-f56193bd3fc0","references":[{"source_name":"Crowdstrike Indrik November 2018","description":"Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.","url":"https://www.crowdstrike.com/blog/big-game-hunting-the-evolution-of-indrik-spider-from-dridex-wire-fraud-to-bitpaymer-targeted-ransomware/"},{"source_name":"Mandiant_UNC2165","description":"Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.","url":"https://cloud.google.com/blog/topics/threat-intelligence/unc2165-shifts-to-evade-sanctions/"},{"source_name":"Symantec WastedLocker June 2020","description":"Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.","url":"https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/wastedlocker-ransomware-us"}]},{"id":"G0120","name":"Evilnum","url":"https://attack.mitre.org/groups/G0120","kind":"intrusion-set","description":"[Evilnum](https://attack.mitre.org/groups/G0120) can deploy additional components or tools as needed.(Citation: ESET EvilNum July 2020)","relationship_id":"relationship--acdab071-f314-4671-a794-3c792b559c28","references":[{"source_name":"ESET EvilNum July 2020","description":"Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.","url":"https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/"}]},{"id":"G0121","name":"Sidewinder","url":"https://attack.mitre.org/groups/G0121","kind":"intrusion-set","description":"[Sidewinder](https://attack.mitre.org/groups/G0121) has used LNK files to download remote files to the victim's network.(Citation: ATT Sidewinder January 2021)(Citation: Cyble Sidewinder September 2020)","relationship_id":"relationship--400ed882-80e9-47f7-85a6-11996fbbb635","references":[{"source_name":"ATT Sidewinder January 2021","description":"Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.","url":"https://cdn-cybersecurity.att.com/docs/global-perspective-of-the-sidewinder-apt.pdf"},{"source_name":"Cyble Sidewinder September 2020","description":"Cyble. (2020, September 26). SideWinder APT Targets with futuristic Tactics and Techniques. Retrieved January 29, 2021.","url":"https://cybleinc.com/2020/09/26/sidewinder-apt-targets-with-futuristic-tactics-and-techniques/"}]},{"id":"G0123","name":"Volatile Cedar","url":"https://attack.mitre.org/groups/G0123","kind":"intrusion-set","description":"[Volatile Cedar](https://attack.mitre.org/groups/G0123) can deploy additional tools.(Citation: ClearSky Lebanese Cedar Jan 2021)","relationship_id":"relationship--aaac742e-ad51-470d-826c-8196cf3c1d3e","references":[{"source_name":"ClearSky Lebanese Cedar Jan 2021","description":"ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.","url":"https://www.clearskysec.com/wp-content/uploads/2021/01/Lebanese-Cedar-APT.pdf"}]},{"id":"G0125","name":"HAFNIUM","url":"https://attack.mitre.org/groups/G0125","kind":"intrusion-set","description":"[HAFNIUM](https://attack.mitre.org/groups/G0125) has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.(Citation: Microsoft HAFNIUM March 2020)(Citation: Rapid7 HAFNIUM Mar 2021) ","relationship_id":"relationship--05ff481d-299f-4b72-9210-f07e7c5bf938","references":[{"source_name":"Rapid7 HAFNIUM Mar 2021","description":"Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.","url":"https://www.rapid7.com/blog/post/2021/03/23/defending-against-the-zero-day-analyzing-attacker-behavior-post-exploitation-of-microsoft-exchange/"},{"source_name":"Microsoft HAFNIUM March 2020","description":"MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.","url":"https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"}]},{"id":"G0127","name":"TA551","url":"https://attack.mitre.org/groups/G0127","kind":"intrusion-set","description":"[TA551](https://attack.mitre.org/groups/G0127) has retrieved DLLs and installer binaries for malware execution from C2.(Citation: Unit 42 TA551 Jan 2021)","relationship_id":"relationship--c4953a3b-d674-4582-b644-1339ec097aad","references":[{"source_name":"Unit 42 TA551 Jan 2021","description":"Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.","url":"https://unit42.paloaltonetworks.com/ta551-shathak-icedid/"}]},{"id":"G0128","name":"ZIRCONIUM","url":"https://attack.mitre.org/groups/G0128","kind":"intrusion-set","description":"[ZIRCONIUM](https://attack.mitre.org/groups/G0128) has used tools to download malicious files to compromised hosts.(Citation: Zscaler APT31 Covid-19 October 2020)","relationship_id":"relationship--ddc7af3d-f8d7-468a-b9ed-59823f96fac2","references":[{"source_name":"Zscaler APT31 Covid-19 October 2020","description":"Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.","url":"https://www.zscaler.com/blogs/security-research/apt-31-leverages-covid-19-vaccine-theme-and-abuses-legitimate-online"}]},{"id":"G0129","name":"Mustang Panda","url":"https://attack.mitre.org/groups/G0129","kind":"intrusion-set","description":"[Mustang Panda](https://attack.mitre.org/groups/G0129) has downloaded additional executables following the initial infection stage.(Citation: Eset PlugX Korplug Mustang Panda March 2022)(Citation: Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022)(Citation: Recorded Future REDDELTA July 2020)(Citation: Sophos PlugX September 2022) [Mustang Panda](https://attack.mitre.org/groups/G0129) has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.(Citation: Unit42 Chinese VSCode 06 September 2024)","relationship_id":"relationship--c592bcf5-6e88-4d77-a274-0a58b7388e76","references":[{"source_name":"Eset PlugX Korplug Mustang Panda March 2022","description":"Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.","url":"https://www.welivesecurity.com/2022/03/23/mustang-panda-hodur-old-tricks-new-korplug-variant/"},{"source_name":"Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022","description":"Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.","url":"https://blog.talosintelligence.com/mustang-panda-targets-europe/"},{"source_name":"Recorded Future REDDELTA July 2020","description":"Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.","url":"https://go.recordedfuture.com/hubfs/reports/cta-2020-0728.pdf"},{"source_name":"Sophos PlugX September 2022","description":"Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.","url":"https://www.secureworks.com/blog/bronze-president-targets-russian-speakers-with-updated-plugx"},{"source_name":"Unit42 Chinese VSCode 06 September 2024","description":"Tom Fakterman. (2024, September 6). Chinese APT Abuses VSCode to Target Government in Asia. Retrieved March 24, 2025.","url":"https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/"}]},{"id":"G0130","name":"Ajax Security Team","url":"https://attack.mitre.org/groups/G0130","kind":"intrusion-set","description":"[Ajax Security Team](https://attack.mitre.org/groups/G0130) has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.(Citation: Check Point Rocket Kitten)","relationship_id":"relationship--efc39174-1103-4834-9efa-d0001ab1dd80","references":[{"source_name":"Check Point Rocket Kitten","description":"Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.","url":"https://blog.checkpoint.com/wp-content/uploads/2015/11/rocket-kitten-report.pdf"}]},{"id":"G0131","name":"Tonto Team","url":"https://attack.mitre.org/groups/G0131","kind":"intrusion-set","description":"[Tonto Team](https://attack.mitre.org/groups/G0131) has downloaded malicious DLLs which served as a [ShadowPad](https://attack.mitre.org/software/S0596) loader.(Citation: ESET Exchange Mar 2021)","relationship_id":"relationship--fb03b86a-02d4-4079-815f-46369026ad17","references":[{"source_name":"ESET Exchange Mar 2021","description":"Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021.","url":"https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/"}]},{"id":"G0133","name":"Nomadic Octopus","url":"https://attack.mitre.org/groups/G0133","kind":"intrusion-set","description":"[Nomadic Octopus](https://attack.mitre.org/groups/G0133) has used malicious macros to download additional files to the victim's machine.