7 results found
https://attack.mitre.org/versions/v17/techniques/T1048/003

…Gholish SocGholish can exfiltrate data directly to its C2 domain via HTTP. [32] G0076 Thrip Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP. [33] S1116 WARPWIRE WARPWIRE can send captured credentials to C2 via HTTP GET or POST requests. [34] [35] S0…