- S0009 Hikit — malware.
Hikit has the ability to download files to a compromised host.[Novetta-Axiom]
Exact relationship: relationship--fb0206c4-ed10-4922-9935-cbb2c7462acd - S0011 Taidoor — malware.
Taidoor has downloaded additional files onto a compromised host.[TrendMicro Taidoor]
Exact relationship: relationship--665f8af6-bdac-4574-9d8c-9c7829e0e4e7 - S0012 PoisonIvy — malware.
PoisonIvy creates a backdoor through which remote attackers can upload files.[Symantec Darkmoon Aug 2005]
Exact relationship: relationship--ae7b632b-bb15-4807-be21-bdfff70f4f2e - S0013 PlugX — malware.
PlugX has a module to download and execute files on the compromised machine.[CIRCL PlugX March 2013][DOJ Affidavit Search and Seizure PlugX December 2024][Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025][Proofpoint TA416 Europe March 2022]
Exact relationship: relationship--7c8e34ad-89a4-44cf-bd56-d1583803f086 - S0015 Ixeshe — malware.
Ixeshe can download and execute additional files.[Trend Micro IXESHE 2012]
Exact relationship: relationship--79b980bb-f79e-4576-b927-be52be236f15 - S0017 BISCUIT — malware.
BISCUIT has a command to download a file from the C2 server.[Mandiant APT1 Appendix]
Exact relationship: relationship--b0220134-2033-4261-9b1d-e94abd691476 - S0020 China Chopper — malware.
China Chopper's server component can download remote files.[FireEye Periscope March 2018][Lee 2013][NCSC Joint Report Public Tools][Rapid7 HAFNIUM Mar 2021][Kaspersky ToddyCat June 2022]
Exact relationship: relationship--30da0c3d-8767-4828-b50d-181d9a89b9a8 - S0022 Uroburos — malware.
Uroburos can use a `Put` command to write files to an infected machine.[Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023]
Exact relationship: relationship--b107d35b-fa2b-4dcb-844e-cacaf15f9982 - S0023 CHOPSTICK — malware.
CHOPSTICK is capable of performing remote file transmission.[Crowdstrike DNC June 2016]
Exact relationship: relationship--731710ae-a6b9-47b7-b8b2-8526ce60be2f - S0024 Dyre — malware.
Dyre has a command to download and executes additional files.[Symantec Dyre June 2015]
Exact relationship: relationship--47cd42b3-1a19-415f-8522-a601268d8017 - S0032 gh0st RAT — malware.
gh0st RAT can download files to the victim’s machine.[Nccgroup Gh0st April 2018][Gh0stRAT ATT March 2019]
Exact relationship: relationship--33a382a9-ebb3-48d9-bb7e-394a27783668 - S0042 LOWBALL — malware.
LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.[FireEye admin@338]
Exact relationship: relationship--25cb2c8f-79d2-4157-8329-fb86caaca0c3 - S0044 JHUHUGIT — malware.
JHUHUGIT can retrieve an additional payload from its C2 server.[ESET Sednit Part 1][Unit 42 Sofacy Feb 2018] JHUHUGIT has a command to download files to the victim’s machine.[Talos Seduploader Oct 2017]
Exact relationship: relationship--f39d9e4d-b4f9-4c12-aa8e-a44f8550b57f - S0051 MiniDuke — malware.
MiniDuke can download additional encrypted backdoors onto the victim via GIF files.[Securelist MiniDuke Feb 2013][ESET Dukes October 2019]
Exact relationship: relationship--67b49860-e1e4-4b56-bf83-108c4ac25e5c - S0053 SeaDuke — malware.
SeaDuke is capable of uploading and downloading files.[Unit 42 SeaDuke 2015]
Exact relationship: relationship--5abaaa8f-19c7-448f-9e5a-66f1cbf412f9 - S0054 CloudDuke — malware.
CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.[F-Secure The Dukes]
Exact relationship: relationship--800825f5-6e74-43ad-a732-476fdf471225 - S0055 RARSTONE — malware.
RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.[Aquino RARSTONE]
Exact relationship: relationship--4bf364ad-1e9c-4860-93c0-241da4c81068 - S0070 HTTPBrowser — malware.
HTTPBrowser is capable of writing a file to the compromised system from the C2 server.[Dell TG-3390]
Exact relationship: relationship--0e12d7d1-5c46-4314-97fb-263853eed6af - S0074 Sakula — malware.
Sakula has the capability to download files.[Dell Sakula]
Exact relationship: relationship--33162cc2-a800-4d42-89bb-13ac1e75dfce - S0077 CallMe — malware.
CallMe has the capability to download a file to the victim from the C2 server.[Scarlet Mimic Jan 2016]
Exact relationship: relationship--bdd64378-e348-4156-8490-528392c6ea82 - S0078 Psylo — malware.
Psylo has a command to download a file to the system from its C2 server.[Scarlet Mimic Jan 2016]
Exact relationship: relationship--a1e74408-5c7b-4538-afd9-a01b23a92429 - S0079 MobileOrder — malware.
MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.[Scarlet Mimic Jan 2016]
Exact relationship: relationship--56d858ef-2d62-4aa9-b050-699de9b048e9 - S0080 Mivast — malware.
Mivast has the capability to download and execute .exe files.[Symantec Backdoor.Mivast]
Exact relationship: relationship--d7699bcf-5732-40f5-a715-d430b00b043e - S0081 Elise — malware.
Elise can download additional files from the C2 server for execution.[Accenture Dragonfish Jan 2018]
Exact relationship: relationship--138c4559-eae3-49a2-baea-b9549aef881c - S0082 Emissary — malware.
Emissary has the capability to download files from the C2 server.[Lotus Blossom Dec 2015]
Exact relationship: relationship--85ca1e00-24c4-403e-8aff-9890f91e9b78 - S0083 Misdat — malware.
Misdat is capable of downloading files from the C2.[Cylance Dust Storm]
Exact relationship: relationship--ae3be82b-3d54-4be8-939b-e074a2cea170 - S0084 Mis-Type — malware.
Mis-Type has downloaded additional malware and files onto a compromised host.[Cylance Dust Storm]
Exact relationship: relationship--424b60eb-a6d1-405f-8f95-648fd6d52658 - S0085 S-Type — malware.
S-Type can download additional files onto a compromised host.[Cylance Dust Storm]
Exact relationship: relationship--4a42e063-e5c1-4408-9634-fe2fe8af76b5 - S0086 ZLib — malware.
ZLib has the ability to download files.[Cylance Dust Storm]
Exact relationship: relationship--2025480a-6d91-4ef5-a6ea-cc025c8aecfb - S0087 Hi-Zor — malware.
Hi-Zor has the ability to upload and download files from its C2 server.[Fidelis INOCNATION]
Exact relationship: relationship--18572125-3439-4f7c-92c8-d787913dc989 - S0088 Kasidet — malware.
Kasidet has the ability to download and execute additional files.[Zscaler Kasidet]
Exact relationship: relationship--c39e878e-a496-4271-9998-2d5c9511e0a4 - S0092 Agent.btz — malware.
Agent.btz attempts to download an encrypted binary from a specified domain.[ThreatExpert Agent.btz]
Exact relationship: relationship--fcc12c1f-1a46-49f4-a872-99cb97968bf0 - S0093 Backdoor.Oldrea — malware.
Backdoor.Oldrea can download additional modules from C2.[Gigamon Berserk Bear October 2021]
Exact relationship: relationship--984a898c-f469-4e7c-94c6-bf512ec69938 - S0094 Trojan.Karagany — malware.
Trojan.Karagany can upload, download, and execute files on the victim.[Symantec Dragonfly][Secureworks Karagany July 2019]
Exact relationship: relationship--7282eabe-73e0-4a10-824b-f18df7f892e2 - S0095 ftp — tool.
ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.[Microsoft FTP][Linux FTP]
Exact relationship: relationship--bb4592cf-4e26-4999-bb6d-5120e0695bfa - S0106 cmd — tool.
cmd can be used to copy files to/from a remotely connected external system.[TechNet Copy]
Exact relationship: relationship--2c13a056-b82d-4f56-a530-8562e0e9b038 - S0109 WEBC2 — malware.
WEBC2 can download and execute a file.[Mandiant APT1]
Exact relationship: relationship--a33a1a9c-c8d1-45f5-ad29-4a4188e5a54b - S0115 Crimson — malware.
Crimson contains a command to retrieve files from its C2 server.[Proofpoint Operation Transparent Tribe March 2016][Kaspersky Transparent Tribe August 2020][Cisco Talos Transparent Tribe Education Campaign July 2022]
Exact relationship: relationship--a0186caf-482a-4f2a-bf2f-cac9fc51244a - S0118 Nidiran — malware.
Nidiran can download and execute files.[Symantec Backdoor.Nidiran]
Exact relationship: relationship--438cae9c-cb03-4db9-ae59-24ed27147725 - S0124 Pisloader — malware.
Pisloader has a command to upload a file to the victim machine.[Palo Alto DNS Requests]
Exact relationship: relationship--ce4707f0-d5b8-4dd6-b5ab-cf1483dd236f - S0125 Remsec — malware.
Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.[Symantec Remsec IOCs][Kaspersky ProjectSauron Technical Analysis]
Exact relationship: relationship--820c50f3-65e8-4a3a-a71a-e079ae8badad - S0128 BADNEWS — malware.
BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.[Forcepoint Monsoon][PaloAlto Patchwork Mar 2018][TrendMicro Patchwork Dec 2017]
Exact relationship: relationship--b3f53743-4bd9-47a6-bf41-6f7786bbdc87 - S0130 Unknown Logger — malware.
Unknown Logger is capable of downloading remote files.[Forcepoint Monsoon]
Exact relationship: relationship--321544e0-902c-443e-adf9-d7e78f0e4d13 - S0132 H1N1 — malware.
H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.[Cisco H1N1 Part 2]
Exact relationship: relationship--a7e5ffbc-d123-4f62-88eb-36b32656cd35 - S0134 Downdelph — malware.
After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.[ESET Sednit Part 3]
Exact relationship: relationship--9c7a9bd0-4f52-4c10-8e79-3b6e72d431d1 - S0137 CORESHELL — malware.
CORESHELL downloads another dropper from its C2 server.[FireEye APT28]
Exact relationship: relationship--e41ab3e7-2b69-4461-a693-e53a24c9ab59 - S0139 PowerDuke — malware.
PowerDuke has a command to download a file.[Volexity PowerDuke November 2016]
Exact relationship: relationship--8ef27cd6-3909-4174-b57c-3dbe3061a6dd - S0140 Shamoon — malware.
Shamoon can download an executable to run on the victim.[Palo Alto Shamoon Nov 2016]
Exact relationship: relationship--3ded5760-4f2e-41f5-a2c5-f2b39eaf5733 - S0141 Winnti for Windows — malware.
The Winnti for Windows dropper can place malicious payloads on targeted systems.[Novetta Winnti April 2015]
Exact relationship: relationship--ace0d0ba-7ee5-46cd-be08-2b33d217a13d - S0144 ChChes — malware.
ChChes is capable of downloading files, including additional modules.[Palo Alto menuPass Feb 2017][JPCERT ChChes Feb 2017][FireEye APT10 April 2017]
Exact relationship: relationship--92c901ce-5edb-417f-8af5-d569203e241c - S0145 POWERSOURCE — malware.
POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.[FireEye FIN7 March 2017]
Exact relationship: relationship--d04d6101-f6f6-42a2-8679-351956b75228 - S0147 Pteranodon — malware.
Pteranodon can download and execute additional files.[Palo Alto Gamaredon Feb 2017][Symantec Shuckworm January 2022][Unit 42 Gamaredon February 2022]
Exact relationship: relationship--35ae6625-8563-493c-8950-1230bd0fd122 - S0148 RTM — malware.
RTM can download additional files.[ESET RTM Feb 2017][Unit42 Redaman January 2019]
Exact relationship: relationship--c839344c-a96d-412f-bded-5ac7c8fd446a - S0150 POSHSPY — malware.