(Citation: ESET Nomadic Octopus 2018) ","relationship_id":"relationship--b5ba9aa4-f2dd-4433-994b-bfe4c7c972fe","references":[{"source_name":"ESET Nomadic Octopus 2018","description":"Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.","url":"https://www.virusbulletin.com/uploads/pdf/conference_slides/2018/Cherepanov-VB2018-Octopus.pdf"}]},{"id":"G0135","name":"BackdoorDiplomacy","url":"https://attack.mitre.org/groups/G0135","kind":"intrusion-set","description":"[BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) has downloaded additional files and tools onto a compromised host.(Citation: ESET BackdoorDiplomacy Jun 2021)","relationship_id":"relationship--b683c558-074d-4e29-808f-6d86948dd5d0","references":[{"source_name":"ESET BackdoorDiplomacy Jun 2021","description":"Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021","url":"https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/"}]},{"id":"G0136","name":"IndigoZebra","url":"https://attack.mitre.org/groups/G0136","kind":"intrusion-set","description":"[IndigoZebra](https://attack.mitre.org/groups/G0136) has downloaded additional files and tools from its C2 server.(Citation: Checkpoint IndigoZebra July 2021)","relationship_id":"relationship--febc7399-bbee-4a97-b5a1-d2d9cf5ba9fc","references":[{"source_name":"Checkpoint IndigoZebra July 2021","description":"CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.","url":"https://research.checkpoint.com/2021/indigozebra-apt-continues-to-attack-central-asia-with-evolving-tools/"}]},{"id":"G0138","name":"Andariel","url":"https://attack.mitre.org/groups/G0138","kind":"intrusion-set","description":"[Andariel](https://attack.mitre.org/groups/G0138) has downloaded additional tools and malware onto compromised hosts.(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)","relationship_id":"relationship--ef8385b2-e62c-4854-9a0b-f23d6de334cd","references":[{"source_name":"AhnLab Andariel Subgroup of Lazarus June 2018","description":"AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group,  a subgroup of the Lazarus. Retrieved September 29, 2021.","url":"https://web.archive.org/web/20230213154832/http://download.ahnlab.com/global/brochure/%5BAnalysis%5DAndariel_Group.pdf"}]},{"id":"G0139","name":"TeamTNT","url":"https://attack.mitre.org/groups/G0139","kind":"intrusion-set","description":"[TeamTNT](https://attack.mitre.org/groups/G0139) has the <code>curl</code> and <code>wget</code> commands as well as batch scripts to download new tools.(Citation: Intezer TeamTNT September 2020)(Citation: Cisco Talos Intelligence Group)","relationship_id":"relationship--8bb0a7b0-a032-4278-abae-5730f574ff00","references":[{"source_name":"Cisco Talos Intelligence Group","description":"Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022.","url":"https://blog.talosintelligence.com/teamtnt-targeting-aws-alibaba-2/"},{"source_name":"Intezer TeamTNT September 2020","description":"Fishbein, N. (2020, September 8). Attackers Abusing Legitimate Cloud Monitoring Tools to Conduct Cyber Attacks. Retrieved September 22, 2021.","url":"https://www.intezer.com/blog/cloud-security/attackers-abusing-legitimate-cloud-monitoring-tools-to-conduct-cyber-attacks/"}]},{"id":"G0140","name":"LazyScripter","url":"https://attack.mitre.org/groups/G0140","kind":"intrusion-set","description":"[LazyScripter](https://attack.mitre.org/groups/G0140) had downloaded additional tools to a compromised host.(Citation: MalwareBytes LazyScripter Feb 2021)","relationship_id":"relationship--928f19e8-6174-47c9-b44a-87477d89bdc9","references":[{"source_name":"MalwareBytes LazyScripter Feb 2021","description":"Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.","url":"https://web.archive.org/web/20211003035156/https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf"}]},{"id":"G0142","name":"Confucius","url":"https://attack.mitre.org/groups/G0142","kind":"intrusion-set","description":"[Confucius](https://attack.mitre.org/groups/G0142) has downloaded additional files and payloads onto a compromised host following initial access.(Citation: Uptycs Confucius APT Jan 2021)(Citation: TrendMicro Confucius APT Aug 2021)","relationship_id":"relationship--95d15400-aa0c-4382-be3f-49f931b81f27","references":[{"source_name":"TrendMicro Confucius APT Aug 2021","description":"Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.","url":"https://www.trendmicro.com/en_us/research/21/h/confucius-uses-pegasus-spyware-related-lures-to-target-pakistani.html"},{"source_name":"Uptycs Confucius APT Jan 2021","description":"Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.","url":"https://www.uptycs.com/blog/confucius-apt-deploys-warzone-rat"}]},{"id":"G0143","name":"Aquatic Panda","url":"https://attack.mitre.org/groups/G0143","kind":"intrusion-set","description":"[Aquatic Panda](https://attack.mitre.org/groups/G0143) has downloaded additional malware onto compromised hosts.(Citation: CrowdStrike AQUATIC PANDA December 2021)","relationship_id":"relationship--52ed39dd-0f4c-4e30-8b3b-7eb75b5c87e3","references":[{"source_name":"CrowdStrike AQUATIC PANDA December 2021","description":"Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.","url":"https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/"}]},{"id":"G1001","name":"HEXANE","url":"https://attack.mitre.org/groups/G1001","kind":"intrusion-set","description":"[HEXANE](https://attack.mitre.org/groups/G1001) has downloaded additional payloads and malicious scripts onto a compromised host.(Citation: Kaspersky Lyceum October 2021)","relationship_id":"relationship--bc0c33f3-211b-4b39-ac75-9d8693897b7f","references":[{"source_name":"Kaspersky Lyceum October 2021","description":"Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.","url":"https://vblocalhost.com/uploads/VB2021-Kayal-etal.pdf"}]},{"id":"G1002","name":"BITTER","url":"https://attack.mitre.org/groups/G1002","kind":"intrusion-set","description":"[BITTER](https://attack.mitre.org/groups/G1002) has downloaded additional malware and tools onto a compromised host.(Citation: Cisco Talos Bitter Bangladesh May 2022)(Citation: Forcepoint BITTER Pakistan Oct 2016) ","relationship_id":"relationship--03c86a72-8298-4558-afc7-19cc09da4ff5","references":[{"source_name":"Forcepoint BITTER Pakistan Oct 2016","description":"Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.","url":"https://www.forcepoint.com/blog/x-labs/bitter-targeted-attack-against-pakistan"},{"source_name":"Cisco Talos Bitter Bangladesh May 2022","description":"Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.","url":"https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html"}]},{"id":"G1008","name":"SideCopy","url":"https://attack.mitre.org/groups/G1008","kind":"intrusion-set","description":"[SideCopy](https://attack.mitre.org/groups/G1008) has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.(Citation: MalwareBytes SideCopy Dec 2021)","relationship_id":"relationship--1d2111ce-5034-472a-89a7-1818d11280fb","references":[{"source_name":"MalwareBytes SideCopy Dec 2021","description":"Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.","url":"https://www.malwarebytes.com/blog/news/2021/12/sidecopy-apt-connecting-lures-to-victims-payloads-to-infrastructure"}]},{"id":"G1009","name":"Moses Staff","url":"https://attack.mitre.org/groups/G1009","kind":"intrusion-set","description":"[Moses Staff](https://attack.mitre.org/groups/G1009) has downloaded and installed web shells to following path <code>C:\\inetpub\\wwwroot\\aspnet_client\\system_web\\IISpool.aspx</code>.(Citation: Checkpoint MosesStaff Nov 2021)","relationship_id":"relationship--cdef12f4-7353-4edc-90d7-f6f7f7a13e7d","references":[{"source_name":"Checkpoint MosesStaff Nov 2021","description":"Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.","url":"https://research.checkpoint.com/2021/mosesstaff-targeting-israeli-companies/"}]},{"id":"G1013","name":"Metador","url":"https://attack.mitre.org/groups/G1013","kind":"intrusion-set","description":"[Metador](https://attack.mitre.org/groups/G1013) has downloaded tools and malware onto a compromised system.