27
Groups Using This
1
Tactics
4
Platforms
47
Prevalence Rank
Description

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

View MITRE record โ†—

Platforms
ESXiLinuxmacOSWindows
Groups Using T1041 (27)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G1015
Scattered Spider
64 techniques9 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G1055
VOID MANTICORE
๐Ÿ‡ฎ๐Ÿ‡ท Iran63 techniques0 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G1052
Contagious Interview
๐Ÿ‡ฐ๐Ÿ‡ต North Korea54 techniques4 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G1043
BlackByte
48 techniques8 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G0128
ZIRCONIUM
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques0 software
G1014
LuminousMoth
๐Ÿ‡จ๐Ÿ‡ณ China28 techniques2 software
G0126
Higaisa
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1035
Winter Vivern
๐Ÿ‡ท๐Ÿ‡บ Russia27 techniques0 software
G0090
WIRTE
26 techniques8 software
G1030
Agrius
๐Ÿ‡ฎ๐Ÿ‡ท Iran22 techniques9 software
G0142
Confucius
19 techniques1 software
G1012
CURIUM
๐Ÿ‡ฎ๐Ÿ‡ท Iran19 techniques1 software
G0038
Stealth Falcon
16 techniques0 software
โ†‘