T1105 Ingress Tool Transfer — ATT&CK Technique
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, certutil, and PowerShell commands such as IEX(New-Object Net.WebClient).downloadString() and Invoke-WebRequest. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`. A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`). Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by User Execution (typically after interacting with Phishing lures). Files can also be transferred using various Web Services as well as native or otherwise present tools on the victim system. In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.
Detection coverage (50)
- Pandemic Registry Key critical
- Greenbug Espionage Group Indicators critical
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE medium
- DarkGate - Autoit3.EXE File Creation By Uncommon Process medium
- Suspicious Curl File Upload - Linux medium
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load high
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 high
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access high
- Axios NPM Compromise Indicators - Linux high
- Axios NPM Compromise File Creation Indicators - Linux high
- Axios NPM Compromise Indicators - macOS high
- Axios NPM Compromise File Creation Indicators - MacOS high
- Axios NPM Compromise Indicators - Windows high
- Curl.EXE Execution low
- Network Connection Initiated From Users\Public Folder medium
- File Download Via Curl.EXE medium
- Potential Data Exfiltration Via Curl.EXE medium
- Download File To Potentially Suspicious Directory Via Wget medium
- Hidden Flag Set On File/Directory Via Chflags - MacOS medium
- Process Execution From WebDAV Share low
- Cisco Stage Data low
- Remote File Copy low
- Wget Creating Files in Tmp Directory medium
- Curl Usage on Linux low
- PUA - Nimgrab Execution high
- File Download Via Nscurl - MacOS medium
- Potential In-Memory Download And Compile Of Payloads medium
- Executable from Webdav medium
- Download from Suspicious Dyndns Hosts medium
- Password Protected ZIP File Opened (Suspicious Filenames) high
- AppX Package Installation Attempts Via AppInstaller.EXE medium
- Suspicious Deno File Written from Remote Source low
- Potentially Suspicious File Creation by OpenEDR's ITSMService medium
- Suspicious File Created by ArcSOC.exe high
- Suspicious Desktopimgdownldr Target File high
- Legitimate Application Writing Files In Uncommon Location high
- Uncommon Network Connection Initiated By Certutil.EXE high
- Suspicious Dropbox API Usage high
- Suspicious Non-Browser Network Communication With Telegram API medium
- Network Connection Initiated By IMEWDBLD.EXE high
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder high
- Local Network Connection Initiated By Script Interpreter medium
- Outbound Network Connection Initiated By Script Interpreter high
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location high
- PowerShell Download Via Net.WebClient - PowerShell Classic low
- Potential COM Objects Download Cradles Usage - PS Script medium
- Suspicious Download From File-Sharing Website Via Bitsadmin high
- File Download with Headless Browser high
- File Download via CertOC.EXE medium
- File Download Via Bitsadmin To A Suspicious Target Folder high
Malware using this technique
- HTTPBrowser
- SideTwist
- BRICKSTORM
- Mivast
- PoetRAT
- Dyre
- TinyTurla
- Turian
- BeaverTail
- Zeus Panda
- Mafalda
- Dacls
- RARSTONE
- Pteranodon
- ANDROMEDA
- Flagpro
- Mongall
- Solar
- GrimAgent
- POWERSOURCE
- GuLoader
- SocGholish
- FlawedAmmyy
- Dtrack
- Squirrelwaffle
- Shark
- DOGCALL
- Caterpillar WebShell
- LODEINFO
- SpicyOmelette
- Hydraq
- Orz
- Samurai
- POSHSPY
- Peppy
- LightNeuron
- njRAT
- JSS Loader
- Hi-Zor
- DarkTortilla
- NETWIRE
- NavRAT
- RogueRobin
- gh0st RAT
- Bisonal
- LOWBALL
- Hancitor
- Smoke Loader
- Chaes
- FoggyWeb
Threat actors using this technique
- Fox Kitten
- BITTER
- HAFNIUM
- Cobalt Group
- Cinnamon Tempest
- BlackByte
- Tropic Trooper
- Scattered Spider
- Lazarus Group
- PLATINUM
- APT15
- Whitefly
- APT37
- SideCopy
- TA2541
- Kimsuky
- Turla
- Gamaredon Group
- APT40
- APT10
- Molerats
- APT29
- Rocke
- Sidewinder
- APT35
- Aquatic Panda
- APT38
- Gorgon Group
- APT39
- APT28
- APT27
- Rancor
- FIN13
- Medusa Group
- MuddyWater
- APT18
- TeamTNT
- Void Manticore
- OilRig
- Storm-1811
- Daggerfly
- Play Ransomware
- LazyScripter
- APT32
- Silence
- Confucius
- APT33
- Conti
- Volatile Cedar
- Evilnum