(Citation: SentinelLabs Metador Sept 2022)","relationship_id":"relationship--e3b628b7-1513-4b68-87ab-809316836075","references":[{"source_name":"SentinelLabs Metador Sept 2022","description":"Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.","url":"https://assets.sentinelone.com/sentinellabs22/metador#page=1"}]},{"id":"G1014","name":"LuminousMoth","url":"https://attack.mitre.org/groups/G1014","kind":"intrusion-set","description":"[LuminousMoth](https://attack.mitre.org/groups/G1014) has downloaded additional malware and tools onto a compromised host.(Citation: Kaspersky LuminousMoth July 2021)(Citation: Bitdefender LuminousMoth July 2021)","relationship_id":"relationship--5a393124-ffca-447e-b230-468f2c57e023","references":[{"source_name":"Bitdefender LuminousMoth July 2021","description":"Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.","url":"https://www.bitdefender.com/blog/labs/luminousmoth-plugx-file-exfiltration-and-persistence-revisited"},{"source_name":"Kaspersky LuminousMoth July 2021","description":"Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.","url":"https://securelist.com/apt-luminousmoth/103332/"}]},{"id":"G1015","name":"Scattered Spider","url":"https://attack.mitre.org/groups/G1015","kind":"intrusion-set","description":"[Scattered Spider](https://attack.mitre.org/groups/G1015) has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.(Citation: Mandiant VMware vSphere JUL 2025)","relationship_id":"relationship--106dcc28-3070-4882-8751-1791d471d564","references":[{"source_name":"Mandiant VMware vSphere JUL 2025","description":"Mandiant Incident Response. (2025, July 23). From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944. Retrieved October 13, 2025.","url":"https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944"}]},{"id":"G1016","name":"FIN13","url":"https://attack.mitre.org/groups/G1016","kind":"intrusion-set","description":"[FIN13](https://attack.mitre.org/groups/G1016) has downloaded additional tools and malware to compromised systems.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)","relationship_id":"relationship--779b1ed2-5ff6-408d-837e-571bbc4ecc4a","references":[{"source_name":"Sygnia Elephant Beetle Jan 2022","description":"Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.","url":"https://web.archive.org/web/20220105132433/https://f.hubspotusercontent30.net/hubfs/8776530/Sygnia-%20Elephant%20Beetle_Jan2022.pdf"},{"source_name":"Mandiant FIN13 Aug 2022","description":"Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.","url":"https://www.mandiant.com/resources/blog/fin13-cybercriminal-mexico"}]},{"id":"G1017","name":"Volt Typhoon","url":"https://attack.mitre.org/groups/G1017","kind":"intrusion-set","description":"\n[Volt Typhoon](https://attack.mitre.org/groups/G1017) has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)","relationship_id":"relationship--ce2b3395-efd0-4ac8-9c52-69a571b66609","references":[{"source_name":"CISA AA24-038A PRC Critical Infrastructure February 2024","description":"CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.","url":"https://www.cisa.gov/sites/default/files/2024-03/aa24-038a_csa_prc_state_sponsored_actors_compromise_us_critical_infrastructure_3.pdf"}]},{"id":"G1018","name":"TA2541","url":"https://attack.mitre.org/groups/G1018","kind":"intrusion-set","description":"\n[TA2541](https://attack.mitre.org/groups/G1018) has used malicious scripts and macros with the ability to download additional payloads.(Citation: Cisco Operation Layover September 2021)\n","relationship_id":"relationship--1fc9bf47-32e7-45e5-87f3-3e7a5efdd35d","references":[{"source_name":"Cisco Operation Layover September 2021","description":"Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.","url":"https://blog.talosintelligence.com/operation-layover-how-we-tracked-attack/"}]},{"id":"G1020","name":"Mustard Tempest","url":"https://attack.mitre.org/groups/G1020","kind":"intrusion-set","description":"[Mustard Tempest](https://attack.mitre.org/groups/G1020) has deployed secondary payloads and third stage implants to compromised hosts.(Citation: Microsoft Ransomware as a Service)","relationship_id":"relationship--eeebf544-5120-400b-9e79-d98aa070f905","references":[{"source_name":"Microsoft Ransomware as a Service","description":"Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.","url":"https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/"}]},{"id":"G1021","name":"Cinnamon Tempest","url":"https://attack.mitre.org/groups/G1021","kind":"intrusion-set","description":"[Cinnamon Tempest](https://attack.mitre.org/groups/G1021) has downloaded files, including [Cobalt Strike](https://attack.mitre.org/software/S0154), to compromised hosts.(Citation: Sygnia Emperor Dragonfly October 2022)","relationship_id":"relationship--0beeaf4e-f9cf-46af-9e2f-116fff614d5f","references":[{"source_name":"Sygnia Emperor Dragonfly October 2022","description":"Biderman, O. et al. (2022, October 3). REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP. Retrieved December 6, 2023.","url":"https://blog.sygnia.co/revealing-emperor-dragonfly-a-chinese-ransomware-group"}]},{"id":"G1032","name":"INC Ransom","url":"https://attack.mitre.org/groups/G1032","kind":"intrusion-set","description":"[INC Ransom](https://attack.mitre.org/groups/G1032) has downloaded tools to compromised servers including Advanced IP Scanner. (Citation: Huntress INC Ransom Group August 2023)(Citation: Huntress INC Ransomware May 2024)","relationship_id":"relationship--e05db24d-57e8-40e9-a412-819ac5592ed8","references":[{"source_name":"Huntress INC Ransomware May 2024","description":"Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.","url":"https://www.huntress.com/blog/lolbin-to-inc-ransomware"},{"source_name":"Huntress INC Ransom Group August 2023","description":"Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.","url":"https://www.huntress.com/blog/investigating-new-inc-ransom-group-activity"}]},{"id":"G1034","name":"Daggerfly","url":"https://attack.mitre.org/groups/G1034","kind":"intrusion-set","description":"[Daggerfly](https://attack.mitre.org/groups/G1034) has used PowerShell and [BITSAdmin](https://attack.mitre.org/software/S0190) to retrieve follow-on payloads from external locations for execution on victim machines.(Citation: Symantec Daggerfly 2023)","relationship_id":"relationship--90f3ee94-f732-4718-8e42-bb002f4e2109","references":[{"source_name":"Symantec Daggerfly 2023","description":"Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.","url":"https://symantec-enterprise-blogs.security.com/threat-intelligence/apt-attacks-telecoms-africa-mgbot"}]},{"id":"G1035","name":"Winter Vivern","url":"https://attack.mitre.org/groups/G1035","kind":"intrusion-set","description":"[Winter Vivern](https://attack.mitre.org/groups/G1035) executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.(Citation: DomainTools WinterVivern 2021)","relationship_id":"relationship--b0aa8d46-dca7-442f-8ddb-c2ed5835732e","references":[{"source_name":"DomainTools WinterVivern 2021","description":"Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.","url":"https://www.domaintools.com/resources/blog/winter-vivern-a-look-at-re-crafted-government-maldocs/"}]},{"id":"G1036","name":"Moonstone Sleet","url":"https://attack.mitre.org/groups/G1036","kind":"intrusion-set","description":"[Moonstone Sleet](https://attack.mitre.org/groups/G1036) retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.(Citation: Microsoft Moonstone Sleet 2024)","relationship_id":"relationship--adeeaadc-9306-4d57-915b-d1e2d07b4387","references":[{"source_name":"Microsoft Moonstone Sleet 2024","description":"Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.","url":"https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/"}]},{"id":"G1040","name":"Play","url":"https://attack.mitre.org/groups/G1040","kind":"intrusion-set","description":"[Play](https://attack.mitre.org/groups/G1040) has used [Cobalt Strike](https://attack.mitre.org/software/S0154) to download files to compromised machines.