T1071.003: T1071.003
Essential information
- MITRE technique ID
T1071.003- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/04/2026 16:43
- Author / Source
- The MITRE Corporation
Aliases
Mail Protocols
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (10)
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
The MITRE Corporation Confidence 100
[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
GopherWhisper usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 27/04/2026 16:43 · Modified 27/04/2026 16:43
-
Earth Baxia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:15 · Modified 21/12/2025 07:15
-
The MITRE Corporation Confidence 100
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Turla, UNC4210 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:18 · Modified 20/12/2025 23:18
-
Agent Tesla usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:11 · Modified 21/12/2025 07:11
-
SilverTerrier usesThe MITRE Corporation Confidence 100
[SilverTerrier](https://attack.mitre.org/groups/G0083) is a Nigerian threat group that has been seen active since 2014. [SilverTerrier](https://attack.mitre.org/groups/G0083) mainly targets organizations in high technology, higher education, and manufacturing.(Citation: Unit42 SilverTerrier 2018)(Citation: Unit42 …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Malware (37)
-
FriendDelivery usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
- NavRAT
-
EAGLEDOOR usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
-
SWORDLDR usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
- ANDROMEDA
-
LaxGopher usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
- IMAPLoader
- Cannon
- PowerExchange
-
CompactGopher usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
-
Kazuar - S0265 usesFamilyPublished 28/05/2026 19:56 · Modified 28/05/2026 19:56
-
JabGopher usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
- Zebrocy
- SUGARDUMP
-
RIPCOY usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
-
BadPatch usesFamily The MITRE Corporation Confidence 100
[BadPatch](https://attack.mitre.org/software/S0337) is a Windows Trojan that was used in a Gaza Hackers-linked campaign.(Citation: Unit 42 BadPatch Oct 2017)
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 - CORESHELL
- Goopy
-
RatGopher usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
Agent Tesla usesFamilyPublished 28/05/2024 13:32 · Modified 28/05/2024 13:32
- JPIN
- CHOPSTICK
-
LunarMail usesFamilyPublished 16/05/2024 09:35 · Modified 16/05/2024 09:35
-
BoxOfFriends usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
-
Agent Tesla - S0331 usesFamilyPublished 15/05/2026 15:23 · Modified 15/05/2026 15:23
- ComRAT
-
Pelmeni usesFamilyPublished 14/05/2026 20:10 · Modified 14/05/2026 20:10
-
RDAT usesFamily The MITRE Corporation Confidence 100
[RDAT](https://attack.mitre.org/software/S0495) is a backdoor used by the suspected Iranian threat group [OilRig](https://attack.mitre.org/groups/G0049). [RDAT](https://attack.mitre.org/software/S0495) was originally identified in 2017 and targeted companies in the telecommunications sector.(Citation: Unit42 RDAT July …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:36 · Modified 27/03/2026 01:03 - KOPILUWAK
- OLDBAIT
-
QUIETCANARY usesFamily The MITRE Corporation Confidence 100
[QUIETCANARY](https://attack.mitre.org/software/S1076) is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.(Citation: Mandiant Suspected Turla Campaign …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 -
SSLORDoor usesFamilyPublished 23/04/2026 14:37 · Modified 23/04/2026 14:37
- Remsec
- Uroburos
- LightNeuron
-
NightClub usesFamily The MITRE Corporation Confidence 100
[NightClub](https://attack.mitre.org/software/S1090) is a modular implant written in C++ that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1019) since at least 2014.(Citation: MoustachedBouncer ESET August 2023)
First seen 01/01/1970 · Last seen 16/11/5138 Published 27/09/2023 21:32 · Modified 27/03/2026 01:05
Reports (8)
-
AlienVault Confidence 100 16 MITREs 14 IOCs 14 ObservablesPublished 15/06/2026 16:53 · Modified 15/06/2026 17:15 · threat-report
-
AlienVault Confidence 100 24 MITREs 2 Malwares 4 IOCs 4 Observables 1 APTPublished 14/05/2026 22:10 · Modified 15/05/2026 19:14 · threat-report
-
AlienVault Confidence 100 20 MITREs 7 Malwares 9 IOCs 9 Observables 1 APTPublished 23/04/2026 16:37 · Modified 27/04/2026 14:45 · threat-report
-
33 MITREs 1 ObservablePublished 18/06/2025 17:19 · Modified 23/06/2025 19:54
-
Blast from the Past related16 MITREs 2 Malwares 1 ObservablePublished 05/02/2025 02:45 · Modified 05/02/2025 11:17
-
19 MITREs 4 Malwares 29 Observables 1 APTPublished 20/09/2024 11:22 · Modified 20/09/2024 12:05
-
11 MITREs 1 Malware 9 Observables 1 APTPublished 18/09/2024 08:32 · Modified 18/09/2024 09:00
-
10 MITREs 5 Malwares 20 Observables 1 APTPublished 07/08/2024 16:11 · Modified 07/08/2024 16:37
Vulnerabilities (CVE) (1)
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath …
- Attack vector
- Network
- Published
- 15/07/2024
- Modified
- 21/12/2025
Attack patterns (MITRE) (1)
-
T1071 subtechnique-ofApplication Layer Protocol
Course Of Action (2)
- Filter Network Traffic mitigates
- Network Intrusion Prevention mitigates