T1207: Rogue Domain Controller
Essential information
- MITRE technique ID
T1207- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:09
- Author / Source
- The MITRE Corporation
Aliases
T1207
Platforms
windows
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (10)
-
DarkGate usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:58 · Modified 21/12/2025 04:30
-
TA-ShadowCricket usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:33 · Modified 21/12/2025 14:33
-
UTA0218 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:18 · Modified 21/12/2025 04:18
-
Chinese state actors usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:10 · Modified 21/12/2025 05:10
-
UNC1860 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:33 · Modified 21/12/2025 06:33
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:00 · Modified 21/12/2025 07:00
-
StormBamboo usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:17 · Modified 21/12/2025 06:17
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:11 · Modified 21/12/2025 06:11
-
DoNex usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:34 · Modified 21/12/2025 03:34
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:19 · Modified 21/12/2025 08:19
Malware (64)
-
TEMPLELOCK usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
Impersoni-Fake-Ator usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
RELOADEXT usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
VoidLink usesFamilyPublished 26/03/2026 11:59 · Modified 26/03/2026 11:59
-
UPDTAE usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
PowHeartBeat usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
Upm usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
DoNex usesFamilyPublished 10/07/2024 09:33 · Modified 10/07/2024 09:33
-
ROTPIPE usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
FACEFACE usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
CredentialStealer usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
TEMPLEPLAY usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
BABYWIPER usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
RUDEBIRD usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
Pemodifier usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
PocoProxy usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
TEMPLEDROP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:33 · Modified 21/12/2025 06:33
-
CoreWarrior usesFamilyPublished 15/10/2024 11:26 · Modified 15/10/2024 11:26
-
DarkRace usesFamilyPublished 10/07/2024 09:33 · Modified 10/07/2024 09:33
-
LockBit usesFamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
-
ShadUser usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
EAGERBEE usesFamilyPublished 06/01/2025 21:27 · Modified 06/01/2025 21:27
-
zylogin usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
IcedID - S0483 usesFamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FsyNet usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
WINTAPIX usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
NUPAKAGE usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
POCOSTICK usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
Wgdrop usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
- GOST
-
MaggieScan usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
SASHEYAWAY usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
Zloader usesFamilyPublished 22/09/2025 19:40 · Modified 22/09/2025 19:40
-
DarkGate - S1111 usesFamilyPublished 09/12/2024 22:32 · Modified 09/12/2024 22:32
-
Winver.exe usesFamilyPublished 30/07/2024 16:14 · Modified 30/07/2024 16:14
-
BASEWALK usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
PhantomNet usesFamilyPublished 23/07/2025 15:42 · Modified 23/07/2025 15:42
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
OATBOAT usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
Maggie usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
MadMxShell usesFamilyPublished 15/07/2024 14:52 · Modified 15/07/2024 14:52
-
SqlShell usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
CCoreDoor usesFamilyPublished 06/06/2024 07:55 · Modified 06/06/2024 07:55
-
rlogin usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
Latrodectus usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
SPARKLOAD usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
MacMa - S1016 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:04 · Modified 21/12/2025 06:04
-
alogin usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
- MacMa
-
Client.exe usesFamilyPublished 30/07/2024 16:14 · Modified 30/07/2024 16:14
- UPSTYLE
-
TOFUDRV usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
axlogin usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
ROADSWEEP usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
HAMMERTOSS - S0037 usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
-
Sqldoor usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
Detofin usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
TEMPLEDOOR usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
- HAMMERTOSS
-
Miner-C - S0133 usesFamilyPublished 27/05/2025 23:59 · Modified 27/05/2025 23:59
-
WorkersDevBackdoor usesFamilyPublished 15/07/2024 14:52 · Modified 15/07/2024 14:52
-
VIROGREEN usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
STAYSHANTE usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
-
xlogin usesFamilyPublished 10/09/2024 08:07 · Modified 10/09/2024 08:07
Reports (11)
-
10 MITREs 13 Observables 1 APTPublished 06/12/2024 17:11 · Modified 06/12/2024 17:25
-
15 MITREs 1 Malware 3 ObservablesPublished 15/10/2024 11:26 · Modified 15/10/2024 11:45
-
1 CVE 19 MITREs 16 Malwares 22 Observables 1 APTPublished 20/09/2024 11:10 · Modified 20/09/2024 11:36
-
19 MITREs 10 Malwares 1 APTPublished 10/09/2024 08:07 · Modified 13/09/2024 06:26
-
19 MITREs 10 Malwares 11 Observables 1 APTPublished 10/09/2024 08:07 · Modified 10/09/2024 08:23
-
9 MITREs 2 Malwares 10 ObservablesPublished 30/08/2024 08:10 · Modified 30/08/2024 08:37
-
1 CVE 15 MITREs 5 Malwares 2 Observables 1 APTPublished 05/08/2024 11:29 · Modified 05/08/2024 11:35
-
19 MITREs 2 Malwares 8 Observables 1 APTPublished 30/07/2024 16:14 · Modified 30/07/2024 16:32
-
14 MITREs 2 Malwares 51 ObservablesPublished 15/07/2024 14:52 · Modified 15/07/2024 15:26
-
1 CVE 18 MITREs 1 Malware 37 Observables 1 APTPublished 11/07/2024 11:56 · Modified 11/07/2024 12:08
-
15 MITREs 9 Malwares 138 Observables 1 APTPublished 06/06/2024 07:55 · Modified 06/06/2024 08:20
Vulnerabilities (CVE) (2)
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Tool (1)
-
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of …
Published 31/05/2017 23:32 · Modified 27/03/2026 01:07