(Citation: Trend Micro Ransomware Spotlight Play July 2023)","relationship_id":"relationship--913ea392-e874-463c-bfbf-a84668cfc5b6","references":[{"source_name":"Trend Micro Ransomware Spotlight Play July 2023","description":"Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.","url":"https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-play"}]},{"id":"G1043","name":"BlackByte","url":"https://attack.mitre.org/groups/G1043","kind":"intrusion-set","description":"[BlackByte](https://attack.mitre.org/groups/G1043) has transferred tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) to victim environments from file sharing and hosting websites.(Citation: Microsoft BlackByte 2023)","relationship_id":"relationship--0e7999e0-a0d4-4f08-be18-8db59a46f69e","references":[{"source_name":"Microsoft BlackByte 2023","description":"Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.","url":"https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/"}]},{"id":"G1046","name":"Storm-1811","url":"https://attack.mitre.org/groups/G1046","kind":"intrusion-set","description":"[Storm-1811](https://attack.mitre.org/groups/G1046) has used scripted `cURL` commands, [BITSAdmin](https://attack.mitre.org/software/S0190), and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.(Citation: Microsoft Storm-1811 2024)(Citation: rapid7-email-bombing)(Citation: RedCanary June Insights 2024)","relationship_id":"relationship--8f025145-ed37-4a29-bf4c-2fb3aa42e1f1","references":[{"source_name":"Microsoft Storm-1811 2024","description":"Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/"},{"source_name":"RedCanary June Insights 2024","description":"The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.","url":"https://redcanary.com/blog/threat-intelligence/intelligence-insights-june-2024/"},{"source_name":"rapid7-email-bombing","description":"Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.","url":"https://www.rapid7.com/blog/post/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators"}]},{"id":"G1051","name":"Medusa Group","url":"https://attack.mitre.org/groups/G1051","kind":"intrusion-set","description":"[Medusa Group](https://attack.mitre.org/groups/G1051) has leveraged [certutil](https://attack.mitre.org/software/S0160), PowerShell, and Windows Command to download additional tools to include RMM services.(Citation: CISA Medusa Group Medusa Ransomware March 2025) [Medusa Group](https://attack.mitre.org/groups/G1051) has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.(Citation: CISA Medusa Group Medusa Ransomware March 2025)(Citation: Broadcom Medusa Ransomware Medusa Group March 2025)","relationship_id":"relationship--7d0f57f6-6bed-44b2-a6b2-0e3da3e57f5e","references":[{"source_name":"CISA Medusa Group Medusa Ransomware March 2025","description":"Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a"},{"source_name":"Broadcom Medusa Ransomware Medusa Group March 2025","description":"Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.","url":"https://www.security.com/threat-intelligence/medusa-ransomware-attacks"}]},{"id":"G1055","name":"VOID MANTICORE","url":"https://attack.mitre.org/groups/G1055","kind":"intrusion-set","description":"[VOID MANTICORE](https://attack.mitre.org/groups/G1055) has deployed additional payloads from dedicated C2 servers.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)(Citation: DOJ FBI Handala Hack March 2026)(Citation: FBI IC3 Flash VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) has also downloaded legitimate tools and software from publicly available services.(Citation: Check Point VOID MANTICORE Handala Hack March 2026) [VOID MANTICORE](https://attack.mitre.org/groups/G1055) had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.(Citation: Check Point VOID MANTICORE Handala Hack March 2026)","relationship_id":"relationship--8dd66fa2-f73f-4088-a1c6-451513ff614d","references":[{"source_name":"Check Point VOID MANTICORE Handala Hack March 2026","description":"Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.","url":"https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/"},{"source_name":"DOJ FBI Handala Hack March 2026","description":"DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.","url":"https://www.justice.gov/opa/media/1431956/dl?inline"},{"source_name":"FBI IC3 Flash VOID MANTICORE Handala Hack March 2026","description":"FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to  Push Malware to Identified Targets. Retrieved April 20, 2026.","url":"https://www.ic3.gov/CSA/2026/260320.pdf"}]},{"id":"G1056","name":"TeamPCP","url":"https://attack.mitre.org/groups/G1056","kind":"intrusion-set","description":"[TeamPCP](https://attack.mitre.org/groups/G1056) has modified legitimate software binaries to retrieve secondary payloads from C2.(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Aikido TeamPCP Telnyx MAR 2026)","relationship_id":"relationship--20011401-761f-4937-bd16-d0d058e44bf9","references":[{"source_name":"Aikido TeamPCP Telnyx MAR 2026","description":"Eriksen, C. (2026, March 27). Popular telnyx package compromised on PyPI by TeamPCP. Retrieved July 16, 2026.","url":"https://www.aikido.dev/blog/telnyx-pypi-compromised-teampcp-canisterworm"},{"source_name":"Wiz TeamPCP KICS MAR 2026","description":"McCarthy, R., Haughom, J., Read, B. (2026, March 23). KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack. Retrieved July 1, 2026.","url":"https://www.wiz.io/blog/teampcp-attack-kics-github-action"}]},{"id":"G1057","name":"ShinyHunters","url":"https://attack.mitre.org/groups/G1057","kind":"intrusion-set","description":"[ShinyHunters](https://attack.mitre.org/groups/G1057) has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment.(Citation: Google_SHOracle_Jun2026)","relationship_id":"relationship--366015da-df59-466c-98fb-8d31d545d09c","references":[{"source_name":"Google_SHOracle_Jun2026","description":"Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026.","url":"https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"}]}],"mitigations":[{"id":"M1031","name":"Network Intrusion Prevention","url":"https://attack.mitre.org/mitigations/M1031","kind":"course-of-action","description":"Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware or unusual data transfer over known protocols like FTP can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools.(Citation: University of Birmingham C2)","relationship_id":"relationship--1ddae833-8280-4afa-b2b0-e250e22104fe","references":[{"source_name":"University of Birmingham C2","description":"Gardiner, J.,  Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.","url":"https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf"}]},{"id":"M1037","name":"Filter Network Traffic","url":"https://attack.mitre.org/mitigations/M1037","kind":"course-of-action","description":"Use network filtering to block outbound traffic from compromised systems to unapproved external destinations. Restricting access to known, trusted IP addresses and protocols can prevent attackers from downloading malicious tools or payloads onto compromised servers after gaining initial access.","relationship_id":"relationship--98c5ba6b-bd0a-4b55-8556-cb73623b9493","references":[]}],"candidates":[{"id":"0139dba1-f391-405e-a4f5-f3989f2c88ef","name":"sftp remote file copy (pull)","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize sftp to perform a remote file copy (pull)\n","inputs":{"remote_host":{"description":"Remote host to copy from","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive sftp","type":"path","default":"/tmp/victim-files/"},"remote_file":{"description":"Path of file to copy","type":"path","default":"/tmp/adversary-sftp"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[],"source_definition_sha256":"42eed955b0e713e27713ebd0d476029c9c9e1024ee6f41d3373f8d1fe23f3891"},{"id":"0fc6e977-cb12-44f6-b263-2824ba917409","name":"rsync remote file copy (push)","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":true,"dependency_count":1,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize rsync to perform a remote file copy (push)\n","inputs":{"remote_path":{"description":"Remote path to receive rsync","type":"path","default":"/tmp/victim-files"},"remote_host":{"description":"Remote host to copy toward","type":"string","default":"victim-host"},"local_path":{"description":"Path of folder to copy","type":"path","default":"/tmp/adversary-rsync/"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"victim"}},"dependencies":[{"description":"rsync must be installed on the machine \n"}],"source_definition_sha256":"63ca281d868df892d8aacc97f444ce7a50dfaaecbf8442bee5c73b4baeb3a695"},{"id":"1a02df58-09af-4064-a765-0babe1a0d1e2","name":"Download a file with IMEWDBLD.