T1102.003: T1102.003
Essential information
- MITRE technique ID
T1102.003- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
One-Way Communication
Platforms
windows macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (28)
-
Storm-1747 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:19 · Modified 21/12/2025 19:19
-
FreeDrain usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:25 · Modified 21/12/2025 13:25
-
Storm-1575 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:11 · Modified 21/12/2025 08:11
-
TeamPCP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/03/2026 22:18 · Modified 20/03/2026 22:18
-
Smilodon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:46 · Modified 21/12/2025 07:46
-
The MITRE Corporation Confidence 100
[APT33](https://attack.mitre.org/groups/G0064) is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Magecart usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:17 · Modified 21/12/2025 00:17
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 12:22 · Modified 21/12/2025 12:22
-
UNC5342 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:35 · Modified 21/12/2025 17:35
-
GlassWorm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:54 · Modified 21/12/2025 18:54
-
BADBOX usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:16 · Modified 21/12/2025 09:16
-
UAC-0057 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:45 · Modified 21/12/2025 15:45
-
CL-UNK-1037 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:43 · Modified 21/12/2025 17:43
-
GLOBAL GROUP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:37 · Modified 21/12/2025 15:37
-
SHADOW-VOID-044 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 27/01/2026 08:33 · Modified 27/01/2026 08:33
-
Ghostwriter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:32 · Modified 21/12/2025 09:32
-
TA2723 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 20:39 · Modified 21/12/2025 20:39
-
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
IPIDEA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 29/01/2026 08:34 · Modified 29/01/2026 08:34
-
BlueDelta usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:08 · Modified 21/12/2025 05:08
-
koneko usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:54 · Modified 21/12/2025 18:54
-
Coquettte usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 12:41 · Modified 21/12/2025 12:41
-
The MITRE Corporation Confidence 100
[Leviathan](https://attack.mitre.org/groups/G0065) is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
MimiStick usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:27 · Modified 21/12/2025 07:27
-
Wang Duo Yu usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:28 · Modified 21/12/2025 13:28
-
The MITRE Corporation Confidence 100
[Gamaredon Group](https://attack.mitre.org/groups/G0047) is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Astaroth usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:52 · Modified 21/12/2025 02:52
Malware (77)
-
Dadsec usesFamilyPublished 29/05/2025 16:10 · Modified 29/05/2025 16:10
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
ClickFix usesFamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
Salty2FA usesFamilyPublished 02/12/2025 21:13 · Modified 02/12/2025 21:13
-
BadIIS usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
AsyncRAT usesFamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
-
HeadLace usesFamilyPublished 05/08/2024 08:30 · Modified 05/08/2024 08:30
-
BADBOX usesFamilyPublished 17/02/2026 12:39 · Modified 17/02/2026 12:39
-
MetaStealer usesFamilyPublished 30/08/2025 09:10 · Modified 30/08/2025 09:10
-
CryptBot usesFamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
-
Rust backdoor usesFamilyPublished 11/03/2026 15:24 · Modified 11/03/2026 15:24
-
NetBird usesFamilyPublished 21/08/2025 07:35 · Modified 21/08/2025 07:35
-
ThunderShell usesFamilyPublished 03/04/2025 17:18 · Modified 03/04/2025 17:18
-