POSHSPY downloads and executes additional PowerShell code and Windows binaries.[FireEye POSHSPY April 2017]
Exact relationship: relationship--be31bf6d-ce4f-4620-8940-445f35ff90a7 - S0153 RedLeaves — malware.
RedLeaves is capable of downloading a file from a specified URL.[PWC Cloud Hopper Technical Annex April 2017]
Exact relationship: relationship--f4902ad9-b1bb-41ce-a448-55e2d9437503 - S0154 Cobalt Strike — malware.
Cobalt Strike can deliver additional payloads to victim machines.[Talos Cobalt Strike September 2020][Cobalt Strike Manual 4.3 November 2020]
Exact relationship: relationship--cecb2ce6-cb40-453d-9487-9f59f156a98c - S0160 certutil — tool.
certutil can be used to download files from a given URL.[TechNet Certutil][LOLBAS Certutil]
Exact relationship: relationship--73f5c564-53b1-48bc-8cab-32fa4a608672 - S0164 TDTESS — malware.
TDTESS has a command to download and execute an additional file.[ClearSky Wilted Tulip July 2017]
Exact relationship: relationship--af4d45e1-1aa4-444c-b176-31df7aaf9374 - S0166 RemoteCMD — malware.
RemoteCMD copies a file over to the remote system before execution.[Symantec Buckeye]
Exact relationship: relationship--b3831788-f18f-4315-997e-275e425c0d31 - S0168 Gazer — malware.
Gazer can execute a task to download a file.[ESET Gazer Aug 2017][Securelist WhiteBear Aug 2017]
Exact relationship: relationship--8db1b5bd-8f0c-4c13-8667-c83713ce799e - S0170 Helminth — malware.
Helminth can download additional files.[Palo Alto OilRig May 2016]
Exact relationship: relationship--86b2980a-dd9f-4553-8f65-69f75f0f4332 - S0171 Felismus — malware.
Felismus can download files from remote servers.[Forcepoint Felismus Mar 2017]
Exact relationship: relationship--e9011839-ca57-434d-a0cc-007594247110 - S0180 Volgmer — malware.
Volgmer can download remote files and additional payloads to the victim's machine.[US-CERT Volgmer Nov 2017][US-CERT Volgmer 2 Nov 2017][Symantec Volgmer Aug 2014]
Exact relationship: relationship--720cc0d6-9285-425b-bda2-3bdd59b4ea8f - S0184 POWRUNER — malware.
POWRUNER can download or upload files from its C2 server.[FireEye APT34 Dec 2017]
Exact relationship: relationship--c4d77981-d2e4-4a12-8e52-5b7464cdc8fd - S0185 SEASHARPEE — malware.
SEASHARPEE can download remote files onto victims.[FireEye APT34 Webinar Dec 2017]
Exact relationship: relationship--04ecc705-0027-4dda-85fe-d6ce028ef05e - S0187 Daserf — malware.
Daserf can download remote files.[Trend Micro Daserf Nov 2017][Secureworks BRONZE BUTLER Oct 2017]
Exact relationship: relationship--24503815-4ac5-4d57-9e95-ebeb84e0c11b - S0190 BITSAdmin — tool.
BITSAdmin can be used to create BITS Jobs to upload and/or download files.[Microsoft BITSAdmin]
Exact relationship: relationship--9edfa8b5-2e9f-4022-93b2-fd819156fe95 - S0192 Pupy — tool.
Pupy can upload and download to/from a victim machine.[GitHub Pupy]
Exact relationship: relationship--151dd9ac-7e33-4580-a4a4-09f71fa73f51 - S0196 PUNCHBUGGY — malware.
PUNCHBUGGY can download additional files and payloads to compromised hosts.[FireEye Know Your Enemy FIN8 Aug 2016][Morphisec ShellTea June 2019]
Exact relationship: relationship--8e7887b3-f622-4860-9bda-3f4ab6231393 - S0198 NETWIRE — malware.
NETWIRE can downloaded payloads from C2 to the compromised host.[FireEye NETWIRE March 2019][Proofpoint NETWIRE December 2020]
Exact relationship: relationship--f4ea1985-0e88-488d-b7ed-ac294719738a - S0199 TURNEDUP — malware.
TURNEDUP is capable of downloading additional files.[FireEye APT33 Sept 2017]
Exact relationship: relationship--1251d1e2-21d3-48f2-a869-44507b34943a - S0200 Dipsind — malware.
Dipsind can download remote files.[Microsoft PLATINUM April 2016]
Exact relationship: relationship--2a2b6def-5d29-41f7-b274-64bed33eb8ed - S0201 JPIN — malware.
JPIN can download files and upgrade itself.[Microsoft PLATINUM April 2016]
Exact relationship: relationship--74c1fa45-5ac3-47a0-a442-2cc5e89f7b4c - S0203 Hydraq — malware.
Hydraq creates a backdoor through which remote attackers can download files and additional malware components.[Symantec Trojan.Hydraq Jan 2010][Symantec Hydraq Jan 2010]
Exact relationship: relationship--5d914544-0a93-43ba-b890-1f4a4fa818e8 - S0204 Briba — malware.
Briba downloads files onto infected hosts.[Symantec Briba May 2012]
Exact relationship: relationship--36755c7d-92bf-4851-91ef-f1bf41f27210 - S0206 Wiarp — malware.
Wiarp creates a backdoor through which remote attackers can download files.[Symantec Wiarp May 2012]
Exact relationship: relationship--0f7e7dc5-ea9c-4d9e-9acd-5fa0dd25910a - S0207 Vasport — malware.
Vasport can download files.[Symantec Vasport May 2012]
Exact relationship: relationship--0e8a0760-f21e-4936-80a1-769c7ef61950 - S0208 Pasam — malware.
Pasam creates a backdoor through which remote attackers can upload files.[Symantec Pasam May 2012]
Exact relationship: relationship--80383098-470f-4293-b4b1-90c4362be307 - S0210 Nerex — malware.
Nerex creates a backdoor through which remote attackers can download files onto a compromised host.[Symantec Ristol May 2012]
Exact relationship: relationship--107e2686-a764-4ace-9200-43ead29ce579 - S0211 Linfo — malware.
Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.[Symantec Linfo May 2012]
Exact relationship: relationship--5c08eb3a-d7a0-4ce0-97a2-496ea4c9f3ed - S0213 DOGCALL — malware.
DOGCALL can download and execute additional payloads.[Unit 42 Nokki Oct 2018]
Exact relationship: relationship--8f41386c-5760-409e-b8b4-513f3d791d9f - S0214 HAPPYWORK — malware.
can download and execute a second-stage payload.[FireEye APT37 Feb 2018]
Exact relationship: relationship--72ac0ee1-24c0-4b4e-b96d-f42575ce9af8 - S0215 KARAE — malware.
KARAE can upload and download files, including second-stage malware.[FireEye APT37 Feb 2018]
Exact relationship: relationship--2fa47765-a47e-430b-9a88-68db5795f557 - S0217 SHUTTERSPEED — malware.
SHUTTERSPEED can download and execute an arbitary executable.[FireEye APT37 Feb 2018]
Exact relationship: relationship--c4cbbe25-bc29-406d-b92e-6e50ee4cd322 - S0218 SLOWDRIFT — malware.
SLOWDRIFT downloads additional payloads.[FireEye APT37 Feb 2018]
Exact relationship: relationship--4c5ae895-9a08-40b6-a548-273a9f96ad5b - S0223 POWERSTATS — malware.
POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.[FireEye MuddyWater Mar 2018]
Exact relationship: relationship--ce7b27ac-fff6-4d3c-bceb-50c16f462552 - S0226 Smoke Loader — malware.
Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.[Malwarebytes SmokeLoader 2016]
Exact relationship: relationship--4bb79228-9531-47c0-8e73-401e741593a8 - S0228 NanHaiShu — malware.
NanHaiShu can download additional files from URLs.[Proofpoint Leviathan Oct 2017]
Exact relationship: relationship--484add44-6a43-4700-b1bc-d64f24157353 - S0229 Orz — malware.
Orz can download files onto the victim.[Proofpoint Leviathan Oct 2017]
Exact relationship: relationship--73db6a54-2270-431b-b7eb-2c5c71389637 - S0230 ZeroT — malware.
ZeroT can download additional payloads onto the victim.[Proofpoint ZeroT Feb 2017]
Exact relationship: relationship--bff3220c-6fea-4925-a9d0-46f06efb7337 - S0234 Bandook — malware.
Bandook can download files to the system.[CheckPoint Bandook Nov 2020]
Exact relationship: relationship--47afdb05-0327-4feb-b80e-1be491b57693 - S0236 Kwampirs — malware.
Kwampirs downloads additional files from C2 servers.[Symantec Security Center Trojan.Kwampirs]
Exact relationship: relationship--9b102737-2d47-4dd5-b4f2-2a323c506cfb - S0239 Bankshot — malware.
Bankshot uploads files and secondary payloads to the victim's machine.[US-CERT Bankshot Dec 2017]
Exact relationship: relationship--a15e391d-cc21-484d-839a-b7057ae40179 - S0240 ROKRAT — malware.
ROKRAT can retrieve additional malicious payloads from its C2 server.[Talos ROKRAT][NCCGroup RokRat Nov 2018][Volexity InkySquid RokRAT August 2021][Malwarebytes RokRAT VBA January 2021]
Exact relationship: relationship--921b3245-0795-40cd-82e1-04f38bc42b14 - S0241 RATANKBA — malware.
RATANKBA uploads and downloads information.[Lazarus RATANKBA][RATANKBA]
Exact relationship: relationship--d8d6740b-a359-4f5c-b7d4-2189eea77892 - S0247 NavRAT — malware.
NavRAT can download files remotely.[Talos NavRAT May 2018]
Exact relationship: relationship--5b48c2b1-0ce7-4856-9bc7-ae359826550c - S0249 Gold Dragon — malware.
Gold Dragon can download additional components from the C2 server.[McAfee Gold Dragon]
Exact relationship: relationship--47880b58-f0e2-4898-a218-6df6333329ed - S0250 Koadic — tool.
Koadic can download additional files and tools.[Github Koadic][MalwareBytes LazyScripter Feb 2021]
Exact relationship: relationship--419392f5-e6a8-4eee-b7c2-f0bac5cce833 - S0251 Zebrocy — malware.
Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.[Palo Alto Sofacy 06-2018][Unit42 Cannon Nov 2018][ESET Zebrocy May 2019][Accenture SNAKEMACKEREL Nov 2018]
Exact relationship: relationship--24bf6b49-b492-44b0-bcc9-37bfba489d62 - S0254 PLAINTEE — malware.
PLAINTEE has downloaded and executed additional plugins.[Rancor Unit42 June 2018]
Exact relationship: relationship--fdea1dc1-4b00-411e-a5d3-cd72688237b5 - S0255 DDKONG — malware.
DDKONG downloads and uploads files on the victim’s machine.[Rancor Unit42 June 2018]
Exact relationship: relationship--083cbf6f-82e3-4d78-b18f-aa2d1f566713 - S0256 Mosquito — malware.
Mosquito can upload and download files to the victim.[ESET Turla Mosquito Jan 2018]
Exact relationship: relationship--6d17cbbf-dd7e-456c-ad9e-e084c95efdaf - S0257 VERMIN — malware.
VERMIN can download and upload files to the victim's machine.[Unit 42 VERMIN Jan 2018]
Exact relationship: relationship--d68649d8-4f18-48b8-93b8-82c8660fc464 - S0258 RGDoor — malware.
RGDoor uploads and downloads files to and from the victim’s machine.[Unit 42 RGDoor Jan 2018]
Exact relationship: relationship--ee03d4e8-79e5-408f-a533-462774da46ed - S0260 InvisiMole — malware.
InvisiMole can upload files to the victim's machine for operations.[ESET InvisiMole June 2018][ESET InvisiMole June 2020]
Exact relationship: relationship--b7760f6b-9b57-4fa8-895a-4f4a209aa366 - S0262 QuasarRAT — tool.