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use IMEWDBLD.exe (built-in to windows) to download a file. This will throw an error for an invalid dictionary file.\nDownloaded files can be found in \"%LocalAppData%\\Microsoft\\Windows\\INetCache\\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>\" or `%LocalAppData%\\Microsoft\\Windows\\INetCache\\IE\\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>.\nRun \"Get-ChildItem -Path C:\\Users\\<USERNAME>\\AppData\\Local\\Microsoft\\Windows\\INetCache\\ -Include <FILENAME>* -Recurse -Force -File -ErrorAction SilentlyContinue\" without quotes and adding the correct username and file name to locate the file.\n","inputs":{"remote_url":{"description":"Location of file to be downloaded.","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1105/T1105.yaml"},"file_name":{"description":"Name of the file to be downloaded without extension.","type":"string","default":"T1105"}},"dependencies":[],"source_definition_sha256":"3dffd3530b4f415034ef82c21c185ca097f6f30e3984d5622cafd56a59858d35"},{"id":"205e676e-0401-4bae-83a5-94b8c5daeb22","name":"Windows push file using sftp.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":true,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test simulates pushing files using SFTP on a Windows environment.\n","inputs":{"remote_path":{"description":"Path of folder to copy","type":"path","default":"/tmp"},"remote_host":{"description":"Remote host to send","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive sftp","type":"path","default":"C:\\temp"},"file_name":{"description":"Name of the file to transfer","type":"string","default":"T1105.txt"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[{"description":"This test requires the `sftp` command to be available on the system.\n"}],"source_definition_sha256":"a409f3c4b71e6ebae2f544760204cb435260dfffb8c25236381d25ff04e49026"},{"id":"2a4b0d29-e5dd-4b66-b729-07423ba1cd9d","name":"Windows push file using scp.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":true,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test simulates pushing files using SCP on a Windows environment.\n","inputs":{"remote_path":{"description":"Path of folder to copy","type":"path","default":"/tmp/"},"remote_host":{"description":"Remote host to send","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to copy from","type":"path","default":"C:\\temp"},"file_name":{"description":"Name of the file to transfer","type":"string","default":"T1105.txt"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[{"description":"This test requires the `scp` command to be available on the system.\n"}],"source_definition_sha256":"d5fd579f7ba99b197b658bdb54d922367a45ee6d38032c3dd0e3529eb2b51678"},{"id":"2b080b99-0deb-4d51-af0f-833d37c4ca6a","name":"Curl Download File","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"The following Atomic utilizes native curl.exe, or downloads it if not installed, to download a remote DLL and output to a number of directories to simulate malicious behavior.\nExpected output will include whether the file downloaded successfully or not.\n","inputs":{"file_download":{"description":"File to download","type":"string","default":"https://github.com/redcanaryco/atomic-red-team/raw/058b5c2423c4a6e9e226f4e5ffa1a6fd9bb1a90e/atomics/T1218.010/bin/AllTheThingsx64.dll"},"curl_path":{"description":"path to curl.exe","type":"path","default":"C:\\Windows\\System32\\Curl.exe"}},"dependencies":[{"description":"Curl must be installed on system.\n"}],"source_definition_sha256":"1fc5fc97ca8358796b710ee855684242a637501015e064a4441b993cec4f7bec"},{"id":"2ca61766-b456-4fcf-a35a-1233685e1cad","name":"OSTAP Worming Activity","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":true,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"OSTap copies itself in a specfic way to shares and secondary drives. This emulates the activity.\n","inputs":{"destination_path":{"description":"Path to create remote file at. Default is local admin share.","type":"string","default":"\\\\localhost\\C$"}},"dependencies":[],"source_definition_sha256":"db503e36b66c1c1e85c7212059a6d869a0c02d416e84467531fa7319958a7cb5"},{"id":"3180f7d5-52c0-4493-9ea0-e3431a84773f","name":"rsync remote file copy (pull)","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":1,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize rsync to perform a remote file copy (pull)\n","inputs":{"remote_path":{"description":"Path of folder to copy","type":"path","default":"/tmp/adversary-rsync/"},"remote_host":{"description":"Remote host to copy from","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive rsync","type":"path","default":"/tmp/victim-files"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[{"description":"rsync must be installed on the machine \n"}],"source_definition_sha256":"4b5c09bcf075e5942d8ae49c4e7a9c3947130b6de0a78a429d955b6d4ffb9911"},{"id":"3d25f1f2-55cb-4a41-a523-d17ad4cfba19","name":"Windows pull file using sftp.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":true,"dependency_count":1,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test simulates pulling files using SFTP on a Windows environment.\n","inputs":{"remote_path":{"description":"Path of file to pull","type":"path","default":"/tmp/T1105.txt"},"remote_host":{"description":"Remote host to pull from","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive files","type":"path","default":"C:\\temp"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[{"description":"This test requires the `sftp` command to be available on the system.\n"}],"source_definition_sha256":"0e183e0e6e0b5dd516f067e31ce140b9032865fad8e36a0e1a1912a9fd3f54d1"},{"id":"3dd6a6cf-9c78-462c-bd75-e9b54fc8925b","name":"Download a file with OneDrive Standalone Updater","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Uses OneDrive Standalone Updater to download a file from a specified URL by setting up the required registry keys.\nThis technique can be used to download files without executing anomalous executables.\nReference: https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/\n","inputs":{"remote_url":{"description":"URL to download file from","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"onedrive_path":{"description":"Path to OneDrive Standalone Updater executable","type":"path","default":"C:\\Users\\$env:USERNAME\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe"}},"dependencies":[{"description":"OneDriveStandaloneUpdater.exe must exist on disk at specified location\n"}],"source_definition_sha256":"a0c3f67ce6e31f757d9e049e74efd8d2391ce5dd443e0aec268803ee2390f1fd"},{"id":"401667dc-05a6-4da0-a2a7-acfe4819559c","name":"Windows pull file using scp.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":true,"dependency_count":1,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test simulates pulling files using SCP on a Windows environment.\n","inputs":{"remote_path":{"description":"Path of folder to pull","type":"path","default":"/tmp/T1105.txt"},"remote_host":{"description":"Remote host to pull from","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive files","type":"path","default":"C:\\temp"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[{"description":"This test requires the `scp` command to be available on the system.