BeaverTail usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
-
JADESNOW usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 20:00 · Modified 21/12/2025 17:35
-
DarkNimbus usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
-
Nymeria usesFamilyPublished 05/02/2025 20:51 · Modified 05/02/2025 20:51
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
-
r.blob skimmer usesFamilyPublished 07/11/2024 22:48 · Modified 07/11/2024 22:48
-
AteraAgent usesFamilyPublished 21/08/2025 07:35 · Modified 21/08/2025 07:35
-
Kimwolf usesFamilyPublished 29/01/2026 03:42 · Modified 29/01/2026 03:42
- EVILNUM
-
Tycoon2FA usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
Rescoms usesFamilyPublished 25/05/2025 17:47 · Modified 25/05/2025 17:47
-
GlassWorm usesFamilyPublished 26/03/2026 20:45 · Modified 26/03/2026 20:45
-
Rhadamanthys usesFamilyPublished 29/04/2026 02:24 · Modified 29/04/2026 02:24
-
BIOPASS RAT usesFamilyPublished 26/01/2026 20:30 · Modified 26/01/2026 20:30
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
Sagerunex usesFamilyPublished 04/04/2025 19:54 · Modified 04/04/2025 19:54
-
NetSupport RAT usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
VenomRAT usesFamilyPublished 03/06/2026 13:18 · Modified 03/06/2026 13:18
-
jquery hex skimmer usesFamilyPublished 07/11/2024 22:48 · Modified 07/11/2024 22:48
-
Casbaneiro usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
-
zgRAT usesFamilyPublished 21/08/2025 00:37 · Modified 21/08/2025 00:37
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
-
InvisibleFerret usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
-
Tsundere usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
IcedID - S0483 usesFamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 16/03/2026 23:26 · Modified 16/03/2026 23:26
-
Tickler usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Aisuru usesFamilyPublished 29/01/2026 03:42 · Modified 29/01/2026 03:42
- OnionDuke
-
TrustConnect RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 19/02/2026 13:44 · Modified 19/02/2026 13:44
-
ToughProgress usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
colortoolsv2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:59 · Modified 21/12/2025 15:59
-
Quasar RAT usesFamilyPublished 15/05/2026 15:23 · Modified 15/05/2026 15:23
-
DOGE Binary Loader usesFamilyPublished 22/04/2025 16:40 · Modified 22/04/2025 16:40
-
HOLODONUT usesFamilyPublished 26/01/2026 20:30 · Modified 26/01/2026 20:30
-
123 Stealer usesFamilyPublished 21/01/2026 12:36 · Modified 21/01/2026 12:36
-
Tsundere Bot usesFamilyPublished 28/01/2026 18:26 · Modified 28/01/2026 18:26
-
XFiles Stealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 30/01/2026 09:49 · Modified 30/01/2026 09:49
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
Rugmi usesFamilyPublished 04/04/2025 19:54 · Modified 04/04/2025 19:54
-
TameCat usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
- HAMMERTOSS
-
Foudre usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
- UPSTYLE
-
DocConnect usesFamilyPublished 19/02/2026 11:10 · Modified 19/02/2026 11:10
- LUMASTEALER
-
GRAYRABBIT usesFamilyPublished 26/01/2026 20:30 · Modified 26/01/2026 20:30
-
WizardNet usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
-
RecordBreaker usesFamilyPublished 25/05/2025 17:47 · Modified 25/05/2025 17:47
-
Emmenhtal Loader usesFamilyPublished 30/01/2026 08:20 · Modified 30/01/2026 08:20
-
Guildma usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
-
mimelib2 usesFamilyPublished 04/09/2025 00:59 · Modified 04/09/2025 00:59
-
MKDOOR usesFamilyPublished 26/01/2026 20:30 · Modified 26/01/2026 20:30
-
MageCart usesFamilyPublished 13/02/2025 01:13 · Modified 13/02/2025 01:13
-
PLUSINJECT usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
PLUSDROP usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
Tonnerre usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
Penguish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:17 · Modified 21/12/2025 13:21
