72 results found (page 3 of 5)
https://attack.mitre.org/versions/v17/techniques/T1048/003

…Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. [2] [3] [4] G0050 APT32 APT32 's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. [5] G0064 APT33 APT33 has used FTP to exfiltrate files (separately from the C2 channel). [6] S01…

https://attack.mitre.org/versions/v10/techniques/T1547/001

…[16] G0022 APT3 APT3 places scripts in the startup folder for persistence. [17] G0050 APT32 APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. [18] [19] [20] G0064 APT33 APT33 has deploy…