\n"}],"source_definition_sha256":"274e2a93a901e1070b7833af4ef174805afd1be6ce33915c3d1b554d38997b3e"},{"id":"42dc4460-9aa6-45d3-b1a6-3955d34e1fe8","name":"Windows - PowerShell Download","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test uses PowerShell to download a payload.\nThis technique is used by multiple adversaries and malware families.\n","inputs":{"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"destination_path":{"description":"Destination path to file","type":"path","default":"$env:TEMP\\Atomic-license.txt"}},"dependencies":[],"source_definition_sha256":"064053f98a4bc6586cea91687408584f30d27a0c3f7aa677fe2dc50c3a4ea678"},{"id":"49845fc1-7961-4590-a0f0-3dbcf065ae7e","name":"Printer Migration Command-Line Tool UNC share folder into a zip file","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Create a ZIP file from a folder in a remote drive\n","inputs":{"Path_unc":{"description":"Path to the UNC folder","type":"path","default":"\\\\127.0.0.1\\c$\\AtomicRedTeam\\atomics\\T1105\\src\\"},"Path_PrintBrm":{"description":"Path to PrintBrm.exe","type":"path","default":"C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"}},"dependencies":[],"source_definition_sha256":"90f755fe52af6bdca89746c312caf7d08c33667c4faf97488b011899415ee025"},{"id":"54782d65-12f0-47a5-b4c1-b70ee23de6df","name":"Lolbas replace.exe use to copy file","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Copy file.cab to destination\nReference: https://lolbas-project.github.io/lolbas/Binaries/Replace/\n","inputs":{"replace_cab":{"description":"Path to the cab file","type":"path","default":"PathToAtomicsFolder\\T1105\\src\\redcanary.cab"},"Path_replace":{"description":"Path to replace.exe","type":"path","default":"C:\\Windows\\System32\\replace.exe"}},"dependencies":[{"description":"#{replace_cab} must exist on system.\n"}],"source_definition_sha256":"fa1b30aa2fb8837300ad8b2acce3f56415a250c1a14921aea49b8f9e115ce8fa"},{"id":"54a4daf1-71df-4383-9ba7-f1a295d8b6d2","name":"File Download via PowerShell","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use PowerShell to download and write an arbitrary file from the internet. Example is from the 2021 Threat Detection Report by Red Canary.\n","inputs":{"target_remote_file":{"description":"File to download","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/4042cb3433bce024e304500dcfe3c5590571573a/LICENSE.txt"},"output_file":{"description":"File to write to","type":"string","default":"LICENSE.txt"}},"dependencies":[],"source_definition_sha256":"87d7f04020fd54bdbe0ac5c224826cd383badb247827c8bb5f74210aaa83c0ab"},{"id":"5bcefe5f-3f30-4f1c-a61a-8d7db3f4450c","name":"File download via nscurl","platforms":["macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use nscurl to download and write a file/payload from the internet.\n-k = Disable certificate checking\n-o = Output destination\n","inputs":{"remote_file":{"description":"URL of remote file to download","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"destination_path":{"description":"Local path to place remote file","type":"path","default":"license.txt"}},"dependencies":[],"source_definition_sha256":"cf7fcb0f77213377c12f56ff459defe65ffb7bb6b5a575d5448492d629ddcc5b"},{"id":"5f507e45-8411-4f99-84e7-e38530c45d01","name":"File download with finger.exe on Windows","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Simulate a file download using finger.exe. Connect to localhost by default, use custom input argument to test finger connecting to an external server.\nBecause this is being tested on the localhost, you should not be expecting a successful connection\nhttps://www.exploit-db.com/exploits/48815\nhttps://www.bleepingcomputer.com/news/security/windows-10-finger-command-can-be-abused-to-download-or-steal-files/\n","inputs":{"remote_host":{"description":"Remote hostname or IP address","type":"string","default":"localhost"}},"dependencies":[],"source_definition_sha256":"afb93396cff925718d0a69009c849af3b3b3f58d29051d0fb20baec4346c3750"},{"id":"635c9a38-6cbf-47dc-8615-3810bc1167cf","name":"Curl Upload File","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":2,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"The following Atomic utilizes native curl.exe, or downloads it if not installed, to upload a txt file to simulate data exfiltration\nExpected output will include whether the file uploaded successfully or not.\n","inputs":{"curl_path":{"description":"path to curl.exe","type":"path","default":"C:\\Windows\\System32\\Curl.exe"},"remote_destination":{"description":"Remote destination","type":"string","default":"www.example.com"},"file_path":{"description":"File to upload","type":"string","default":"c:\\temp\\atomictestfile.txt"}},"dependencies":[{"description":"Curl must be installed on system.\n"},{"description":"A file must be created to upload\n"}],"source_definition_sha256":"a8f58580ee5ce3d59ef224cd427ee65cc963993000466b12f292e8b9dfb96d08"},{"id":"66ee226e-64cb-4dae-80e3-5bf5763e4a51","name":"Arbitrary file download using the Notepad++ GUP.exe binary","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":true,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"GUP is an open source signed binary used by Notepad++ for software updates, and can be used to download arbitrary files(.zip) from internet/github.\n[Reference](https://x.com/nas_bench/status/1535322182863179776?s=20)\nUpon execution, a sample zip file will be downloaded to C:\\Temp\\Sample folder","inputs":{"target_file_url":{"description":"URL of the target ZIP file (Eg: https://example.com/test.zip)","type":"url","default":"https://getsamplefiles.com/download/zip/sample-2.zip"},"working_dir":{"description":"The directory where GUP.exe & it's dependecies exists","type":"path","default":"PathToAtomicsFolder\\T1105\\bin\\"},"gup_executable":{"description":"GUP is an open source signed binary used by Notepad++ for software updates","type":"String","default":"PathToAtomicsFolder\\T1105\\bin\\GUP.exe"},"target_file_sha256":{"description":"SHA256 value of target ZIP file","type":"string","default":"CAC4D26F32CA629DFB10FE614ED00EB1066A0C0011386290D3426C3DE2E53AC6"}},"dependencies":[{"description":"Gup.exe binary must exist on disk at specified location (#{gup_executable})"}],"source_definition_sha256":"6c66838df3f4090d66ecf35f8cbe8c8cca9cfbd6f0e22c41bb92185ceac917b8"},{"id":"6934c16e-0b3a-4e7f-ab8c-c414acd32181","name":"File Download with Sqlcmd.exe","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":true,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"One of the windows packages 'Sqlcmd.exe' can be abused to download malicious files from C2 servers\nThis Atomic will exhibit the similar behavior by downloading a sample zip file from src directory of this Technique folder via GitHub URL","inputs":{"remote_url":{"description":"URL of the C2 Server from where file/s need to be downloaded","type":"url","default":"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1105/src/T1105.zip"},"local_file_path":{"description":"The local file path along with filename to where the file needs to be downloaded and placed.","type":"path","default":"C:\\T1105.zip"}},"dependencies":[{"description":"Windows package 'Sqlcmd' need to be available in the machine to execute this atomic successfully"}],"source_definition_sha256":"b192e66b008bf02b547df4e106b147084f21ed29a37263aeb5a7df5e4f0b4761"},{"id":"6fdaae87-c05b-42f8-842e-991a74e8376b","name":"certreq download","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use certreq to download a file from the web","inputs":{"local_path":{"description":"Local path to place file","type":"string","default":"%temp%\\Atomic-license.txt"},"remote_file":{"description":"URL of file to copy","type":"url","default":"https://example.com"}},"dependencies":[],"source_definition_sha256":"0c79b91c03a12425ffa3309d50034ca33f4c0dd30caad48942c31af2d661357c"},{"id":"70f4d07c-5c3e-4d53-bb0a-cdf3ada14baf","name":"MAZE Propagation Script","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":2,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test simulates MAZE ransomware's propogation script that searches through a list of computers, tests connectivity to them, and copies a binary file to the Windows\\Temp directory of each one. \nUpon successful execution, a specified binary file will attempt to be copied to each online machine, a list of the online machines, as well as a list of offline machines will be output to a specified location.