T1568.002: T1568.002
Essential information
- MITRE technique ID
T1568.002- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 27/04/2026 16:36
- Author / Source
- The MITRE Corporation
Aliases
Domain Generation Algorithms
Platforms
windows macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (11)
-
Storm-0249 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:18 · Modified 21/12/2025 13:18
-
play usesThe MITRE Corporation Confidence 100
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Grandoreiro usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:03 · Modified 21/12/2025 03:03
-
OP-512 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 08/06/2026 10:23 · Modified 08/06/2026 10:23
-
MirrorFace usesAlienVault Confidence 100
[MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:36 · Modified 04/05/2026 16:33 -
medusa usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 08:55 · Modified 21/12/2025 07:18 -
The MITRE Corporation Confidence 100
[TA551](https://attack.mitre.org/groups/G0127) is a financially-motivated threat group that has been active since at least 2018. (Citation: Secureworks GOLD CABIN) The group has primarily targeted English, German, Italian, and Japanese …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Danabot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:14 · Modified 21/12/2025 14:25
-
ITG05 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:42 · Modified 21/12/2025 03:43
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Malware (62)
-
BadIIS usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Grandoreiro - S0531 usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
- DarkWatchman
- POSHSPY
- Grandoreiro
-
PhantomCore usesFamilyPublished 23/01/2026 10:12 · Modified 23/01/2026 10:12
-
Mekotio usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
-
RMMProject usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
perfcc usesFamilyPublished 17/09/2024 11:14 · Modified 17/09/2024 11:14
-
PLUSINJECT usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
Ebury usesFamilyPublished 15/05/2024 16:00 · Modified 15/05/2024 16:00
-
GhostKit usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
- Aria-body
-
ToughProgress usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
BadPotato usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
- Conficker
-
PlugX - S0013 usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
DanaBot usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
- CHOPSTICK
-
SilentCryptoMiner usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
- MiniDuke
-
gsocket usesFamilyPublished 14/05/2026 20:10 · Modified 14/05/2026 20:10
-
Brute Ratel usesFamilyPublished 27/05/2025 10:35 · Modified 27/05/2025 10:35
-
Potemkin usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
Rungan usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
- OCEANMAP
-
Meterpreter usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
- Milan
-
hero.dll usesFamilyPublished 12/02/2026 09:29 · Modified 12/02/2026 09:29
- Shark
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 31/05/2017 23:32 · Modified 08/06/2026 10:23 - MASEPIE
-
hero.exe usesFamilyPublished 12/02/2026 09:29 · Modified 12/02/2026 09:29
- Bazar
- BONDUPDATER
-
NOOPDOOR usesFamilyPublished 27/11/2024 18:31 · Modified 27/11/2024 18:31
-
COROXY usesFamilyPublished 01/11/2025 10:24 · Modified 01/11/2025 10:24
- STEELHOOK
-
EfsPotato usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 08/06/2026 10:23 · Modified 08/06/2026 10:23
-
Gamshen usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Bedep usesFamilyPublished 22/04/2026 22:57 · Modified 22/04/2026 22:57
-
Havoc usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
Angler usesFamilyPublished 22/04/2026 22:57 · Modified 22/04/2026 22:57
-
SweetPotato usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
PE_URSNIF usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
HiddenFace usesFamilyPublished 18/03/2025 20:59 · Modified 18/03/2025 20:59
-
LODEINFO usesFamilyPublished 19/11/2024 09:19 · Modified 19/11/2024 09:19
-
Medusa usesFamilyPublished 06/04/2026 20:26 · Modified 06/04/2026 20:26
-
Guildma usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
- SombRAT
-
Chisel usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
QakBot usesFamilyPublished 30/05/2024 14:20 · Modified 30/05/2024 14:20
- CCBkdr
- Doki
-
TangleBot usesFamilyPublished 26/06/2024 08:23 · Modified 26/06/2024 08:23
-
Uphero.exe usesFamilyPublished 12/02/2026 09:29 · Modified 12/02/2026 09:29
- Vadokrist
-
EtherRAT usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
POISONPLUG.SHADOW usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
PLUSDROP usesFamilyPublished 10/06/2025 10:52 · Modified 10/06/2025 10:52
-
XMRig usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
Reports (13)
-
AlienVault Confidence 100 8 MITREs 5 Malwares 200 IOCs 200 ObservablesPublished 18/06/2026 21:31 · threat-report
-
AlienVault Confidence 100 19 MITREs 4 Malwares 22 IOCs 22 ObservablesPublished 16/06/2026 16:27 · Modified 16/06/2026 17:19 · threat-report
-
AlienVault Confidence 100 19 MITREs 11 Malwares 7 IOCs 7 Observables 1 APTPublished 05/06/2026 20:07 · Modified 08/06/2026 08:23 · threat-report
-
AlienVault Confidence 100 21 MITREs 2 Malwares 7 IOCs 7 ObservablesPublished 28/05/2026 12:56 · Modified 28/05/2026 15:34 · threat-report
-
1 CVE 16 MITREs 2 Malwares 1 ObservablePublished 22/04/2026 22:57 · Modified 27/04/2026 14:36
-
8 MITREs 3 Observables 1 APTPublished 10/12/2025 09:17 · Modified 21/12/2025 18:53
-
7 MITREs 17 ObservablesPublished 06/03/2025 12:31 · Modified 06/03/2025 15:41
-
1 CVE 11 MITREs 2 Malwares 18 ObservablesPublished 17/09/2024 11:14 · Modified 17/09/2024 11:28
-
18 MITREs 3 Malwares 16 ObservablesPublished 03/09/2024 20:00 · Modified 03/09/2024 20:20
-
1 CVE 21 MITREs 2 Malwares 27 Observables 1 APTPublished 02/08/2024 08:41 · Modified 02/08/2024 09:03
-
11 MITREs 1 Malware 2 Observables 1 APTPublished 22/07/2024 16:03 · Modified 22/07/2024 16:13
-
A New Compact Variant Discovered related8 MITREs 2 Malwares 50 Observables 1 APTPublished 26/06/2024 08:23 · Modified 26/06/2024 08:56
-
12 MITREs 1 Malware 1 APTPublished 14/05/2024 08:16 · Modified 14/05/2024 08:28
Vulnerabilities (CVE) (8)
Microsoft Outlook Information Disclosure Vulnerability
- Attack vector
- NETWORK
- Published
- 12/12/2023
- Modified
- 21/12/2025
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, …
- Published
- 10/05/2022
- Modified
- 20/12/2025
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the …
- Attack vector
- Network
- Published
- 14/03/2023
- Modified
- 21/12/2025
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code …
- Attack vector
- NETWORK
- Published
- 03/03/2023
- Modified
- 21/12/2025
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an …
- Attack vector
- Network
- Published
- 06/02/2025
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Attack vector
- Network
- Published
- 15/02/2024
- Modified
- 21/12/2025
Attack patterns (MITRE) (1)
-
T1568 subtechnique-ofDynamic Resolution
Tool (2)
-
ngrok usesThe MITRE Corporation Confidence 100
[ngrok](https://attack.mitre.org/software/S0508) is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public …
Published 14/09/2023 20:56 · Modified 27/03/2026 01:07 -
AsyncRAT usesThe MITRE Corporation Confidence 100
[AsyncRAT](https://attack.mitre.org/software/S1087) is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.(Citation: Morphisec Snip3 May 2021)(Citation: Cisco Operation Layover …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07
Course Of Action (2)
- Network Intrusion Prevention mitigates
- Restrict Web-Based Content mitigates