FORENSIA

ATT&CK · T1105

Ingress Tool Transfer

Tactics: command-and-control

About

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, certutil, and PowerShell commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`. A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`). Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by User Execution (typically after interacting with Phishing lures). Files can also be transferred using various Web Services as well as native or otherwise present tools on the victim system. In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

86 known groups

Software

400 malware/tools implement this

HikitTaidoorPoisonIvyPlugXIxesheBISCUITChina ChopperUroburosCHOPSTICKDyregh0st RATLOWBALLJHUHUGITMiniDukeSeaDukeCloudDukeRARSTONEHTTPBrowserSakulaCallMePsyloMobileOrderMivastEliseEmissaryMisdatMis-TypeS-TypeZLibHi-ZorKasidetAgent.btzBackdoor.OldreaTrojan.KaraganyftpcmdWEBC2CrimsonNidiranPisloaderRemsecBADNEWSUnknown LoggerH1N1DowndelphCORESHELLPowerDukeShamoonWinnti for WindowsChChesPOWERSOURCEPteranodonRTMPOSHSPYRedLeavesCobalt StrikecertutilTDTESSRemoteCMDGazerHelminthFelismusVolgmerPOWRUNERSEASHARPEEDaserfBITSAdminPupyPUNCHBUGGYNETWIRETURNEDUPDipsindJPINHydraqBribaWiarpVasportPasamNerexLinfoDOGCALLHAPPYWORKKARAESHUTTERSPEEDSLOWDRIFTPOWERSTATSSmoke LoaderNanHaiShuOrzZeroTBandookKwampirsBankshotROKRATRATANKBANavRATGold DragonKoadicZebrocyPLAINTEEDDKONGMosquitoVERMINRGDoorInvisiMoleQuasarRATTYPEFRAMEOopsIEKazuarTrickBotFELIXROOTBisonalRogueRobinKEYMARBLENDiskMonitorCalistoUPPERCUTjRATMore_eggsZeus PandaAgent TeslaRemcosUBoatRATDarkCometNanoCoreBadPatchMicropsiaOctopusXbashGreyEnergyAzorultSeasaltAuditCredCardinal RATCannonOSX_OCEANLOTUS.DNOKKIDenisKONNIBONDUPDATEREmpireEmotetCoinTickerAstarothSpeakUpHOPLIGHTRevenge RATStoneDrillFlawedAmmyyServHelpernjRATUrsnifKeyBoyYAHOYAHSQLRatHiddenWaspLightNeuronEvilBunnyHyperBroExaramel for LinuxOSX/ShlayeresentutlMacheteZxShellBabySharkPoetRATWinnti for LinuxHotCroissantPLEADTSCookieKivarsAttorOkrumVBShowerShimRatShimRatReporterLokibotSHARPSTATSLoudMinerPonyMetamorfoAria-bodyNetwalkerMechaFlounderSDBbotCARROTBATCARROTBALLSkidmapABKBBKbuild_downerdown_newAvengerBackConfigValakBundloreIcedIDCarberpBonadanKesselStrongPityCookieMinerGoldenSpyRDATREvilDaclsCryptoisticHancitorMCMDPipeMonDrovorubAnchorRegDukeLiteDukeWellMessWellMailSoreFangPolyglotDukeBLINDINGCANKGH_SPYCSPY DownloaderJavaliMelcozGrandoreiroLuciferSLOTHFULMEDIABazarSharpStageDropBookMoleNetEgregorSUNBURSTGuLoaderBlackMouldDtrackEVILNUMExplosiveCaterpillar WebShellBendyBearWaterbearKerrdownTAINTEDSCRIBEPenquinGoldMaxSibotRemoteUtilitiesThiefQuestShadowPadP.A.S. WebshellKinsingDokiHildegardIndustroyerConfickerSideTwistPS1CostaBricksSombRATDEATHRANSOMEcipekacCubaP8RATSodaMasterFYAntiRainyDayNebulaeChaesGrimAgentSliverBoomBoxVaporRageSeth-LockerBADFLICKPeppySpicyOmeletteTurianJSS LoaderSMOKEDHAMQakBotBoxCaonMarkiRATxCaonBLUELIGHTXCSSETDiavolFoggyWebRCSessionSysUpdatePandoraThreatNeedleGelsemiumChrommmeTinyTurlaKOCTOPUSWarzoneRATTomirisZoxCharmPowerLitePowerLizarPowerPunchQuietSieveCyclops BlinkMeteorWhisperGateNeoichorSILENTTRINITYDRATzarusDonutFlagproPowerLessZxxZDanBotMilanMacMaOutSteelSaint BotSharkKevinDnsSystemCreepyDriveAmadeyMongallAction RATSquirrelwaffleStrifeWaterSmall SieveBumblebeeFunnyDreammacOS.OSAMinermetaMainMafaldaBrute Ratel C4SVCReadyWoody RATDarkTortillaANDROMEDABADHATCHSardonicSnip3AsyncRATDiscoSharpDiscoNightClubSamuraiSLIGHTPULSEDarkGateSTEADYPULSEZIPLINEWIREFIREBUSHWALKSocGholishRaspberry RobinGootloaderSpicaRaccoon StealerCHIMNEYSWEEPIMAPLoaderDUSTTRAPLatrodectusSolarSampleCheck5000ODAgentOilCheckOilBoosterPowerExchangeMagicRATStrelaStealerLightSpyreGeorgNeo-reGeorgNICECURLTAMECATHannotogVIRTUALPITARIFLESPINECASTLETAPPUBLOADHavocTONESHELLRedLine StealerInvisibleFerretBeaverTailXORIndex LoaderHexEval LoaderSystemBCHTTPTroyShai-HuludGlassWormPHASEJAMBRICKSTORMCaminhoPureCrypterLODEINFODOWNIISSAHiddenFacePHPsertAshTagMuddyViperTsundere Botnet

Corpus indicators tagged with this technique

6,642 indicators in the corpus carry T1105.