\nReference: https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html \n","inputs":{"binary_file":{"description":"Binary file to copy to remote machines","type":"string","default":"$env:comspec"},"exe_remote_folder":{"description":"Path to store executable on remote machine (no drive letter)","type":"string","default":"\\Windows\\Temp\\T1105.exe"},"remote_drive_letter":{"description":"Remote drive letter","type":"string","default":"C"}},"dependencies":[{"description":"Binary file must exist at specified location (#{binary_file})\n"},{"description":"Machine list must exist at specified location (\"PathToAtomicsFolder\\..\\ExternalPayloads\\T1105MachineList.txt\")\n"}],"source_definition_sha256":"3acca00baaf35961b0ea2bf8ca2b0af29a3ccf549b8b1b91e036ecab3896e01a"},{"id":"815bef8b-bf91-4b67-be4c-abe4c2a94ccc","name":"Download a File with Windows Defender MpCmdRun.exe","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Uses Windows Defender MpCmdRun.exe to download a file from the internet (must have version 4.18 installed).\nThe input arguments \"remote_file\" and \"local_path\" can be used to specify the download URL and the name of the output file.\nBy default, the test downloads the Atomic Red Team license file to the temp directory.\n\nMore info and how to find your version can be found here https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/\n","inputs":{"remote_file":{"description":"URL of file to download","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"local_path":{"description":"Location to save downloaded file","type":"path","default":"%temp%\\Atomic-license.txt"}},"dependencies":[{"description":"Must have a Windows Defender version with MpCmdRun.exe installed"}],"source_definition_sha256":"8877c0750a08e950698deffd52910b13e97a2bfcf968cd78833211de4295fb08"},{"id":"83a49600-222b-4866-80a0-37736ad29344","name":"scp remote file copy (push)","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize scp to perform a remote file copy (push)\n","inputs":{"remote_path":{"description":"Remote path to receive scp","type":"path","default":"/tmp/victim-files/"},"local_file":{"description":"Path of file to copy","type":"path","default":"/tmp/adversary-scp"},"remote_host":{"description":"Remote host to copy toward","type":"string","default":"victim-host"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"victim"}},"dependencies":[],"source_definition_sha256":"0cbebd15cb83290de45cad1e0e03a9522eab2ef7be8df7f6b3d94ee2210e73b1"},{"id":"97116a3f-efac-4b26-8336-b9cb18c45188","name":"Download a file using wscript","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use wscript to run a local VisualBasic file to download a remote file","inputs":{"vbscript_file":{"description":"Full path to the VisualBasic downloading the file","type":"string","default":"PathToAtomicsFolder\\T1105\\src\\T1105-download-file.vbs"}},"dependencies":[{"description":"#{vbscript_file} must be exist on system.\n"}],"source_definition_sha256":"c0781063ca0a9af2648c469e62299b4075e82f1ba7dc57c3af1d5b79ea869d2f"},{"id":"a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b","name":"Windows - BITSAdmin BITS Download","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"This test uses BITSAdmin.exe to schedule a BITS job for the download of a file.\nThis technique is used by Qbot malware to download payloads.\n","inputs":{"bits_job_name":{"description":"Name of the created BITS job","type":"string","default":"qcxjb7"},"local_path":{"description":"Local path to place file","type":"path","default":"%temp%\\Atomic-license.txt"},"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"}},"dependencies":[],"source_definition_sha256":"713d9b14df39588b263f456f2a842e7f9e4b22d76741183bfa65f282d299bbcc"},{"id":"b1729c57-9384-4d1c-9b99-9b220afb384e","name":"Nimgrab - Transfer Files","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use nimgrab.exe to download a file from the web. \n","inputs":{"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"destination_path":{"description":"Destination path to file","type":"path","default":"$env:TEMP\\Atomic-license.txt"}},"dependencies":[{"description":"NimGrab must be installed on system.\n"}],"source_definition_sha256":"4cbe476a6e94bd0f0049b61f49f6310a4d018f16bc8890e582d5a5b0f44ef3f9"},{"id":"b9d22b9a-9778-4426-abf0-568ea64e9c33","name":"scp remote file copy (pull)","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize scp to perform a remote file copy (pull)\n","inputs":{"remote_host":{"description":"Remote host to copy from","type":"string","default":"adversary-host"},"local_path":{"description":"Local path to receive scp","type":"path","default":"/tmp/victim-files/"},"remote_file":{"description":"Path of file to copy","type":"path","default":"/tmp/adversary-scp"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"adversary"}},"dependencies":[],"source_definition_sha256":"c81aeb11a1059d06761a0d9f523b00e1d6f74e9ab4f664fb6844c47fc8e2a2ea"},{"id":"bdc373c5-e9cf-4563-8a7b-a9ba720a90f3","name":"Linux Download File and Run","platforms":["linux"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize linux Curl to download a remote file, chmod +x it and run it.\n","inputs":{"remote_url":{"description":"url of remote payload","type":"string","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1105/src/atomic.sh"},"payload_name":{"description":"payload name","type":"string","default":"atomic.sh"}},"dependencies":[],"source_definition_sha256":"194756ad30294a62063a5be813a19298766bddfdb1e0cf00bb2803eb4ed2e509"},{"id":"c01cad7f-7a4c-49df-985e-b190dcf6a279","name":"iwr or Invoke Web-Request download","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":true,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use 'iwr' or \"Invoke-WebRequest\" -URI argument to download a file from the web. Note: without -URI also works in some versions.\n","inputs":{"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"local_path":{"description":"Local path to place file","type":"path","default":"%temp%\\Atomic-license.txt"}},"dependencies":[],"source_definition_sha256":"56d58ed286e56bb977362d110d363b6ae007ecc4d6addbbeaf0005ace145dab9"},{"id":"c82b1e60-c549-406f-9b00-0a8ae31c9cfe","name":"Remote File Copy using PSCP","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Copy a staged file using PSCP.exe to a public target location.\n","inputs":{"pscp_url":{"description":"pscp.exe download path","type":"string","default":"https://the.earth.li/~sgtatham/putty/latest/w64/pscp.exe"},"pscp_binary":{"description":"PSCP binary location","type":"string","default":"PathToAtomicsFolder\\..\\ExternalPayloads\\pscp.exe"},"scp_user":{"description":"Username of the SCP user","type":"string","default":"atomic"},"scp_password":{"description":"Password for the SCP User","type":"string","default":"atomic"},"scp_port":{"description":"port for the remote server","type":"string","default":"22"},"exfil_package":{"description":"path to exfil package","type":"path","default":"C:\\Temp\\T1105_scp.zip"},"target_location":{"description":"Remote location where the data will be copied to.","type":"string","default":"127.0.0.1"},"target_filename":{"description":"Filename on the destination.","type":"string","default":"T1105_scp.zip"}},"dependencies":[{"description":"pscp.exe must be available on the system.