QuasarRAT can download files to the victim’s machine and execute them.[GitHub QuasarRAT][Volexity Patchwork June 2018]
Exact relationship: relationship--4a33da76-c838-48fe-97ad-80d285cf165f - S0263 TYPEFRAME — malware.
TYPEFRAME can upload and download files to the victim’s machine.[US-CERT TYPEFRAME June 2018]
Exact relationship: relationship--42914dfa-9644-4bf6-bb5f-45c0e3303d7b - S0264 OopsIE — malware.
OopsIE can download files from its C2 server to the victim's machine.[Unit 42 OopsIE! Feb 2018][Unit 42 OilRig Sept 2018]
Exact relationship: relationship--978dbb17-c5c5-4248-8385-9dc6f691030b - S0265 Kazuar — malware.
Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.[Unit 42 Kazuar May 2017]
Exact relationship: relationship--2286857e-ad96-4dda-abac-988e8cadda5c - S0266 TrickBot — malware.
TrickBot downloads several additional files and saves them to the victim's machine.[Trend Micro Totbrick Oct 2016][Bitdefender Trickbot VNC module Whitepaper 2021]
Exact relationship: relationship--d8e0ed13-7938-4c9c-99ef-511b8dbf76aa - S0267 FELIXROOT — malware.
FELIXROOT downloads and uploads files to and from the victim’s machine.[FireEye FELIXROOT July 2018][ESET GreyEnergy Oct 2018]
Exact relationship: relationship--e4c5ab65-e084-4844-9bf8-546d78f20e96 - S0268 Bisonal — malware.
Bisonal has the capability to download files to execute on the victim’s machine.[Unit 42 Bisonal July 2018][Kaspersky CactusPete Aug 2020][Talos Bisonal Mar 2020]
Exact relationship: relationship--1b95cd32-155b-488d-bbf8-e16f22e2a1d5 - S0270 RogueRobin — malware.
RogueRobin can save a new file to the system from the C2 server.[Unit 42 DarkHydrus July 2018][Unit42 DarkHydrus Jan 2019]
Exact relationship: relationship--2227a2ce-2eda-4fe3-a9ca-524e0de0ded2 - S0271 KEYMARBLE — malware.
KEYMARBLE can upload files to the victim’s machine and can download additional payloads.[US-CERT KEYMARBLE Aug 2018]
Exact relationship: relationship--30efb3df-f7b4-47f8-9c5a-53a94509c929 - S0272 NDiskMonitor — malware.
NDiskMonitor can download and execute a file from given URL.[TrendMicro Patchwork Dec 2017]
Exact relationship: relationship--34d105a6-47ac-4a8b-b892-6f630cd97096 - S0274 Calisto — malware.
Calisto has the capability to upload and download files to the victim's machine.[Symantec Calisto July 2018]
Exact relationship: relationship--406257ac-ff42-4e15-b72e-50202e38b675 - S0275 UPPERCUT — malware.
UPPERCUT can download and upload files to and from the victim’s machine.[FireEye APT10 Sept 2018][Trend Micro Earth Kasha Updates APR 2025][Trend Micro Earth Kasha Anel NOV 2024]
Exact relationship: relationship--a2ad2bea-4359-47a8-ae5f-f18beab07316 - S0283 jRAT — malware.
jRAT can download and execute files.[jRAT Symantec Aug 2018][Kaspersky Adwind Feb 2016][Symantec Frutas Feb 2013]
Exact relationship: relationship--730190b3-d372-4461-9bf4-94de4c078968 - S0284 More_eggs — malware.
More_eggs can download and launch additional payloads.[Talos Cobalt Group July 2018][Security Intelligence More Eggs Aug 2019]
Exact relationship: relationship--0485006f-c4f6-4657-85a0-6beec8d9368a - S0330 Zeus Panda — malware.
Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.[GDATA Zeus Panda June 2017]
Exact relationship: relationship--4c0f441f-13b1-4b79-b658-e081d5143a94 - S0331 Agent Tesla — malware.
Agent Tesla can download additional files for execution on the victim’s machine.[Talos Agent Tesla Oct 2018][DigiTrust Agent Tesla Jan 2017]
Exact relationship: relationship--40ae8100-d02c-445a-acf5-8e30f04ec6c0 - S0332 Remcos — tool.
Remcos can upload and download files to and from the victim’s machine.[Riskiq Remcos Jan 2018][Fortinet Remcos Campaign NOV 2024]
Exact relationship: relationship--ad787fb5-9d63-423d-941f-bfe7648b2e24 - S0333 UBoatRAT — malware.
UBoatRAT can upload and download files to the victim’s machine.[PaloAlto UBoatRAT Nov 2017]
Exact relationship: relationship--ebf44df8-d7c7-4c95-87f0-e31f88b83c72 - S0334 DarkComet — malware.
DarkComet can load any files onto the infected machine to execute.[TrendMicro DarkComet Sept 2014][Malwarebytes DarkComet March 2018]
Exact relationship: relationship--75f88090-55cb-4b3b-84af-cf51058c3ccc - S0336 NanoCore — malware.
NanoCore has the capability to download and activate additional modules for execution.[DigiTrust NanoCore Jan 2017][PaloAlto NanoCore Feb 2016]
Exact relationship: relationship--10806c6b-100d-456b-bb05-62d90713be64 - S0337 BadPatch — malware.
BadPatch can download and execute or update malware.[Unit 42 BadPatch Oct 2017]
Exact relationship: relationship--91eab726-0a0c-4898-8376-66987fd1037c - S0339 Micropsia — malware.
Micropsia can download and execute an executable from the C2 server.[Talos Micropsia June 2017][Radware Micropsia July 2018]
Exact relationship: relationship--7ec1ddbb-57d1-4530-97d1-dd5d02cd3eb2 - S0340 Octopus — malware.
Octopus can download additional files and tools onto the victim’s machine.[Securelist Octopus Oct 2018][Security Affairs DustSquad Oct 2018][ESET Nomadic Octopus 2018]
Exact relationship: relationship--c77d6f2a-664e-4bbb-bf86-c2c58adbdc84 - S0341 Xbash — malware.
Xbash can download additional malicious files from its C2 server.[Unit42 Xbash Sept 2018]
Exact relationship: relationship--809ffec1-52a1-45a5-b410-049352b99700 - S0342 GreyEnergy — malware.
GreyEnergy can download additional modules and payloads.[ESET GreyEnergy Oct 2018]
Exact relationship: relationship--a21e7dd8-9194-4c09-870c-11f44f391838 - S0344 Azorult — malware.
Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.[Unit42 Azorult Nov 2018][Proofpoint Azorult July 2018]
Exact relationship: relationship--6dbac0dd-ebd3-49dc-bbef-d5a7fd464e02 - S0345 Seasalt — malware.
Seasalt has a command to download additional files.[Mandiant APT1 Appendix][Mandiant APT1 Appendix]
Exact relationship: relationship--75f47e28-75dd-4471-8d00-ed4a2c4d3328 - S0347 AuditCred — malware.
AuditCred can download files and additional malware.[TrendMicro Lazarus Nov 2018]
Exact relationship: relationship--4d23c95c-366e-464c-b41c-64e48f4e166a - S0348 Cardinal RAT — malware.
Cardinal RAT can download and execute additional payloads.[PaloAlto CardinalRat Apr 2017]
Exact relationship: relationship--2e83c5c4-76f3-46a3-980f-0063069671cf - S0351 Cannon — malware.
Cannon can download a payload for execution.[Unit42 Cannon Nov 2018]
Exact relationship: relationship--f315cbb6-e49c-4820-99cb-262d36acf17f - S0352 OSX_OCEANLOTUS.D — malware.
OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.[TrendMicro MacOS April 2018][Trend Micro MacOS Backdoor November 2020]
Exact relationship: relationship--5cb54f4b-f615-44ad-94d6-136ff507c2d6 - S0353 NOKKI — malware.
NOKKI has downloaded a remote module for execution.[Unit 42 NOKKI Sept 2018]
Exact relationship: relationship--65384e27-6d16-4d25-a17b-3d74dde8f224 - S0354 Denis — malware.
Denis deploys additional backdoors and hacking tools to the system.[Cybereason Cobalt Kitty 2017]
Exact relationship: relationship--117ecbd3-b4cd-4ad2-a5f4-30ba79563406 - S0356 KONNI — malware.
KONNI can download files and execute them on the victim’s machine.[Talos Konni May 2017][Malwarebytes Konni Aug 2021]
Exact relationship: relationship--8720f2bc-c099-4d2c-a9b4-faf019bf55a4 - S0360 BONDUPDATER — malware.
BONDUPDATER can download or upload files from its C2 server.[Palo Alto OilRig Sep 2018]
Exact relationship: relationship--dd4a0bb3-b9f0-4d69-9768-a17d95783398 - S0363 Empire — tool.
Empire can upload and download to and from a victim machine.[Github PowerShell Empire]
Exact relationship: relationship--efd94521-6d23-4947-a257-1c81ac52f0d9 - S0367 Emotet — malware.
Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.[Pincus Emotet 2020]
Exact relationship: relationship--622ba39c-2f40-4605-81ce-ef04cea95808 - S0369 CoinTicker — malware.
CoinTicker executes a Python script to download its second stage.[CoinTicker 2019]
Exact relationship: relationship--9a5f9534-a2a4-402e-89bd-d014c2fba224 - S0373 Astaroth — malware.
Astaroth uses certutil and BITSAdmin to download additional malware. [Cofense Astaroth Sept 2018][Cybereason Astaroth Feb 2019][Securelist Brazilian Banking Malware July 2020]
Exact relationship: relationship--ad731b3e-709e-49d0-a501-6fe69f78a428 - S0374 SpeakUp — malware.
SpeakUp downloads and executes additional files from a remote server. [CheckPoint SpeakUp Feb 2019]
Exact relationship: relationship--1c3d2111-f234-4624-999e-ce902367c212 - S0376 HOPLIGHT — malware.
HOPLIGHT has the ability to connect to a remote host in order to upload and download files.[US-CERT HOPLIGHT Apr 2019]
Exact relationship: relationship--b4349e95-eeff-4784-8a7d-2c6d60a734dd - S0379 Revenge RAT — malware.
Revenge RAT has the ability to upload and download files.[Cylance Shaheen Nov 2018]
Exact relationship: relationship--1f5aee41-e3bc-4ed0-a0e2-fa8f7cd6de26 - S0380 StoneDrill — malware.
StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.[Kaspersky StoneDrill 2017]
Exact relationship: relationship--10974f3d-30fc-4ab6-b691-21acff792a05 - S0381 FlawedAmmyy — malware.
FlawedAmmyy can transfer files from C2.[Korean FSI TA505 2020]
Exact relationship: relationship--9f43174e-9fec-447c-b5d9-12b348447853 - S0382 ServHelper — malware.
ServHelper may download additional files to execute.[Proofpoint TA505 Jan 2019][Deep Instinct TA505 Apr 2019]
Exact relationship: relationship--435f910b-21a6-4814-b167-5262ca1e1e58 - S0385 njRAT — malware.
njRAT can download files to the victim’s machine.[Fidelis njRAT June 2013][Trend Micro njRAT 2018] APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.[Kaspersky BlindEagle AUG 2024]
Exact relationship: relationship--168ab4a2-db4d-4d64-9951-6547145aabe6 - S0386 Ursnif — malware.
Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.[TrendMicro PE_URSNIF.A2][TrendMicro BKDR_URSNIF.SM]
Exact relationship: relationship--0d88d99d-88b0-4e49-b2c3-3607a32069ed - S0387 KeyBoy — malware.
KeyBoy has a download and upload functionality.[PWC KeyBoys Feb 2017][Rapid7 KeyBoy Jun 2013]
Exact relationship: relationship--8833fac6-778f-4cf8-8b2a-6dee29164ffa - S0388 YAHOYAH — malware.
