T1205: T1205
Essential information
- MITRE technique ID
T1205- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Traffic Signaling
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
| mitre-attack | defense-evasion |
| mitre-attack | persistence |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (17)
-
UNC3886 usesThe MITRE Corporation Confidence 100
[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
UAC-0057 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:45 · Modified 21/12/2025 15:45
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 22/05/2026 04:12 -
PolarEdge usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:57 · Modified 21/12/2025 16:57
-
Dust Specter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 03/03/2026 18:14 · Modified 03/03/2026 18:14
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Winnti usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:07 · Modified 20/12/2025 22:07
-
BBTok usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:42 · Modified 21/12/2025 06:42
-
UNC5221 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:58 · Modified 21/12/2025 04:58
-
Water Barghest usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:58 · Modified 21/12/2025 07:58
-
AISURU usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:49 · Modified 21/12/2025 17:49
-
ShadyPanda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:23 · Modified 21/12/2025 19:23
-
Tadashi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 30/04/2026 10:17 · Modified 30/04/2026 10:17
-
RudePanda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:42 · Modified 21/12/2025 17:42
-
The MITRE Corporation Confidence 100
[APT-C-36](https://attack.mitre.org/groups/G0099) is a suspected South America espionage group that has been active since at least 2018. The group mainly targets Colombian government institutions as well as important corporations …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
LapDogs usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:11 · Modified 21/12/2025 15:11
Malware (65)
-
ConfuserEx usesFamilyPublished 27/08/2025 19:54 · Modified 27/08/2025 19:54
-
TWINTALK usesFamilyPublished 02/03/2026 17:44 · Modified 02/03/2026 17:44
- SYNful Knock
-
SPAWNSNARE usesFamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
-
REPTILE usesFamilyPublished 11/04/2025 15:42 · Modified 11/04/2025 15:42
- Ryuk
-
WingtbCLI usesFamilyPublished 22/10/2025 19:02 · Modified 22/10/2025 19:02
-
VLTRig usesFamilyPublished 29/04/2026 19:42 · Modified 29/04/2026 19:42
-
MystRodX usesFamilyPublished 28/08/2025 10:25 · Modified 28/08/2025 10:25
-
Glutton usesFamilyPublished 11/12/2024 19:24 · Modified 11/12/2024 19:24
-
Bashlite usesFamilyPublished 28/01/2026 13:31 · Modified 28/01/2026 13:31
-
Mirai usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
- Beep
-
ShortLeash usesFamilyPublished 26/06/2025 21:14 · Modified 26/06/2025 21:14
- Umbreon
-
SPLITDROP usesFamilyPublished 02/03/2026 17:44 · Modified 02/03/2026 17:44
- Pandora
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
Maggie usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
GHOSTFORM usesFamilyPublished 02/03/2026 17:44 · Modified 02/03/2026 17:44
-
LummaC2 usesFamilyPublished 16/01/2026 20:33 · Modified 16/01/2026 20:33
- HinataBot
-
SEASPY usesFamilyPublished 19/02/2026 16:01 · Modified 19/02/2026 16:01
-
Atera Agent usesFamilyPublished 18/09/2024 08:29 · Modified 18/09/2024 08:29
-
Infinity V+ usesFamilyPublished 03/12/2025 20:19 · Modified 03/12/2025 20:19
- Uroburos
-
BRUSHFIRE usesFamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
-
BBTok usesFamilyPublished 26/09/2024 12:55 · Modified 26/09/2024 12:55
-
TWINTASK usesFamilyPublished 02/03/2026 17:44 · Modified 02/03/2026 17:44
-
PureCrypter usesFamilyPublished 10/10/2025 08:25 · Modified 10/10/2025 08:25
-
Emmenhtal Loader usesFamilyPublished 30/01/2026 08:20 · Modified 30/01/2026 08:20
- BUSHWALK
-
ToneShell usesFamilyPublished 17/04/2026 18:56 · Modified 17/04/2026 18:56
-
SPAWNSLOTH usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:44 · Modified 21/12/2025 08:44
-
HijackServer usesFamilyPublished 22/10/2025 19:02 · Modified 22/10/2025 19:02
-
TRANSLATEXT usesFamilyPublished 28/06/2024 07:46 · Modified 28/06/2024 07:46
-
TrailBlazer - S0682 usesFamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
- Winnti for Linux
-
WeTab usesFamilyPublished 03/12/2025 20:19 · Modified 03/12/2025 20:19
- Penquin
-
Rhadamanthys usesFamilyPublished 29/04/2026 02:24 · Modified 29/04/2026 02:24
-
SPAWNWAVE usesFamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
- Chaos
-
AIRASHI usesFamilyPublished 25/09/2025 09:20 · Modified 25/09/2025 09:20
-
Clean Master usesFamilyPublished 03/12/2025 20:19 · Modified 03/12/2025 20:19
- BOLDMOVE
-
Aisuru usesFamilyPublished 29/01/2026 03:42 · Modified 29/01/2026 03:42
-
Ngioweb usesFamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
- Bumblebee
-
xlabs_v1 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 30/04/2026 10:17 · Modified 30/04/2026 10:17
-
J-magic usesFamilyPublished 23/01/2025 21:03 · Modified 23/01/2025 21:03
-
PUBLOAD usesFamilyPublished 07/04/2026 11:11 · Modified 07/04/2026 11:11
-