\n"}],"source_definition_sha256":"1f560a02275d7f518de9b598dd31b4c0d8a69d519acf4f0f79149009eaf8b022"},{"id":"c99a829f-0bb8-4187-b2c6-d47d1df74cab","name":"whois file download","platforms":["linux","macos"],"method":"automated","executor":"sh","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Download a remote file using the whois utility\n","inputs":{"remote_host":{"description":"Remote hostname or IP address","type":"string","default":"localhost"},"remote_port":{"description":"Remote port to connect to","type":"integer","default":8443},"output_file":{"description":"Path of file to save output to","type":"path","default":"/tmp/T1105.whois.out"},"query":{"description":"Query to send to remote server","type":"string","default":"Hello from Atomic Red Team test T1105"},"timeout":{"description":"Timeout period before ending process (seconds)","type":"integer","default":1}},"dependencies":[{"description":"The whois and timeout commands must be present\n"}],"source_definition_sha256":"c38a27fc0b163e8b99754e178142d0fd523eb2c96e6c9c88fae0bfda86f022c8"},{"id":"d239772b-88e2-4a2e-8473-897503401bcc","name":"Download a file with Microsoft Connection Manager Auto-Download","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":1,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Uses the cmdl32 to download arbitrary file from the internet. The cmdl32 package is allowed to install the profile used to launch the VPN connection. However, the config is modified to download the arbitary file. \nThe issue of cmdl32.exe detecting and deleting the payload by identifying it as not a VPN Servers profile is avoided by setting a temporary TMP folder and denying the delete permission to all files for the user.\nUpon successful execution the test will open calculator and Notepad executable for 10 seconds.\nreference:\nhttps://twitter.com/ElliotKillick/status/1455897435063074824\nhttps://github.com/LOLBAS-Project/LOLBAS/pull/151\nhttps://lolbas-project.github.io/lolbas/Binaries/Cmdl32/\nhttps://strontic.github.io/xcyclopedia/library/cmdl32.exe-FA1D5B8802FFF4A85B6F52A52C871BBB.html\n","inputs":{"Path_to_file":{"description":"Path to the Batch script","type":"path","default":"PathToAtomicsFolder\\T1105\\src\\T1105.bat"}},"dependencies":[{"description":"#{Path_to_file} must exist on system.\n"}],"source_definition_sha256":"9d54d615cff9831723e16596b765ca4d10cf0014d4db29a211e677529e532aa9"},{"id":"dd3b61dd-7bbc-48cd-ab51-49ad1a776df0","name":"certutil download (urlcache)","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use certutil -urlcache argument to download a file from the web. Note - /urlcache also works!\n","inputs":{"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"local_path":{"description":"Local path to place file","type":"path","default":"Atomic-license.txt"}},"dependencies":[],"source_definition_sha256":"f91cd2e69828ac9e7d02977aaab2779c51a1961691eed2f01018e77352029ce5"},{"id":"ed0335ac-0354-400c-8148-f6151d20035a","name":"Lolbas replace.exe use to copy UNC file","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Copy UNC file to destination\nReference: https://lolbas-project.github.io/lolbas/Binaries/Replace/\n","inputs":{"replace_cab":{"description":"UNC Path to the cab file","type":"path","default":"\\\\127.0.0.1\\c$\\AtomicRedTeam\\atomics\\T1105\\src\\redcanary.cab"},"Path_replace":{"description":"Path to replace.exe","type":"path","default":"C:\\Windows\\System32\\replace.exe"}},"dependencies":[],"source_definition_sha256":"e22d1d8608e1f30a9244aabec7234716243659f06ae5ac63de93633d3f8a9f6d"},{"id":"f564c297-7978-4aa9-b37a-d90477feea4e","name":"sftp remote file copy (push)","platforms":["linux","macos"],"method":"automated","executor":"bash","elevation_required":false,"dependency_count":0,"cleanup_defined":false,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Utilize sftp to perform a remote file copy (push)\n","inputs":{"remote_path":{"description":"Remote path to receive sftp","type":"path","default":"/tmp/victim-files/"},"local_file":{"description":"Path of file to copy","type":"path","default":"/tmp/adversary-sftp"},"remote_host":{"description":"Remote host to copy toward","type":"string","default":"victim-host"},"username":{"description":"User account to authenticate on remote host","type":"string","default":"victim"}},"dependencies":[],"source_definition_sha256":"c035e2fc93d6929f5e6f02e908bd2f9461bc304e19af1d3f2a65c8f3994150b1"},{"id":"fa5a2759-41d7-4e13-a19c-e8f28a53566f","name":"svchost writing a file to a UNC path","platforms":["windows"],"method":"automated","executor":"command_prompt","elevation_required":true,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"svchost.exe writing a non-Microsoft Office file to a file with a UNC path.\nUpon successful execution, this will rename cmd.exe as svchost.exe and move it to `c:\\`, then execute svchost.exe with output to a txt file.\n","inputs":{},"dependencies":[],"source_definition_sha256":"e96827aab98905df7454f9973b6df2fc203655d6cd5e13b7b090bfe57905bf16"},{"id":"ffd492e3-0455-4518-9fb1-46527c9f241b","name":"certutil download (verifyctl)","platforms":["windows"],"method":"automated","executor":"powershell","elevation_required":false,"dependency_count":0,"cleanup_defined":true,"review_status":"not_individually_reviewed","source_url":"https://github.com/redcanaryco/atomic-red-team/blob/388942adbd9641f4dfdcf079d7efe9a75ec0ac43/atomics/T1105/T1105.yaml","description":"Use certutil -verifyctl argument to download a file from the web. Note - /verifyctl also works!\n","inputs":{"remote_file":{"description":"URL of file to copy","type":"url","default":"https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt"},"local_path":{"description":"Local path to place file","type":"path","default":"Atomic-license.txt"}},"dependencies":[],"source_definition_sha256":"fe6a2196714ae0f60ba47dd28a4e3741976741e4aad994712509a1d6a9f25553"}],"simulation":{"atomic_status":"documented_candidate","lab_execution":"not_run","browser_attack_runner":false,"prerequisites":"Use disposable lab hosts and test accounts, explicit target allowlists, a clean snapshot, bounded egress and a restore plan. Review every candidate and dependency before any execution.","scenario":null},"validation":{"source_identity":"checked_against_pinned_source","relationship_join":"exact_ids_no_inheritance","page_contract":"automated_checks_required","sensor_capture":"not_run","detection_backend":"not_run","adversary_simulation":"not_run","independent_incident_fact_check":"not_performed"},"technique_links":{"T1570":"/ttp-simulation/techniques/enterprise/T1570/","T1059.001":"/ttp-simulation/techniques/enterprise/T1059.001/","T1204":"/ttp-simulation/techniques/enterprise/T1204/","T1566":"/ttp-simulation/techniques/enterprise/T1566/","T1102":"/ttp-simulation/techniques/enterprise/T1102/","T1105":"/ttp-simulation/techniques/enterprise/T1105/","T1197":"/ttp-simulation/techniques/enterprise/T1197/","T1027.008":"/ttp-simulation/techniques/enterprise/T1027.008/"},"synthetic":{"schema":"1200km.ttp.collection-fixture.v1","synthetic":true,"technique_key":"enterprise/T1105","purpose":"Collection/parser contract exercise, NOT a positive example or detection of this TTP.","events":[{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0064","collector":"illustrative-lab-collector","observation":{"interpreter":"/bin/sh","command_line":"printf LAB_TELEMETRY_CHECK","actor_uid":1000,"session_id":"lab-session-1"}},{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0039","collector":"illustrative-lab-collector","observation":{"process_id":4200,"path":"C:\\Lab\\demo.txt","action":"create","size_bytes":64}},{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0082","collector":"illustrative-lab-collector","observation":{"process_guid":"lab-process-001","destination_ip":"198.51.100.20","destination_port":443,"protocol":"tcp","initiated":true}},{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0078","collector":"illustrative-lab-collector","observation":{"source_ip":"192.0.2.10","destination_ip":"198.51.100.20","destination_port":443,"protocol":"tcp","bytes_sent":128,"bytes_received":512}},{"schema":"1200km.telemetry.example.v1","synthetic":true,"timestamp":"2026-09-27T12:00:00Z","telemetry_id":"DC0032","collector":"illustrative-lab-collector","observation":{"process_guid":"lab-process-001","image":"C:\\Windows\\System32\\whoami.exe","parent_image":"C:\\Windows\\System32\\cmd.exe","command_line":"whoami","user":"LAB\\analyst"}}]}}