YAHOYAH uses HTTP GET requests to download other files that are executed in memory.[TrendMicro TropicTrooper 2015]
Exact relationship: relationship--1729ebeb-c92c-4d8e-a859-0d081b3821a1 - S0390 SQLRat — malware.
SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.[Flashpoint FIN 7 March 2019]
Exact relationship: relationship--1cfc5611-b428-4fce-8b8d-f591523c9d9c - S0394 HiddenWasp — malware.
HiddenWasp downloads a tar compressed archive from a download server to the system.[Intezer HiddenWasp Map 2019]
Exact relationship: relationship--bf66a7c4-7d72-4769-a96a-83d3363fa7a9 - S0395 LightNeuron — malware.
LightNeuron has the ability to download and execute additional files.[ESET LightNeuron May 2019]
Exact relationship: relationship--80cc26ad-62b5-49f0-bb8d-bd588bd51585 - S0396 EvilBunny — malware.
EvilBunny has downloaded additional Lua scripts from the C2.[Cyphort EvilBunny Dec 2014]
Exact relationship: relationship--0109ee05-c2a9-4dcf-80d1-f859500c97c9 - S0398 HyperBro — malware.
HyperBro has the ability to download additional files.[Unit42 Emissary Panda May 2019]
Exact relationship: relationship--c96b0cbe-7523-4ee6-ae73-b6a8cba3ea44 - S0401 Exaramel for Linux — malware.
Exaramel for Linux has a command to download a file from and to a remote C2 server.[ESET TeleBots Oct 2018][ANSSI Sandworm January 2021]
Exact relationship: relationship--15bb2796-7c6d-4d03-8d86-8d83254bcf0b - S0402 OSX/Shlayer — malware.
OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the <code>curl -fsL "$url" >$tmp_path</code> command to download malicious payloads into a temporary directory.[Carbon Black Shlayer Feb 2019][sentinelone shlayer to zshlayer][20 macOS Common Tools and Techniques][objectivesee osx.shlayer apple approved 2020]
Exact relationship: relationship--bd79d063-3407-4da9-b6d1-6170a3b9edfc - S0404 esentutl — tool.
esentutl can be used to copy files from a given URL.[LOLBAS Esentutl]
Exact relationship: relationship--bb4f1b15-8382-44f9-b201-6726e83b79b0 - S0409 Machete — malware.
Machete can download additional files for execution on the victim’s machine.[ESET Machete July 2019]
Exact relationship: relationship--9901b17d-551e-4971-9ff7-7142e7c2bb4e - S0412 ZxShell — malware.
ZxShell has a command to transfer files from a remote host.[Talos ZxShell Oct 2014]
Exact relationship: relationship--ffffed15-5695-44b9-b85b-89ba8187415d - S0414 BabyShark — malware.
BabyShark has downloaded additional files from the C2.[Unit42 BabyShark Apr 2019][CISA AA20-301A Kimsuky]
Exact relationship: relationship--18d97b33-8ad5-426e-a390-72bea109bee0 - S0428 PoetRAT — malware.
PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.[Talos PoetRAT April 2020][Talos PoetRAT October 2020]
Exact relationship: relationship--3337112a-0b29-450f-9183-a0ec428c4898 - S0430 Winnti for Linux — malware.
Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host. [Chronicle Winnti for Linux May 2019]
Exact relationship: relationship--90925137-7ffe-46d6-82d4-0ad7748740a3 - S0431 HotCroissant — malware.
HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.[Carbon Black HotCroissant April 2020]
Exact relationship: relationship--967c2498-0f51-464f-b5e5-2a0539614033 - S0435 PLEAD — malware.
PLEAD has the ability to upload and download files to and from an infected host.[JPCert PLEAD Downloader June 2018]
Exact relationship: relationship--9020d567-103b-4dc2-b27d-115078ae2a76 - S0436 TSCookie — malware.
TSCookie has the ability to upload and download files to and from the infected host.[JPCert TSCookie March 2018]
Exact relationship: relationship--1e54c837-6d59-40dc-a114-3bcef0037327 - S0437 Kivars — malware.
Kivars has the ability to download and execute files.[TrendMicro BlackTech June 2017]
Exact relationship: relationship--93dc6241-29b4-45c6-9593-f7862936ffd8 - S0438 Attor — malware.
Attor can download additional plugins, updates and other files. [ESET Attor Oct 2019]
Exact relationship: relationship--57a19f3b-838f-45df-8cfe-964cbe5396d2 - S0439 Okrum — malware.
Okrum has built-in commands for uploading, downloading, and executing files to the system.[ESET Okrum July 2019]
Exact relationship: relationship--140dda5e-b3d5-47ce-aac5-22060d5bddf2 - S0442 VBShower — malware.
VBShower has the ability to download VBS files to the target computer.[Kaspersky Cloud Atlas August 2019]
Exact relationship: relationship--fe3b8cb8-8ff1-4abf-ac98-ce31108e5bb5 - S0444 ShimRat — malware.
ShimRat can download additional files.[FOX-IT May 2016 Mofang]
Exact relationship: relationship--0177d430-a0b9-4f2f-8c66-8dfa4391611a - S0445 ShimRatReporter — tool.
ShimRatReporter had the ability to download additional payloads.[FOX-IT May 2016 Mofang]
Exact relationship: relationship--137f13ee-0607-47ba-952b-dbe39c1330bb - S0447 Lokibot — malware.
Lokibot downloaded several staged items onto the victim's machine.[Talos Lokibot Jan 2021]
Exact relationship: relationship--f7328802-07f4-4f00-821a-962fb2678e15 - S0450 SHARPSTATS — malware.
SHARPSTATS has the ability to upload and download files.[TrendMicro POWERSTATS V3 June 2019]
Exact relationship: relationship--8f0afd2b-8cb3-4b5b-b19f-39887602fe95 - S0451 LoudMiner — malware.
LoudMiner used SCP to update the miner from the C2.[ESET LoudMiner June 2019]
Exact relationship: relationship--8f43b5c3-883a-40b7-b9b2-a96ba8c7001b - S0453 Pony — malware.
Pony can download additional files onto the infected system.[Malwarebytes Pony April 2016]
Exact relationship: relationship--3ea6e72b-3d19-4864-aebd-cc31dad7d519 - S0455 Metamorfo — malware.
Metamorfo has used MSI files to download additional files to execute.[Medium Metamorfo Apr 2020][FireEye Metamorfo Apr 2018][Fortinet Metamorfo Feb 2020][ESET Casbaneiro Oct 2019]
Exact relationship: relationship--de745ef4-59a0-470c-95c9-5043a717dc54 - S0456 Aria-body — malware.
Aria-body has the ability to download additional payloads from C2.[CheckPoint Naikon May 2020]
Exact relationship: relationship--cbb686ae-3dc8-4e91-80fc-075209505425 - S0457 Netwalker — malware.
Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.[Sophos Netwalker May 2020]
Exact relationship: relationship--ed0e96e6-6b71-468a-9e76-477ed3765ca4 - S0459 MechaFlounder — malware.
MechaFlounder has the ability to upload and download files to and from a compromised host.[Unit 42 MechaFlounder March 2019]
Exact relationship: relationship--b96089fa-ebca-4d3c-9290-473cb98ad577 - S0461 SDBbot — malware.
SDBbot has the ability to download a DLL from C2 to a compromised host.[Proofpoint TA505 October 2019]
Exact relationship: relationship--7ef04aca-4890-4035-8c0b-69d9a78e8029 - S0462 CARROTBAT — malware.
CARROTBAT has the ability to download and execute a remote file via certutil.[Unit 42 CARROTBAT November 2018]
Exact relationship: relationship--9e81f24e-6f72-44eb-9f19-2a3e7dca14ad - S0465 CARROTBALL — tool.
CARROTBALL has the ability to download and install a remote payload.[Unit 42 CARROTBAT January 2020]
Exact relationship: relationship--6d5221c3-2efa-4374-8842-8c955fda112b - S0468 Skidmap — malware.
Skidmap has the ability to download files on an infected host.[Trend Micro Skidmap]
Exact relationship: relationship--1eb0fe9c-86e9-4c8c-8a24-c7b139559971 - S0469 ABK — malware.
ABK has the ability to download files from C2.[Trend Micro Tick November 2019]
Exact relationship: relationship--9ffa4f56-8fe5-4439-897d-df432bccb52d - S0470 BBK — malware.
BBK has the ability to download files from C2 to the infected host.[Trend Micro Tick November 2019]
Exact relationship: relationship--576db5e8-7371-4dea-ada9-599cc231e727 - S0471 build_downer — malware.
build_downer has the ability to download files from C2 to the infected host.[Trend Micro Tick November 2019]
Exact relationship: relationship--d870ed48-a7df-4aee-af06-c58ee59432e7 - S0472 down_new — malware.
down_new has the ability to download files to the compromised host.[Trend Micro Tick November 2019]
Exact relationship: relationship--0efece7a-dc3a-46e1-b56c-7db9e3b61149 - S0473 Avenger — malware.
Avenger has the ability to download files from C2 to a compromised host.[Trend Micro Tick November 2019]
Exact relationship: relationship--96c91811-fec3-43a6-890f-08921e543325 - S0475 BackConfig — malware.
BackConfig can download and execute additional payloads on a compromised host.[Unit 42 BackConfig May 2020]
Exact relationship: relationship--197ade21-6787-4ed3-a3ce-ff4b59b2f15c - S0476 Valak — malware.
Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.[Unit 42 Valak July 2020][Cybereason Valak May 2020]
Exact relationship: relationship--86ce6e35-bf83-4d55-a3c8-3ac2e2d2f872 - S0482 Bundlore — malware.
Bundlore can download and execute new versions of itself.[MacKeeper Bundlore Apr 2019]
Exact relationship: relationship--6b69d848-b3d9-4f8f-96dc-381e1dd793d4 - S0483 IcedID — malware.
IcedID has the ability to download additional modules and a configuration file from C2.[IBM IcedID November 2017][Juniper IcedID June 2020][DFIR_Quantum_Ransomware][Latrodectus APR 2024]
Exact relationship: relationship--a8484e9d-ad08-4d2c-8328-24552dd22f35 - S0484 Carberp — malware.
Carberp can download and execute new plugins from the C2 server. [Prevx Carberp March 2011][Trusteer Carberp October 2010]
Exact relationship: relationship--320966af-53db-41e3-aaf0-f5fd68bce8ca - S0486 Bonadan — malware.
Bonadan can download additional modules from the C2 server.[ESET ForSSHe December 2018]
Exact relationship: relationship--db2b0471-38e9-4c50-bf96-1c498f38223c - S0487 Kessel — malware.
Kessel can download additional modules from the C2 server.[ESET ForSSHe December 2018]
Exact relationship: relationship--25f5e7b1-4f7f-48e1-b647-16a4ac018357 - S0491 StrongPity — malware.
StrongPity can download files to specified targets.[Bitdefender StrongPity June 2020]
Exact relationship: relationship--c7cf767a-fa78-4ca7-9bd1-612d51d0c098 - S0492 CookieMiner — malware.
CookieMiner can download additional scripts from a web server.[Unit42 CookieMiner Jan 2019]
Exact relationship: relationship--7f249ef4-8a3c-4ab5-998f-256ac8ecf588 - S0493 GoldenSpy — malware.
GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system.[Trustwave GoldenSpy June 2020]
Exact relationship: relationship--b6d77871-1b71-4b65-b04b-9ee1d4b80a9c - S0495 RDAT — malware.
RDAT can download files via DNS.[Unit42 RDAT July 2020]
Exact relationship: relationship--abca8fe1-0303-43a8-b469-a7921358a3f1 - S0496 REvil — malware.
REvil can download a copy of itself from an attacker controlled IP address to the victim machine.[Talos Sodinokibi April 2019][McAfee Sodinokibi October 2019][Picus Sodinokibi January 2020]
Exact relationship: relationship--a910e0f8-1548-4dd6-a0eb-19430a5f75b0 - S0497 Dacls — malware.
