ftp

ftp is a utility commonly available with operating systems to transfer information over the File Transfer Protocol (FTP). Adversaries can use it to transfer other tools onto a system or to exfiltrate data.[1][2]

ID: S0095
Associated Software: ftp.exe
Type: TOOL
Platforms: Linux, Windows, macOS
Version: 2.1
Created: 31 May 2017
Last Modified: 14 August 2024

Techniques Used

Domain ID Name Use
Enterprise T1048 .003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol

ftp may be used to exfiltrate data separate from the main command and control protocol.[1][2]

Enterprise T1105 Ingress Tool Transfer

ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.[1][2]

Enterprise T1570 Lateral Tool Transfer

ftp may be abused by adversaries to transfer tools or files between systems within a compromised environment.[1][2]

Groups That Use This Software

ID Name References
G0019 Naikon

[3]

G0087 APT39

[4]

G0096 APT41

[5]

G0064 APT33

[6]

G0049 OilRig

[7]

G1001 HEXANE

HEXANE probed victim infrastructure in support of HomeLand Justice.[8]

Campaigns

ID Name Description
C0038 HomeLand Justice

[9]

References