T1008 Fallback Channels — ATT&CK Technique
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
Detection coverage (5)
- New Outlook Macro Created medium
- Suspicious Outlook Macro Created high
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting high
- Outlook Macro Execution Without Warning Setting Enabled high
- Windows Outlook Macro Security Modified
Malware using this technique
- JHUHUGIT
- Linfo
- CHOPSTICK
- HOPLIGHT
- InvisiMole
- SslMM
- Ebury
- BISCUIT
- TrickBot
- Valak
- S-Type
- FatDuke
- TinyTurla
- HiddenFace
- QUIETEXIT
- Shark
- MiniDuke
- WinMM
- Bumblebee
- Exaramel for Linux
- RainyDay
- Stuxnet
- PipeMon
- OilBooster
- CharmPower
- Kazuar
- AppleSeed
- Gelsemium
- ShimRat
- Mis-Type
- Uroburos
- NETEAGLE
- SideTwist
- GlassWorm
- DustySky
- Kevin
- Derusbi
- Machete
- XTunnel
- Bazar
- Crutch
- TAINTEDSCRIBE
- Cardinal RAT
- RDAT
- QUADAGENT
- Kwampirs
- Mythic
- BlackEnergy
- Anchor