Dacls can download its payload from a C2 server.[SentinelOne Lazarus macOS July 2020][TrendMicro macOS Dacls May 2020]
Exact relationship: relationship--38affc70-544f-4211-be66-0d09f7882edb - S0498 Cryptoistic — malware.
Cryptoistic has the ability to send and receive files.[SentinelOne Lazarus macOS July 2020]
Exact relationship: relationship--dc802d43-a21f-4871-a281-4896817b9bc1 - S0499 Hancitor — malware.
Hancitor has the ability to download additional files from C2.[Threatpost Hancitor]
Exact relationship: relationship--3d902953-306b-48d4-be7b-f08030ecb62e - S0500 MCMD — tool.
MCMD can upload additional files to a compromised host.[Secureworks MCMD July 2019]
Exact relationship: relationship--ceaf4145-f168-4bba-8480-d3650bcc657f - S0501 PipeMon — malware.
PipeMon can install additional modules via C2 commands.[ESET PipeMon May 2020]
Exact relationship: relationship--3e18f486-1e6f-49fa-8b99-4daf615d3e8d - S0502 Drovorub — malware.
Drovorub can download files to a compromised host.[NSA/FBI Drovorub August 2020]
Exact relationship: relationship--f3b7dbe2-1dd5-4d57-a5ef-1764775d5c99 - S0504 Anchor — malware.
Anchor can download additional payloads.[Cyberreason Anchor December 2019][Medium Anchor DNS July 2020]
Exact relationship: relationship--116996cd-b855-4730-814d-869fd90e7ce1 - S0511 RegDuke — malware.
RegDuke can download files from C2.[ESET Dukes October 2019]
Exact relationship: relationship--342b69ad-118b-467d-838e-33ffa931af29 - S0513 LiteDuke — malware.
LiteDuke has the ability to download files.[ESET Dukes October 2019]
Exact relationship: relationship--a34352d8-8dc9-4721-9e73-ae56f5a886e7 - S0514 WellMess — malware.
WellMess can write files to a compromised host.[PWC WellMess July 2020][CISA WellMess July 2020]
Exact relationship: relationship--6204f142-a2a7-406f-9874-af8f3bb9dca9 - S0515 WellMail — malware.
WellMail can receive data and executable scripts from C2.[CISA WellMail July 2020]
Exact relationship: relationship--05dc9f8c-a1ea-4cdf-ae86-e98af40d5bd7 - S0516 SoreFang — malware.
SoreFang can download additional payloads from C2.[CISA SoreFang July 2016][NCSC APT29 July 2020]
Exact relationship: relationship--0aebf9e4-9730-45ce-877d-f78432c13fad - S0518 PolyglotDuke — malware.
PolyglotDuke can retrieve payloads from the C2 server.[ESET Dukes October 2019]
Exact relationship: relationship--28d3336f-108b-40fb-b3d7-9ec4311931c4 - S0520 BLINDINGCAN — malware.
BLINDINGCAN has downloaded files to a victim machine.[US-CERT BLINDINGCAN Aug 2020]
Exact relationship: relationship--1c33c9cd-afac-490a-b487-bd97c93a14cc - S0526 KGH_SPY — malware.
KGH_SPY has the ability to download and execute code from remote servers.[Cybereason Kimsuky November 2020]
Exact relationship: relationship--8f55bbbb-7404-4872-9832-c884297cdbe9 - S0527 CSPY Downloader — tool.
CSPY Downloader can download additional tools to a compromised host.[Cybereason Kimsuky November 2020]
Exact relationship: relationship--6213e3cf-c18e-47de-b281-07aa3c3179db - S0528 Javali — malware.
Javali can download payloads from remote C2 servers.[Securelist Brazilian Banking Malware July 2020]
Exact relationship: relationship--fe518957-8722-498f-8da0-4b5eca466cef - S0530 Melcoz — malware.
Melcoz has the ability to download additional files to a compromised host.[Securelist Brazilian Banking Malware July 2020]
Exact relationship: relationship--57ad2c1a-785c-46ad-bdf1-2f9afe2389e8 - S0531 Grandoreiro — malware.
Grandoreiro can download its second stage from a hardcoded URL within the loader's code.[IBM Grandoreiro April 2020][ESET Grandoreiro April 2020]
Exact relationship: relationship--213522ec-117d-4ac8-82c7-b297fe7c26b4 - S0532 Lucifer — malware.
Lucifer can download and execute a replica of itself using certutil.[Unit 42 Lucifer June 2020]
Exact relationship: relationship--322a78a2-1765-414f-9b07-29a1360e1134 - S0533 SLOTHFULMEDIA — malware.
SLOTHFULMEDIA has downloaded files onto a victim machine.[CISA MAR SLOTHFULMEDIA October 2020]
Exact relationship: relationship--99f5f421-c462-472c-9aa8-29a4316c3f5e - S0534 Bazar — malware.
Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.[Cybereason Bazar July 2020][Zscaler Bazar September 2020][NCC Group Team9 June 2020][CrowdStrike Wizard Spider October 2020]
Exact relationship: relationship--c646d6ed-e0f6-48b0-a4a3-d52b0a21f250 - S0546 SharpStage — malware.
SharpStage has the ability to download and execute additional payloads via a DropBox API.[Cybereason Molerats Dec 2020][BleepingComputer Molerats Dec 2020]
Exact relationship: relationship--72babf5f-f117-4a1c-a453-6e6c16c355c4 - S0547 DropBook — malware.
DropBook can download and execute additional files.[Cybereason Molerats Dec 2020][BleepingComputer Molerats Dec 2020]
Exact relationship: relationship--867a1701-c263-4582-ad1c-7c0baae2cf23 - S0553 MoleNet — malware.
MoleNet can download additional payloads from the C2.[Cybereason Molerats Dec 2020]
Exact relationship: relationship--cca578fe-fe2d-44ef-bc55-9518f83f1443 - S0554 Egregor — malware.
Egregor has the ability to download files from its C2 server.[Cybereason Egregor Nov 2020][Intrinsec Egregor Nov 2020]
Exact relationship: relationship--87182fef-ddbc-466e-b55b-989f10592d0c - S0559 SUNBURST — malware.
SUNBURST delivered different payloads, including TEARDROP in at least one instance.[FireEye SUNBURST Backdoor December 2020]
Exact relationship: relationship--e83fb711-3ce0-4c6a-a8b2-0efb96551b99 - S0561 GuLoader — malware.
GuLoader can download further malware for execution on the victim's machine.[Medium Eli Salem GuLoader April 2021]
Exact relationship: relationship--9bd2274b-95bc-4b7f-93f5-0b658d256217 - S0564 BlackMould — malware.
BlackMould has the ability to download files to the victim's machine.[Microsoft GALLIUM December 2019]
Exact relationship: relationship--ba8145fd-61d3-4729-a7c8-96216d2e6078 - S0567 Dtrack — malware.
Dtrack’s can download and upload a file to the victim’s computer.[Securelist Dtrack][CyberBit Dtrack]
Exact relationship: relationship--ef463100-ac00-44ab-805b-75e4c8886699 - S0568 EVILNUM — malware.
EVILNUM can download and upload files to the victim's computer.[ESET EvilNum July 2020][Prevailion EvilNum May 2020]
Exact relationship: relationship--b3b6e98e-8d0f-4262-ae61-26c171bf20c6 - S0569 Explosive — malware.
Explosive has a function to download a file to the infected system.[CheckPoint Volatile Cedar March 2015]
Exact relationship: relationship--a4e88205-c591-4bad-9daa-0bf8f6049c57 - S0572 Caterpillar WebShell — malware.
Caterpillar WebShell has a module to download and upload files to the system.[ClearSky Lebanese Cedar Jan 2021]
Exact relationship: relationship--d4dc5fe6-fbfb-4718-8a7f-cd1eca70db61 - S0574 BendyBear — malware.
BendyBear is designed to download an implant from a C2 server.[Unit42 BendyBear Feb 2021]
Exact relationship: relationship--0f55c28a-835f-4a85-a733-8fac5b819dcf - S0579 Waterbear — malware.
Waterbear can receive and load executables from remote C2 servers.[Trend Micro Waterbear December 2019]
Exact relationship: relationship--5c3a903f-5934-48ec-84da-e88e0d1b4e68 - S0585 Kerrdown — malware.
Kerrdown can download specific payloads to a compromised host based on OS architecture.[Unit 42 KerrDown February 2019]
Exact relationship: relationship--9f57a541-c6d1-490f-bd15-1dee6280365b - S0586 TAINTEDSCRIBE — malware.
TAINTEDSCRIBE can download additional modules from its C2 server.[CISA MAR-10288834-2.v1 TAINTEDSCRIBE MAY 2020]
Exact relationship: relationship--98557068-7d60-40d4-8294-01469aadf6fe - S0587 Penquin — malware.
Penquin can execute the command code <code>do_download</code> to retrieve remote files from C2.[Leonardo Turla Penquin May 2020]
Exact relationship: relationship--729f4b9b-2d25-4e69-9a9b-adaa62c2ee31 - S0588 GoldMax — malware.
GoldMax can download and execute additional files.[MSTIC NOBELIUM Mar 2021][FireEye SUNSHUTTLE Mar 2021]
Exact relationship: relationship--bb1a7fc8-bec0-4655-bbfe-0c786e237452 - S0589 Sibot — malware.
Sibot can download and execute a payload onto a compromised system.[MSTIC NOBELIUM Mar 2021]
Exact relationship: relationship--8fe424be-6873-4b25-a87e-88b2de005d7f - S0592 RemoteUtilities — tool.
RemoteUtilities can upload and download files to and from a target machine.[Trend Micro Muddy Water March 2021]
Exact relationship: relationship--e39a9d68-162f-45a3-b7c2-5914dd900b73 - S0595 ThiefQuest — malware.
ThiefQuest can download and execute payloads in-memory or from disk.[wardle evilquest partii]
Exact relationship: relationship--ea4871e2-8754-4002-9e76-a2c1c0ed7e2f - S0596 ShadowPad — malware.
ShadowPad has downloaded code from a C2 server.[Securelist ShadowPad Aug 2017]
Exact relationship: relationship--f72ffc5a-c872-4b28-b40e-2a3ec85bddcc - S0598 P.A.S. Webshell — malware.
P.A.S. Webshell can upload and download files to and from compromised hosts.[ANSSI Sandworm January 2021]
Exact relationship: relationship--f77760d0-35c1-4e91-98b9-2ac57ba183d5 - S0599 Kinsing — malware.
Kinsing has downloaded additional lateral movement scripts from C2.[Aqua Kinsing April 2020]
Exact relationship: relationship--dd39f1a9-8eb4-4818-8597-ed228d7dba83 - S0600 Doki — malware.
Doki has downloaded scripts from C2.[Intezer Doki July 20]
Exact relationship: relationship--6a556d19-33f1-4b6e-bec3-00ca32dd5df7 - S0601 Hildegard — malware.
Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.[Unit 42 Hildegard Malware]
Exact relationship: relationship--cdd9ae58-bed9-4cce-ad46-d4e96a789ded - S0604 Industroyer — malware.
Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.[ESET Industroyer]
Exact relationship: relationship--4f90d1a5-4903-46d9-95b2-73bb118f8cb9 - S0608 Conficker — malware.
Conficker downloads an HTTP server to the infected machine.[SANS Conficker]
Exact relationship: relationship--fa443fec-23f0-40dd-8a94-06cd19f4eb86 - S0610 SideTwist — malware.
SideTwist has the ability to download additional files.[Check Point APT34 April 2021]
Exact relationship: relationship--6b47884a-47ac-4f0a-9d5b-3c6eb0efd761 - S0613 PS1 — malware.
CostaBricks can download additional payloads onto a compromised host.[BlackBerry CostaRicto November 2020]
Exact relationship: relationship--107f8870-4adf-4f63-acf2-d28677905235 - S0614 CostaBricks — malware.
CostaBricks has been used to load SombRAT onto a compromised host.[BlackBerry CostaRicto November 2020]
Exact relationship: relationship--48652244-02b0-4a80-82a9-b99fca669d85 - S0615 SombRAT — malware.
