MITRE ATT&CK technique
T1105 — Ingress Tool Transfer
Last fetched
T1105 (Ingress Tool Transfer) is a MITRE ATT&CK technique tracked in WhisperGraph, serving the Command and Control tactic.
Description
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570)). On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, [certutil](https://attack.mitre.org/software/S0160), and [PowerShell](https://attack.mitre.org/techniques/T1059/001) commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.(Citation: t1105_lolbas) A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).(Citation: Google Cloud Threat Intelligence COSCMICENERGY 2023) Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by [User Execution](https://attack.mitre.org/techniques/T1204) (typically after interacting with [Phishing](https://attack.mitre.org/techniques/T1566) lures).(Citation: T1105: Trellix_search-ms) Files can also be transferred using various [Web Service](https://attack.mitre.org/techniques/T1102)s as well as native or otherwise present tools on the victim system.(Citation: PTSecurity Cobalt Dec 2016) In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.(Citation: Dropbox Malware Sync)
Tactics
Threat actors observed using this technique
- LuminousMoth
- Moses Staff
- Silence
- APT41
- Rancor
- LazyScripter
- Storm-1811
- SideCopy
- ShinyHunters
- Wizard Spider
- ZIRCONIUM
- Metador
- BlackByte
- Molerats
- FIN13
- menuPass
- Evilnum
- Medusa Group
- Elderwood
- Fox Kitten
- Ke3chang
- BRONZE BUTLER
- Gamaredon Group
- HEXANE
- Scattered Spider
- Nomadic Octopus
- Threat Group-3390
- APT3
- Cobalt Group
- APT-C-36
- BackdoorDiplomacy
- TA505
- Indrik Spider
- Play
- Mustard Tempest
- Whitefly
- Mustang Panda
- Volt Typhoon
- BITTER
- Confucius
- INC Ransom
- Dragonfly
- Lazarus Group
- HAFNIUM
- Chimera
- Ajax Security Team
- Moonstone Sleet
- TA2541
- Volatile Cedar
- Tonto Team
- IndigoZebra
- Patchwork
- Windshift
- Winter Vivern
- Darkhotel
- TA551
- Winnti Group
- Sidewinder
- APT18
- Andariel
- Daggerfly
- FIN8
- FIN7
- Leviathan
- Tropic Trooper
- Gorgon Group
- TeamTNT
- OilRig
- Kimsuky
- Rocke
- VOID MANTICORE
- Cinnamon Tempest
- GALLIUM
- APT28
- APT29
- Aquatic Panda
- Magic Hound
- TeamPCP
- APT32
- APT33
- Sandworm Team
- APT37
- APT38
- APT39
- PLATINUM
- WIRTE
- MuddyWater
- Turla
- MUSTANG PANDA
- INDRIK SPIDER
- WindShift
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1105 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.