NetSupport RAT usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
Remcos RAT usesFamilyPublished 17/06/2026 18:20 · Modified 17/06/2026 18:20
-
cd00r usesFamilyPublished 23/01/2025 21:03 · Modified 23/01/2025 21:03
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
- ZIPLINE
-
XFiles Stealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 30/01/2026 09:49 · Modified 30/01/2026 09:49
-
PolarEdge usesFamilyPublished 01/09/2025 09:30 · Modified 01/09/2025 09:30
- Kobalos
- Zerobot
-
UPX usesFamilyPublished 27/08/2025 19:54 · Modified 27/08/2025 19:54
-
Dero usesFamilyPublished 21/05/2025 23:03 · Modified 21/05/2025 23:03
-
HijackDriverManager usesFamilyPublished 22/10/2025 19:02 · Modified 22/10/2025 19:02
-
VoidLink usesFamilyPublished 26/03/2026 11:59 · Modified 26/03/2026 11:59
Reports (15)
-
19 MITREs 3 Malwares 10 Observables 1 APTPublished 29/04/2026 19:42 · Modified 30/04/2026 08:17
-
18 MITREs 1 Malware 2 ObservablesPublished 26/03/2026 11:59 · Modified 27/03/2026 00:10
-
20 MITREs 3 Malwares 1 APTPublished 03/12/2025 20:19 · Modified 21/12/2025 18:23
-
9 CVEs 18 MITREs 2 Malwares 11 Observables 1 APTPublished 25/09/2025 09:20 · Modified 25/09/2025 14:48
-
15 MITREs 1 Malware 12 ObservablesPublished 28/08/2025 10:25 · Modified 28/08/2025 13:45
-
1 CVE 21 MITREs 3 Malwares 37 Observables 1 APTPublished 27/08/2025 19:54 · Modified 27/08/2025 20:27
-
19 MITREs 5 Malwares 1 APTPublished 04/04/2025 07:07 · Modified 04/04/2025 17:02
-
20 MITREs 3 Malwares 4 ObservablesPublished 23/01/2025 21:03 · Modified 24/01/2025 08:23
-
16 MITREs 2 MalwaresPublished 17/01/2025 18:13 · Modified 20/01/2025 11:13
-
15 MITREs 1 Malware 5 Observables 1 APTPublished 11/12/2024 19:24 · Modified 11/12/2024 19:36
-
10 MITREs 1 Malware 66 Observables 1 APTPublished 18/11/2024 14:21 · Modified 18/11/2024 16:38
-
19 MITREs 1 Malware 1 APTPublished 26/09/2024 12:55 · Modified 27/09/2024 17:47
-
A hard look at BBTok related19 MITREs 1 Malware 19 Observables 1 APTPublished 26/09/2024 12:55 · Modified 26/09/2024 13:10
-
20 MITREs 1 Malware 5 ObservablesPublished 05/08/2024 08:39 · Modified 05/08/2024 09:05
-
19 MITREs 2 Malwares 21 ObservablesPublished 26/07/2024 08:25 · Modified 26/07/2024 09:00
Vulnerabilities (CVE) (44)
targets
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions …
- Attack vector
- NETWORK
- Published
- 23/08/2022
- Modified
- 21/12/2025
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in …
- Attack vector
- NETWORK
- Published
- 11/07/2025
- Modified
- 21/12/2025
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, …
- Attack vector
- NETWORK
- Published
- 28/01/2020
- Modified
- 21/12/2025
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any …
- Attack vector
- NETWORK
- Published
- 27/04/2022
- Modified
- 20/12/2025
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an …
- Attack vector
- Network
- Published
- 03/03/2025
- Modified
- 21/12/2025
targets
targets
targets
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 01/05/2015
- Modified
- 22/04/2026
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim …
- Attack vector
- Network
- Published
- 09/06/2025
- Modified
- 21/12/2025
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute …
- Attack vector
- Network
- Published
- 31/05/2023
- Modified
- 21/12/2025
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
- Published
- 03/11/2021
- Modified
- 20/12/2025
targets
targets
- Published
- 20/12/2025
- Modified
- 20/12/2025
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of …
- Attack vector
- NETWORK
- Published
- 08/07/2024
- Modified
- 21/12/2025
targets
targets
targets
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a …
- Attack vector
- Network
- Published
- 12/11/2024
- Modified
- 27/05/2026
targets
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- Published
- 12/12/2024
- Modified
- 12/12/2024
In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-qspi: check return value after calling platform_get_resource_byname() It will cause null-ptr-deref …
- Published
- 26/02/2025
- Modified
- 26/02/2025
targets
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
- Published
- 10/01/2022
- Modified
- 20/12/2025
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and …
- Published
- 16/05/2022
- Modified
- 20/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
targets
targets
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol …
- Published
- 10/02/2015
- Modified
- 07/05/2026
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured …
- Published
- 03/11/2021
- Modified
- 20/12/2025
targets
targets
targets
- Published
- 20/12/2025
- Modified
- 21/12/2025
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path …
- Published
- 20/12/2017
- Modified
- 13/05/2026
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON …
- Attack vector
- NETWORK
- Published
- 06/01/2023
- Modified
- 21/12/2025
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This …
- Published
- 19/12/2017
- Modified
- 13/05/2026
targets
targets
Attack patterns (MITRE) (2)
-
T1205.001 subtechnique-ofPort Knocking
-
Socket Filters subtechnique-of
Campaign (2)
- Cutting Edge uses
- RedPenguin uses
Course Of Action (2)
- Filter Network Traffic mitigates
- Disable or Remove Feature or Program mitigates