SombRAT has the ability to download and execute additional payloads.[BlackBerry CostaRicto November 2020][FireEye FiveHands April 2021][CISA AR21-126A FIVEHANDS May 2021]
Exact relationship: relationship--5e6f5555-f7dd-462d-b110-afc28f021be5 - S0616 DEATHRANSOM — malware.
DEATHRANSOM can download files to a compromised host.[FireEye FiveHands April 2021]
Exact relationship: relationship--7bf6a452-db06-4b7a-b177-678fdf841fbf - S0624 Ecipekac — malware.
Ecipekac can download additional payloads to a compromised host.[Securelist APT10 March 2021]
Exact relationship: relationship--eda15dd3-2e7d-470c-8b1d-227c7d877e67 - S0625 Cuba — malware.
Cuba can download files from its C2 server.[McAfee Cuba April 2021]
Exact relationship: relationship--633959b9-383c-486d-9e36-520e5afc502d - S0626 P8RAT — malware.
P8RAT can download additional payloads to a target system.[Securelist APT10 March 2021]
Exact relationship: relationship--96b018b8-701c-4658-b58b-716ba632fd72 - S0627 SodaMaster — malware.
SodaMaster has the ability to download additional payloads from C2 to the targeted system.[Securelist APT10 March 2021]
Exact relationship: relationship--035dca04-cf9e-45ac-a037-f171b06078e6 - S0628 FYAnti — malware.
FYAnti can download additional payloads to a compromised host.[Securelist APT10 March 2021]
Exact relationship: relationship--3b4dc8f1-51c3-41bb-82a7-a877e5618ab7 - S0629 RainyDay — malware.
RainyDay can download files to a compromised host.[Bitdefender Naikon April 2021]
Exact relationship: relationship--2d3a8912-53fd-416b-bef8-f6ad980ae7c0 - S0630 Nebulae — malware.
Nebulae can download files from C2.[Bitdefender Naikon April 2021]
Exact relationship: relationship--156d46b3-538e-4481-ad53-b85de891f6d5 - S0631 Chaes — malware.
Chaes can download additional files onto an infected machine.[Cybereason Chaes Nov 2020]
Exact relationship: relationship--e3a516b0-fa02-43dc-8247-0545a53693b1 - S0632 GrimAgent — malware.
GrimAgent has the ability to download and execute additional payloads.[Group IB GrimAgent July 2021]
Exact relationship: relationship--494255a0-7672-4302-9e1b-bf3767cb8384 - S0633 Sliver — tool.
Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the <code>upload</code> command.[GitHub Sliver Upload][Cybereason Sliver Undated]
Exact relationship: relationship--94ea901d-3904-4d84-9b0f-7df943683cd7 - S0635 BoomBox — malware.
BoomBox has the ability to download next stage malware components to a compromised system.[MSTIC Nobelium Toolset May 2021]
Exact relationship: relationship--33eb06fa-5983-47d8-9f7f-d594f311a008 - S0636 VaporRage — malware.
VaporRage has the ability to download malicious shellcode to compromised systems.[MSTIC Nobelium Toolset May 2021]
Exact relationship: relationship--8972de3e-d073-47ec-9665-a10896601e12 - S0639 Seth-Locker — malware.
Seth-Locker has the ability to download and execute files on a compromised host.[Trend Micro Ransomware February 2021]
Exact relationship: relationship--1715a3b2-1c13-403e-8add-e8709fc7f92c - S0642 BADFLICK — malware.
BADFLICK has download files from its C2 server.[Accenture MUDCARP March 2019]
Exact relationship: relationship--c07e24ea-bf70-4f9c-a45e-73dfc0ede007 - S0643 Peppy — malware.
Peppy can download and execute remote files.[Proofpoint Operation Transparent Tribe March 2016]
Exact relationship: relationship--2bfc128f-2bc9-436b-abe0-4206b9e35727 - S0646 SpicyOmelette — malware.
SpicyOmelette can download malicious files from threat actor controlled AWS URL's.[Secureworks GOLD KINGSWOOD September 2018]
Exact relationship: relationship--7f7f05aa-a246-48ce-89d2-48035cac5ffa - S0647 Turian — malware.
Turian can download additional files and tools from its C2.[ESET BackdoorDiplomacy Jun 2021]
Exact relationship: relationship--bfab83a2-934e-4e3c-b2c9-626d88231497 - S0648 JSS Loader — malware.
JSS Loader has the ability to download malicious executables to a compromised host.[CrowdStrike Carbon Spider August 2021]
Exact relationship: relationship--f4e1e921-1436-4fdc-88bc-f3321383e96a - S0649 SMOKEDHAM — malware.
SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.[FireEye SMOKEDHAM June 2021]
Exact relationship: relationship--452e340a-df31-4ae9-a801-d26c57d491ea - S0650 QakBot — malware.
QakBot has the ability to download additional components and malware.[Trend Micro Qakbot May 2020][Crowdstrike Qakbot October 2020][Trend Micro Qakbot December 2020][Cyberint Qakbot May 2021][Kaspersky QakBot September 2021][Group IB Ransomware September 2020]
Exact relationship: relationship--aa444f15-777c-4bf6-819b-f03476d59401 - S0651 BoxCaon — malware.
BoxCaon can download files.[Checkpoint IndigoZebra July 2021]
Exact relationship: relationship--237429d4-808b-478f-ab0f-a01bff89834e - S0652 MarkiRAT — malware.
MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.[Kaspersky Ferocious Kitten Jun 2021]
Exact relationship: relationship--2f4684b2-728f-46c5-9c91-98731c935b28 - S0653 xCaon — malware.
xCaon has a command to download files to the victim's machine.[Checkpoint IndigoZebra July 2021]
Exact relationship: relationship--ae7cd450-60bc-426b-92df-14d9d1be279b - S0657 BLUELIGHT — malware.
BLUELIGHT can download additional files onto the host.[Volexity InkySquid BLUELIGHT August 2021]
Exact relationship: relationship--2161578b-44ef-4c44-90ad-2ee8920a3db8 - S0658 XCSSET — malware.
XCSSET downloads browser specific AppleScript modules using a constructed URL with the <code>curl</code> command, <code>https://" & domain & "/agent/scripts/" & moduleName & ".applescript</code>.[trendmicro xcsset xcode project 2020]
Exact relationship: relationship--30e190f8-2f7d-4795-9bed-90576fafdd0b - S0659 Diavol — malware.
Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.[Fortinet Diavol July 2021]
Exact relationship: relationship--d55ab651-738b-4bbc-9438-57fc76be8f52 - S0661 FoggyWeb — malware.
FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.[MSTIC FoggyWeb September 2021]
Exact relationship: relationship--998c449f-ef46-4f42-a6a4-bd025338584e - S0662 RCSession — malware.
RCSession has the ability to drop additional files to an infected machine.[Profero APT27 December 2020]
Exact relationship: relationship--6758c87e-d187-46df-b02a-1e093b3054cc - S0663 SysUpdate — malware.
SysUpdate has the ability to download files to a compromised host.[Trend Micro Iron Tiger April 2021][Lunghi Iron Tiger Linux]
Exact relationship: relationship--759ce6e8-da01-4cd6-9d03-9b0a1edde9be - S0664 Pandora — malware.
Pandora can load additional drivers and files onto a victim machine.[Trend Micro Iron Tiger April 2021]
Exact relationship: relationship--0110e04e-5812-4b69-9700-037b52d3ebb4 - S0665 ThreatNeedle — malware.
ThreatNeedle can download additional tools to enable lateral movement.[Kaspersky ThreatNeedle Feb 2021]
Exact relationship: relationship--4e49358b-43d4-4fc6-8ad0-72882de328b4 - S0666 Gelsemium — malware.
Gelsemium can download additional plug-ins to a compromised host.[ESET Gelsemium June 2021]
Exact relationship: relationship--9548ed41-931a-4d95-8256-b3fcad5914ad - S0667 Chrommme — malware.
Chrommme can download its code from C2.[ESET Gelsemium June 2021]
Exact relationship: relationship--4253a9ab-fddb-4c2f-b4c7-c4bc8182d9a4 - S0668 TinyTurla — malware.
TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.[Talos TinyTurla September 2021]
Exact relationship: relationship--72ec975a-43b4-4766-a2f4-385b6112858d - S0669 KOCTOPUS — malware.
KOCTOPUS has executed a PowerShell command to download a file to the system.[MalwareBytes LazyScripter Feb 2021]
Exact relationship: relationship--63eceedb-657b-47a0-a437-983aad5d82e0 - S0670 WarzoneRAT — malware.
WarzoneRAT can download and execute additional files.[Check Point Warzone Feb 2020]
Exact relationship: relationship--2f081501-0c5c-4662-b7b4-3dc5a8a3b1af - S0671 Tomiris — malware.
Tomiris can download files and execute them on a victim's system.[Kaspersky Tomiris Sep 2021]
Exact relationship: relationship--9e0bef30-edc0-4a18-9033-a1f487e35b76 - S0672 Zox — malware.
Zox can download files to a compromised machine.[Novetta-Axiom]
Exact relationship: relationship--55d5ccb4-b794-467b-b734-fa3763bbdf99 - S0674 CharmPower — malware.
CharmPower has the ability to download additional modules to a compromised host.[Check Point APT35 CharmPower January 2022]
Exact relationship: relationship--e0a7e8ca-a199-4909-a4da-302bcc6216e6 - S0680 LitePower — malware.
LitePower has the ability to download payloads containing system commands to a compromised host.[Kaspersky WIRTE November 2021]
Exact relationship: relationship--3593e540-dfc0-4995-8640-db52961b3666 - S0681 Lizar — malware.
Lizar can download additional plugins, files, and tools.[BiZone Lizar May 2021][SekoiaBourhis_DiceLoader_Feb2024][Cocomazzi FIN7 Reboot]
Exact relationship: relationship--a19231c9-e6b4-4d3f-9c9d-f4e85cba5e3a - S0685 PowerPunch — malware.
PowerPunch can download payloads from adversary infrastructure.[Microsoft Actinium February 2022]
Exact relationship: relationship--87b69ac6-d50d-4bbf-ac8b-7ad81b4e9ee8 - S0686 QuietSieve — malware.
QuietSieve can download and execute payloads on a target host.[Microsoft Actinium February 2022]
Exact relationship: relationship--16446d10-cf55-4e1e-bbf8-7ce6b8a2fb2b - S0687 Cyclops Blink — malware.
Cyclops Blink has the ability to download files to target systems.[NCSC Cyclops Blink February 2022][Trend Micro Cyclops Blink March 2022]
Exact relationship: relationship--ca7d9090-d5ff-4a10-b403-015daa559e84 - S0688 Meteor — malware.
Meteor has the ability to download additional files for execution on the victim's machine.[Check Point Meteor Aug 2021]
Exact relationship: relationship--201f9d85-be41-4aeb-984f-6ece40d4177d - S0689 WhisperGate — malware.
WhisperGate can download additional stages of malware from a Discord CDN channel.[Microsoft WhisperGate January 2022][Unit 42 WhisperGate January 2022][Cisco Ukraine Wipers January 2022][Medium S2W WhisperGate January 2022]
Exact relationship: relationship--f099adef-7e4e-4b52-b4fa-27f7db8389f3 - S0691 Neoichor — malware.
Neoichor can download additional files onto a compromised host.[Microsoft NICKEL December 2021]
Exact relationship: relationship--22a59466-1502-431a-a2c7-a8cb09928a74 - S0692 SILENTTRINITY — tool.
SILENTTRINITY can load additional files and tools, including Mimikatz.[GitHub SILENTTRINITY Modules July 2019]
Exact relationship: relationship--1b16de68-c627-4f38-a85f-bbba2fef7e20 - S0694 DRATzarus — malware.
DRATzarus can deploy additional tools onto an infected machine.[ClearSky Lazarus Aug 2020]
Exact relationship: relationship--6684ebb4-cab6-4443-a539-f71bdddbf15c - S0695 Donut — tool.