-
FMAPP.exe usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
BadBox2.0 usesFamilyPublished 29/01/2026 03:42 · Modified 29/01/2026 03:42
-
WebSocket skimmer usesFamilyPublished 07/11/2024 22:48 · Modified 07/11/2024 22:48
-
PeckBirdy usesFamilyPublished 26/01/2026 20:30 · Modified 26/01/2026 20:30
-
Astaroth - S0373 usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
Reports (32)
-
17 MITREs 1 Observable 1 APTPublished 19/05/2026 12:45 · Modified 21/05/2026 17:12
-
18 MITREs 1 Malware 1 Observable 1 APTPublished 26/03/2026 20:45 · Modified 27/03/2026 00:11
-
7 MITREs 1 Malware 160 ObservablesPublished 16/03/2026 23:26 · Modified 17/03/2026 01:44
-
26 MITREs 2 Malwares 19 ObservablesPublished 11/03/2026 15:24 · Modified 16/03/2026 09:51
-
19 MITREs 6 Malwares 5 Observables 1 APTPublished 04/03/2026 19:42 · Modified 05/03/2026 09:48
-
1 CVE 19 MITREs 7 Malwares 21 Observables 1 APTPublished 26/01/2026 20:30 · Modified 27/01/2026 07:34
-
10 MITREs 2 Observables 1 APTPublished 13/01/2026 19:36 · Modified 14/01/2026 11:12
-
11 MITREs 8 Observables 1 APTPublished 18/12/2025 13:28 · Modified 21/12/2025 19:39
-
12 MITREs 1 ObservablePublished 10/12/2025 18:35 · Modified 21/12/2025 18:57
-
10 MITREs 2 Malwares 1 APTPublished 02/12/2025 21:13 · Modified 21/12/2025 18:19
-
20 MITREs 2 Malwares 21 Observables 1 APTPublished 20/11/2025 22:12 · Modified 21/11/2025 09:36
-
14 MITREs 1 Malware 1 APTPublished 20/08/2025 17:38 · Modified 20/08/2025 21:20
-
8 MITREs 71 ObservablesPublished 20/05/2025 21:16 · Modified 21/05/2025 22:05
-
Unmasking the FreeDrain Network related14 MITREs 1 APTPublished 08/05/2025 21:45 · Modified 09/05/2025 17:25
-
Where to Find Aspiring Hackers related11 MITREs 7 Malwares 1 APTPublished 04/04/2025 19:54 · Modified 07/04/2025 08:04
-
19 MITREs 2 MalwaresPublished 04/04/2025 07:07 · Modified 04/04/2025 17:02
-
10 MITREs 2 MalwaresPublished 03/04/2025 17:18 · Modified 03/04/2025 19:04
-
8 MITREsPublished 27/03/2025 11:03 · Modified 27/03/2025 14:21
-
9 MITREsPublished 10/03/2025 13:04 · Modified 12/03/2025 07:54
-
20 MITREs 4 ObservablesPublished 24/02/2025 15:43 · Modified 24/02/2025 16:52
-
9 MITREs 1 Malware 137 Observables 1 APTPublished 17/02/2025 11:17 · Modified 17/02/2025 11:29
-
10 MITREs 1 MalwarePublished 13/02/2025 01:13 · Modified 13/02/2025 10:12
-
13 MITREs 1 MalwarePublished 05/02/2025 20:51 · Modified 06/02/2025 01:29
-
Unpacking the BADBOX Botnet related8 MITREs 1 Malware 19 Observables 1 APTPublished 05/02/2025 00:14 · Modified 05/02/2025 11:17
-
12 MITREs 6 MalwaresPublished 28/01/2025 17:19 · Modified 29/01/2025 17:32
-
1 CVE 7 MITREs 1 Malware 25 Observables 1 APTPublished 24/01/2025 13:30 · Modified 24/01/2025 14:24
-
6 MITREsPublished 09/11/2024 01:13 · Modified 11/11/2024 09:55
-
10 MITREs 4 Malwares 1 APTPublished 07/11/2024 22:48 · Modified 08/11/2024 10:22
-
9 MITREs 70 ObservablesPublished 23/10/2024 13:19 · Modified 23/10/2024 13:51
-
10 MITREs 2 Malwares 14 Observables 1 APTPublished 27/09/2024 17:05 · Modified 27/09/2024 17:12
-
11 MITREs 1 Malware 9 Observables 1 APTPublished 30/08/2024 17:46 · Modified 30/08/2024 18:08
-
18 MITREs 1 Malware 30 Observables 1 APTPublished 31/05/2024 14:17 · Modified 31/05/2024 14:34
Vulnerabilities (CVE) (7)
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim …
- Attack vector
- Network
- Published
- 09/06/2025
- Modified
- 21/12/2025
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a …
- Attack vector
- NETWORK
- Published
- 08/01/2021
- Modified
- 27/01/2026
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system …
- Attack vector
- Network
- Published
- 12/06/2024
- Modified
- 21/12/2025
targets
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An …
- Published
- 14/06/2022
- Modified
- 27/05/2026
Attack patterns (MITRE) (1)
-
T1102 subtechnique-ofWeb Service
Campaign (1)
- ArcaneDoor uses
Course Of Action (2)
- Restrict Web-Based Content mitigates
- Network Intrusion Prevention mitigates