Donut can download and execute previously staged shellcode payloads.[Donut Github]
Exact relationship: relationship--c720f9ab-106c-47ce-b327-83727be6d35a - S0696 Flagpro — malware.
Flagpro can download additional malware from the C2 server.[NTT Security Flagpro new December 2021]
Exact relationship: relationship--82ce210f-a994-4541-b62f-40ead02ad202 - S1012 PowerLess — malware.
PowerLess can download additional payloads to a compromised host.[Cybereason PowerLess February 2022]
Exact relationship: relationship--4bd59ceb-eb44-45c0-b775-3eaea3307455 - S1013 ZxxZ — malware.
ZxxZ can download and execute additional files.[Cisco Talos Bitter Bangladesh May 2022]
Exact relationship: relationship--0bde7434-49de-40c4-906c-fc5f3bfc6d16 - S1014 DanBot — malware.
DanBot can download additional files to a targeted system.[SecureWorks August 2019]
Exact relationship: relationship--6bfbee18-c771-4260-b460-8058dbc5c08a - S1015 Milan — malware.
Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.[ClearSky Siamesekitten August 2021]
Exact relationship: relationship--4e39da36-f7e0-4e26-b354-ca34fb801e33 - S1016 MacMa — malware.
MacMa has downloaded additional files, including an exploit for used privilege escalation.[ESET DazzleSpy Jan 2022][Objective-See MacMa Nov 2021]
Exact relationship: relationship--e132f8f8-c15d-4423-8794-8571d37a3998 - S1017 OutSteel — malware.
OutSteel can download files from its C2 server.[Palo Alto Unit 42 OutSteel SaintBot February 2022 ]
Exact relationship: relationship--e12c4451-5d26-4eea-a7e9-fcdfd517e77d - S1018 Saint Bot — malware.
Saint Bot can download additional files onto a compromised host.[Palo Alto Unit 42 OutSteel SaintBot February 2022 ]
Exact relationship: relationship--3a9e3914-2503-41e7-a9cb-57dd30f97a8a - S1019 Shark — malware.
Shark can download additional files from its C2 via HTTP or DNS.[ClearSky Siamesekitten August 2021][Accenture Lyceum Targets November 2021]
Exact relationship: relationship--03d6c33c-22d4-484f-8f16-8d49c307da80 - S1020 Kevin — malware.
Kevin can download files to the compromised host.[Kaspersky Lyceum October 2021]
Exact relationship: relationship--3fadfbe5-6ed1-4d6d-a5ed-a355506431ba - S1021 DnsSystem — malware.
DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`.[Zscaler Lyceum DnsSystem June 2022]
Exact relationship: relationship--607ae633-8e47-457a-9507-511d1e28f470 - S1023 CreepyDrive — malware.
CreepyDrive can download files to the compromised host.[Microsoft POLONIUM June 2022]
Exact relationship: relationship--ac5bf8d9-900b-4aa4-8f97-81566666cd26 - S1025 Amadey — malware.
Amadey can download and execute files to further infect a host machine with additional malware.[BlackBerry Amadey 2020]
Exact relationship: relationship--a2b97730-39f9-4ba6-b481-d27f883ff26f - S1026 Mongall — malware.
Mongall can download files to targeted systems.[SentinelOne Aoqin Dragon June 2022]
Exact relationship: relationship--ac062b78-400d-4d9a-9c5b-95c7a1b6dd42 - S1028 Action RAT — malware.
Action RAT has the ability to download additional payloads onto an infected machine.[MalwareBytes SideCopy Dec 2021]
Exact relationship: relationship--0e7cace2-18db-4068-8a99-3dc66ed24741 - S1030 Squirrelwaffle — malware.
Squirrelwaffle has downloaded and executed additional encoded payloads.[ZScaler Squirrelwaffle Sep 2021][Netskope Squirrelwaffle Oct 2021]
Exact relationship: relationship--66794b81-fc1e-4a28-9a52-7e67d64cbed6 - S1034 StrifeWater — malware.
StrifeWater can download updates and auxiliary modules.[Cybereason StrifeWater Feb 2022]
Exact relationship: relationship--f12643cb-1ff8-49b9-a57e-38246a46c428 - S1035 Small Sieve — malware.
Small Sieve has the ability to download files.[NCSC GCHQ Small Sieve Jan 2022]
Exact relationship: relationship--2ffd84e6-b76d-4c0c-9c76-ef8e55446546 - S1039 Bumblebee — malware.
Bumblebee can download and execute additional payloads including through the use of a `Dex` command.[Google EXOTIC LILY March 2022][Proofpoint Bumblebee April 2022][Symantec Bumblebee June 2022]
Exact relationship: relationship--7065f730-96fc-4a33-b6fb-101af568b74b - S1044 FunnyDream — malware.
FunnyDream can download additional files onto a compromised host.[Bitdefender FunnyDream Campaign November 2020]
Exact relationship: relationship--9c2ed616-647a-4cf5-9f43-b0b78f9fdcd1 - S1048 macOS.OSAMiner — malware.
macOS.OSAMiner has used `curl` to download a Stripped Payloads from a public facing adversary-controlled webpage.
Exact relationship: relationship--0a8e3f80-f415-450c-9976-feb917facd8a - S1059 metaMain — malware.
metaMain can download files onto compromised systems.[SentinelLabs Metador Sept 2022][SentinelLabs Metador Technical Appendix Sept 2022]
Exact relationship: relationship--bd2c2f6f-5bc1-4150-b618-3b53b037670f - S1060 Mafalda — malware.
Mafalda can download additional files onto the compromised host.[SentinelLabs Metador Technical Appendix Sept 2022]
Exact relationship: relationship--995aaffc-947a-4674-825f-9b6d53b7aefc - S1063 Brute Ratel C4 — tool.
Brute Ratel C4 can download files to compromised hosts.[Palo Alto Brute Ratel July 2022][Rapid7 Fake W2 July 2024]
Exact relationship: relationship--d723027c-349b-48f8-af77-808ee2f7d92f - S1064 SVCReady — malware.
SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.[HP SVCReady Jun 2022]
Exact relationship: relationship--3f491de8-7a45-413d-8e80-5c74b38e0fc1 - S1065 Woody RAT — malware.
Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`.[MalwareBytes WoodyRAT Aug 2022]
Exact relationship: relationship--88e52860-d4cc-485a-b23f-ad2cda301727 - S1066 DarkTortilla — malware.
DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.[Secureworks DarkTortilla Aug 2022]
Exact relationship: relationship--02c8a28f-c188-47a9-ab93-d9abb862abab - S1074 ANDROMEDA — malware.
ANDROMEDA can download additional payloads from C2.[Mandiant Suspected Turla Campaign February 2023]
Exact relationship: relationship--0b15b2f4-ba30-4393-88ec-08235206bfac - S1081 BADHATCH — malware.
BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine.[Gigamon BADHATCH Jul 2019]
Exact relationship: relationship--785e8778-84d2-46a5-b96a-ea71b1adc650 - S1085 Sardonic — malware.
Sardonic has the ability to upload additional malicious files to a compromised machine.[Bitdefender Sardonic Aug 2021]
Exact relationship: relationship--49f54bdd-564c-43b0-95d7-5300f20d994f - S1086 Snip3 — malware.
Snip3 can download additional payloads to compromised systems.[Morphisec Snip3 May 2021][Telefonica Snip3 December 2021]
Exact relationship: relationship--992be3b6-caea-497f-ae2b-256197433cc8 - S1087 AsyncRAT — tool.
AsyncRAT has the ability to download files including over SFTP.[AsyncRAT GitHub][ESET MirrorFace 2025]
Exact relationship: relationship--ca31e6ec-8cf9-4e5e-907a-895c3d19543f - S1088 Disco — malware.
Disco can download files to targeted systems via SMB.[MoustachedBouncer ESET August 2023]
Exact relationship: relationship--128afec2-d9a5-4433-89d9-0cc65abf15bd - S1089 SharpDisco — malware.
SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources.[MoustachedBouncer ESET August 2023]
Exact relationship: relationship--f02fafab-e905-48a4-953d-6238f740cc77 - S1090 NightClub — malware.
NightClub can load multiple additional plugins on an infected host.[MoustachedBouncer ESET August 2023]
Exact relationship: relationship--a881d020-95c1-4123-98d0-c31cb8d2ff4e - S1099 Samurai — malware.
Samurai has been used to deploy other malware including Ninja.[Kaspersky ToddyCat June 2022]
Exact relationship: relationship--62435a47-3830-4518-9c9f-1f0d25711907 - S1110 SLIGHTPULSE — malware.
RAPIDPULSE can transfer files to and from compromised hosts.[Mandiant Pulse Secure Update May 2021]
Exact relationship: relationship--5de10f34-9796-499d-a3e4-3977f2eb7154 - S1111 DarkGate — malware.
DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server.[Ensilo Darkgate 2018] DarkGate uses Windows Batch scripts executing the <code>curl</code> command to retrieve follow-on payloads.[Trellix Darkgate 2023] DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.[Rapid7 BlackBasta 2024]
Exact relationship: relationship--89006d46-811b-4ad7-9b27-cf9f563418a2 - S1112 STEADYPULSE — malware.
STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.[Mandiant Pulse Secure Zero-Day April 2021]
Exact relationship: relationship--ef96fb44-5139-4547-9660-2ba64e6635d9 - S1114 ZIPLINE — malware.
ZIPLINE can download files to be saved on the compromised system.[Mandiant Cutting Edge January 2024][Mandiant Cutting Edge Part 2 January 2024]
Exact relationship: relationship--e34a0e21-1db1-4c11-8e71-07bae802d8b9 - S1115 WIREFIRE — malware.
WIREFIRE has the ability to download files to compromised devices.[Mandiant Cutting Edge January 2024]
Exact relationship: relationship--3c295abc-714f-4c14-82dd-554761b4a0b2 - S1118 BUSHWALK — malware.
BUSHWALK can write malicious payloads sent through a web request’s command parameter.[Mandiant Cutting Edge Part 2 January 2024][Mandiant Cutting Edge Part 3 February 2024]
Exact relationship: relationship--01d9bce9-9ae9-4167-b279-0f0ee4e6b263 - S1124 SocGholish — malware.
SocGholish can download additional malware to infected hosts.[Red Canary SocGholish March 2024][Secureworks Gold Prelude Profile]
Exact relationship: relationship--446e3bf2-9a37-4d22-a7ca-ede547e5e16e - S1130 Raspberry Robin — malware.
Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's <code>%AppData%</code> folder.[HP RaspberryRobin 2024][RedCanary RaspberryRobin 2022]
Exact relationship: relationship--538697e9-2dda-43cb-ba43-208402f62f9d - S1138 Gootloader — malware.
Gootloader can fetch second stage code from hardcoded web domains.[Sophos Gootloader][SentinelOne Gootloader June 2021]
Exact relationship: relationship--d27bfd8a-f9f3-4dbf-86a2-b12ac9ea3de8 - S1140 Spica — malware.
Spica can upload and download files to and from compromised hosts.[Google TAG COLDRIVER January 2024]
Exact relationship: relationship--598500a6-dbb0-435c-a022-67150d6d11e8 - S1148 Raccoon Stealer — malware.
Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.[S2W Racoon 2022][Sekoia Raccoon2 2022]
Exact relationship: relationship--688a4ea0-c9ff-4bb1-a6ab-fc565cea1461 - S1149 CHIMNEYSWEEP — malware.
CHIMNEYSWEEP can download additional files from C2.[Mandiant ROADSWEEP August 2022]
Exact relationship: relationship--23b98d85-7ae7-4611-80a4-36441c2462e3 - S1152 IMAPLoader — malware.
IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.[PWC Yellow Liderc 2023]
Exact relationship: relationship--e54309eb-8865-452a-8a87-55168264612a - S1159 DUSTTRAP — malware.
DUSTTRAP can retrieve and load additional payloads.[Google Cloud APT41 2024]
Exact relationship: relationship--7a0da394-d797-4649-b9bf-1b5822ca3467 - S1160 Latrodectus — malware.
Latrodectus can download and execute PEs, DLLs, and shellcode from C2.[Latrodectus APR 2024][Elastic Latrodectus May 2024][Bitsight Latrodectus June 2024]
Exact relationship: relationship--70d06758-46ce-47b9-a3af-ff341d210a4a - S1166 Solar — malware.
Solar has the ability to download and execute files.[ESET OilRig Campaigns Sep 2023]
Exact relationship: relationship--3c6b31af-c6aa-4254-87f9-b9fdd473b40a - S1168 SampleCheck5000 — malware.
SampleCheck5000 can download additional payloads to compromised hosts.[ESET OilRig Campaigns Sep 2023][ESET OilRig Downloaders DEC 2023]
Exact relationship: relationship--53afb9f9-366b-4f0c-b348-05cd430f809a - S1170 ODAgent — malware.
ODAgent has the ability to download and execute files on compromised systems.[ESET OilRig Downloaders DEC 2023]
Exact relationship: relationship--457b0035-c414-4d7e-a708-ca07a5696deb - S1171 OilCheck — malware.
OilCheck can download staged payloads from an actor-controlled infrastructure.[ESET OilRig Downloaders DEC 2023]
Exact relationship: relationship--8523250e-25c3-4eb0-ae89-397965b9712e - S1172 OilBooster — malware.
OilBooster can download and execute files from an actor-controlled OneDrive account.[ESET OilRig Downloaders DEC 2023]
Exact relationship: relationship--9dbe8924-bf0a-4b76-98ff-04f6f442ae8b - S1173 PowerExchange — malware.
PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.[Symantec Crambus OCT 2023]
Exact relationship: relationship--1632dc5e-5ec9-4c93-9fc3-e4496879dfab - S1182 MagicRAT — malware.
MagicRAT can import and execute additional payloads.[Cisco MagicRAT 2022]
Exact relationship: relationship--1918de84-79d9-447f-9bef-0b8fa601758a - S1183 StrelaStealer — malware.
StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.[IBM StrelaStealer 2024]
Exact relationship: relationship--d40cf993-60c2-4b5f-8af8-fb8975b43ebf - S1185 LightSpy — malware.
On macOS, LightSpy downloads a `.json` file from the C2 server. The `.json` file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the `.json` file, which are compiled `.dylib` files. These `.dylib` files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections.[Huntress LightSpy macOS 2024]
Exact relationship: relationship--343c91aa-d902-409b-804d-e751d6715f1a - S1187 reGeorg — malware.
reGeorg has the ability to download files to targeted systems.[GitHub Neo-reGeorg 2019]
Exact relationship: relationship--5df789ae-1df2-4be4-9844-6c26b7c6d697 - S1189 Neo-reGeorg — malware.
Neo-reGeorg has the ability to download files to targeted systems.[GitHub Neo-reGeorg 2019]
Exact relationship: relationship--0dc7c2ef-bbeb-4d0a-be04-4f2d8c57be6f - S1192 NICECURL — malware.
NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.[Mandiant APT42-untangling]
Exact relationship: relationship--f3e042f4-e641-4d7e-8c8d-40d17851eeda - S1193 TAMECAT — malware.
TAMECAT has used `wget` and `curl` to download additional content.[Mandiant APT42-untangling]
Exact relationship: relationship--2a587f38-6625-4949-ae69-ed456f088d8b - S1211 Hannotog — malware.
Hannotog can download additional files to the victim machine.[Symantec Bilbug 2022]
Exact relationship: relationship--db526d10-c127-476d-9d97-668c139f6c05 - S1217 VIRTUALPITA — malware.
VIRTUALPITA has the ability to upload and download files.[Google Cloud Threat Intelligence ESXi VIBs 2022]
Exact relationship: relationship--6ebaf47d-862d-4522-83d4-71590ac9f7f6 - S1222 RIFLESPINE — malware.
RIFLESPINE can download and execute files.[Google Cloud Mandiant UNC3886 2024]
Exact relationship: relationship--4fc2c8ef-7c54-419a-af32-20fcd9770cfc - S1224 CASTLETAP — malware.
CASTLETAP can transfer files to compromised network devices.[Mandiant Fortinet Zero Day]
Exact relationship: relationship--2798addb-2787-4573-9380-9b2449dd3c94 - S1228 PUBLOAD — malware.
PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server.[Lab52 MUSTANG PANDA PUBLOAD MAY 2023][IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025][2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA][2022 November_TrendMicro_Earth Preta_Toneshell_Pubload][Palo Alto Networks, Unit 42] PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.[Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024]
Exact relationship: relationship--01c84feb-9dcf-455f-8900-fba08e8e7bc3 - S1229 Havoc — malware.
Havoc has the ability to upload files to infected systems.[Havoc Framework Documentation][Immersive Labs Havoc C2 APR 2024]
Exact relationship: relationship--55488927-0c46-4dfc-98f6-ceb530026578 - S1239 TONESHELL — malware.
TONESHELL has the ability to download additional files to the victim device.[Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023]
Exact relationship: relationship--5560a545-7bc2-482a-bb85-eaf4e2ed773b - S1240 RedLine Stealer — malware.
RedLine Stealer has the ability download additional payloads.[Kroll RedLine Stealer August 2024][Veriti RedLine Stealer MAAS April 2023]
Exact relationship: relationship--94813c25-e3ba-4f51-ba49-f0fc5e486e8a - S1245 InvisibleFerret — malware.
InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment.[ESET Contagious Interview BeaverTail InvisibleFerret February 2025] InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.[Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024][PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023]
Exact relationship: relationship--497ebc9c-e993-4097-9cb0-11b5a13b0bb5 - S1246 BeaverTail — malware.
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.[Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024][Socket BeaverTail XORIndex HexEval Contagious Interview July 2025][Socket HexEval BeaverTail Contagious Interview June 2025][ESET Contagious Interview BeaverTail InvisibleFerret February 2025][PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023][PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024]
Exact relationship: relationship--af861bf5-a686-4661-8613-c3f1c6972723 - S1248 XORIndex Loader — malware.
XORIndex Loader has been used to download a malicious payload to include BeaverTail.[Socket BeaverTail XORIndex HexEval Contagious Interview July 2025]
Exact relationship: relationship--a8195876-514d-49b7-9b9c-30c75eaff089 - S1249 HexEval Loader — malware.
HexEval Loader has been used to download a malicious payload to include BeaverTail.[Socket Contagious Interview NPM April 2025][Socket BeaverTail XORIndex HexEval Contagious Interview July 2025][Socket HexEval BeaverTail Contagious Interview June 2025]
Exact relationship: relationship--2dc59875-4281-45f2-acfb-5e36428e812d - S9001 SystemBC — malware.
SystemBC has downloaded additional files for execution on the victim’s machine.[SophosGnGal_SystemBC_Dec2020][TrumanKroll_SYSTEMBCServer_Jan2024] The server component of SystemBC has the ability to send additional files to victim machines.[TrumanKroll_SYSTEMBCServer_Jan2024]
Exact relationship: relationship--2eb1f662-5901-4bbe-b45b-54c8dfc5e20e - S9007 HTTPTroy — malware.
HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command.[Gen Digital Kimsuky HTTPTroy October 2025]
Exact relationship: relationship--0f164983-ed7d-44cc-b6db-90b141e271ff - S9008 Shai-Hulud — malware.
Shai-Hulud has downloaded packages from code repositories.[Aikido Shai-Hulud September 2025][Wiz Shai-Hulud September 2025][Socket Shai-Hulud November 2025][Socket Shai-Hulud Trufflehog September 2025] Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.[Netskope Shai-Hulud November 2025][Wiz Shai-Hulud September 2025][Microsoft Shai-Hulud December 2025][Socket Shai-Hulud November 2025][Socket Shai-Hulud Trufflehog September 2025]
Exact relationship: relationship--472255be-4ec3-41ad-b66d-3cede330abbc - S9010 GlassWorm — malware.
GlassWorm has downloaded additional payloads from C2.[Koi Glassworm New Tricks December 2025][Koi Glassworm Extensions November 2025][Socket GlassWorm January 2026][Koi GlassWorm Rust December 2025]
Exact relationship: relationship--d8613097-6ef1-4b84-8641-0951cab8376f - S9014 PHASEJAM — malware.
PHASEJAM has the ability to upload files onto the compromised appliance.[Google UNC5221 Ivanti January 2025]
Exact relationship: relationship--761a260b-5392-43a9-94fe-249ad77b75db - S9015 BRICKSTORM — malware.
BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.[CISA BRICKSTORM UNC5221 AR25-338A February 2026][Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024][NVISO BRICKSTORM April 2025][Google BRICKSTORM September 2025]
Exact relationship: relationship--c4973466-b155-40e6-8eff-1888cd50b61c - S9016 Caminho — malware.
Caminho has the ability to download files onto compromised hosts.[Zscaler BlindEagle DEC 2025]
Exact relationship: relationship--ae3003a7-3d6d-4dbc-8da9-65c947243cd5 - S9019 PureCrypter — malware.
PureCrypter can download additional payloads for execution on the compromised host.[Zscaler PureCrypter JUN 2022][Check Point Blind Eagle MAR 2025]
Exact relationship: relationship--aa736843-16e9-4872-827a-41d24782cdb7 - S9020 LODEINFO — malware.
LODEINFO has the ability to download additional files from the C2.[Kaspersky LODEINFO Part II OCT 2022][ESET MirrorFace DEC 2022][ITOCHU LODEINFO JAN 2024]
Exact relationship: relationship--392dbbcb-92e8-4ccc-8b1d-73c8577fc487 - S9021 DOWNIISSA — malware.
DOWNIISSA can download files to the compromised host.[Kaspersky LODEINFO OCT 2022]
Exact relationship: relationship--526929a7-d746-477b-a34b-fe41e2e2e16a - S9023 HiddenFace — malware.
HiddenFace can download files from the C2 to victim systems.[Trend Micro Earth Kasha NOV 2024][JPCERT MirrorFace JUL 2024]
Exact relationship: relationship--630c1788-f3b9-40f2-acf9-95ae8c12d322 - S9028 PHPsert — malware.
PHPsert has the ability to retrieve remote payloads.[sentinelone operationDigitalEye Dec 2024]
Exact relationship: relationship--631156f6-a414-4856-81b0-e4bd727e77ba - S9031 AshTag — malware.
The AshTag stager component can retrieve and execute the main payload.[Palo Alto Ashen Lepus DEC 2025]
Exact relationship: relationship--b2cbfcbd-5200-41ef-9338-ac9b0b0eb9df - S9032 MuddyViper — malware.
MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.[ESET_MuddyWater_Dec2025]
Exact relationship: relationship--25725116-788a-429a-b026-a6345bbd7f25 - S9034 Tsundere Botnet — malware.
Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.[SecureListUbiedo_Tsundere_Nov2025]
Exact relationship: relationship--54a96733-eb51-43ba-a080-3b4adbcbc915 - S9041 TeamPCP Cloud Stealer — malware.
TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems.[Wiz Trivy Compromise MAR 2026][Aqua Security Blog Trivy Compromise APR 2026][Wiz TeamPCP KICS MAR 2026][Palo Alto TeamPCP MAR 2026]
Exact relationship: relationship--28bdfde8-ff79-44b9-a515-88d230f23aae - S9042 CanisterWorm — malware.
CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes.[Aikido CanisterWorm MAR 2026][Aikido TeamPCP Trivy MAR 2026] CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.[Aikido CanisterWorm MAR 2026]
Exact relationship: relationship--3a4f7d04-6c45-4a96-9ce7-bd951d350a1f - S9043 Mini Shai-Hulud — malware.
Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure.[Wiz Mini Shai-Hulud MAY 2026][Hunt.io TeamPCP Toolkit MAY 2026][Phoenix TeamPCP 20 MAY 2026]
Exact relationship: relationship--83874b9c-91ee-400d-bc46-529ad159e083