T1105Ingress Tool Transfer
T1105 — Ingress Tool Transfer is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 214 detection use cases covering it and 117 threat-intel articles citing it.
Command and Control
214Use cases
117Articles
0Sub-techniques
1Tactic
Use cases covering this technique (214)
[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Microsoft Intune Device Health Scripts Microsoft Intune Mobile Apps BITSAdmin Download File Cisco Isovalent - Curl Execution With Insecure Flags Cisco NVM - Suspicious File Download via Headless Browser Cisco NVM - Webserver Download From File Sharing Website Curl Execution with Percent Encoded URL Detect Certify Command Line Arguments Download Files Using Telegram File Download or Read to Pipe Execution Linux Curl Upload File Linux Ingress Tool Transfer Hunting Linux Ingress Tool Transfer with Curl Living Off The Land Detection Log4Shell CVE-2021-44228 Exploitation LOLBAS With Network Traffic PowerShell Script Block With URL Chain PowerShell WebRequest Using Memory Stream Suspicious Curl Network Connection Windows Cabinet File Extraction Via Expand Windows Curl Download to Suspicious Path Windows Curl Upload to Remote Destination Windows DLL Module Loaded in Temp Dir Windows DNS Query Request To TinyUrl Windows File Download Via CertUtil Windows File Download Via PowerShell Windows Ingress Tool Transfer Using Explorer Windows Ldifde Directory Object Behavior Windows Process Execution From RDP Share Windows SQL Spawning CertUtil Windows SSH Proxy Command Windows Suspicious Defender Update Activity in INetCache WinRAR Spawning Shell Application Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Connection to File Sharing Domain Cisco Secure Firewall - File Download Over Uncommon Port Cisco Secure Firewall - High EVE Threat Confidence Cisco Secure Firewall - Malware File Downloaded Cisco Secure Firewall - Repeated Malware Downloads Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts Cisco Secure Firewall - Wget or Curl Download Juniper Networks Remote Code Execution Exploit Detection Any Powershell DownloadFile Any Powershell DownloadString CertUtil Download With URLCache and Split Arguments CertUtil Download With VerifyCtl and Split Arguments Curl Download and Bash Execution Wget Download and Bash Execution Windows CertUtil Download With URL Argument [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE [LLM] File read/write/delete/rename performed by a goshs process (SFTP data access) [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) [LLM] Cruciferra loader side-load DLLs and Remcos logs.dat drop [LLM] Browser-assembled SourTrade executable dropped with campaign-domain origin (MotW) [LLM] SourTrade ServiceWorker build-instruction fetch (/config + /sw.js on campaign domains) [LLM] Java (fat-JAR) outbound fetch of remote JAR / SSRF egress to public IP (CVE-2026 [LLM] BlueNoroff typosquatted Zoom/Teams infrastructure network contact [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) [LLM] TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) [LLM] msaRAT: curl.exe downloading MSI payload into ProgramData [LLM] Financial_report.bat dropper downloaded from ClickUp attachment host [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) [LLM] Network/DNS contact to Q2 2026 campaign infrastructure (pixeldrain payload + ClickUp dropper hosts) [LLM] msaRAT delivery: curl.exe fetching fake Windows-update MSI to ProgramData over HTTP [LLM] Unsanctioned RMM trio deployment: Endpoint Central, Mesh Agent, Tactical RMM [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ [LLM] Ruby/gem process downloading payload from git.disroot.org (SleeperGem) [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop [LLM] rundll32 loading DLL from remote WebDAV @ssl GUID share with ordinal export (ACR Stealer) [LLM] Endpoint traffic to ACR Stealer C2 / dead-drop domains [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains [LLM] HelloProxy C2-handler artifact: tesh4RPC.txt written to C:\Users\Public [LLM] Second-stage sync.js dropped under OS 'NodeJS' masquerade directory [LLM] Node.js retrieving Miasma second stage from IPFS gateway (specific CIDs) [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot [LLM] Talos prevalent-malware SHA256 execution (UAT-7810 telemetry batch) [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices [LLM] Outbound egress from shell/downloader child of a Python (Langroid) process [LLM] GitHub Actions runner outbound to gist.githubusercontent.com (tj-actions/changed-files CVE-2025-30066) [LLM] 9router chain: node fetches tailscale.com/install.sh then spawns sudo -S sh within seconds [LLM] curl/wget child of 9router node fetching tailscale.com/install.sh (probe or exploit delivery) [LLM] PurpleFox fileless infection: remote MSI via msiexec + reflective PE injection [LLM] LoLBin abuse: certutil decode/urlcache, bitsadmin transfer, wmic process-call-create [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant [LLM] Bun v1.3.13 runtime pulled from GitHub Releases during npm install (Phantom Gyp staging) [LLM] Outbound connection to CL-STA-1062 / TinyRCT C2 and tool-staging infrastructure [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 [LLM] easy-day-js postinstall dropper spawning node.exe with C2 IP passed as argument [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] Shai-Hulud npm preinstall Bun bootstrap (setup_bun.js / bun_environment.js) [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases [LLM] Miasma loader fetches standalone Bun v1.3.13 from oven-sh GitHub releases during install [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) [LLM] Bun runtime download to /tmp from a node process during npm install [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory [LLM] cscript.exe launching .vbs from .laravel_locale temp directory [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory [LLM] VS Code/Cursor extension host fetches dropper from nrwl/nx orphan commit on GitHub [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) [LLM] Malicious node-ipc package landed on disk under node_modules [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) [LLM] Python child process executing lightning _runtime/start.py bootstrapper [LLM] Mini Shai-Hulud payload file drop: setup.mjs/execution.js by hash & size in node_modules [LLM] Qinglong cryptominer payload download from file.551911.xyz [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path [LLM] Malicious axios or plain-crypto-js package files written to node_modules [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) [LLM] TeamPCP WAV-stego payload drop (hangup.wav / ringtone.wav) [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop [LLM] GlassWorm Stage-3 RAT installation under %APPDATA%\QtCvyfVWKH\index.js [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper [LLM] VSCode-family host fetching from raw.githubusercontent.com/BlokTrooper/extension path [LLM] Glassworm side-staged Node.js runtime under %APPDATA%\_node_x86 / _node_x64 [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download [LLM] Cacheract memdump.py download/execution on CI runner or developer host [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) [LLM] Executable dropped into C:\inetpub\pub\ shared directory [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install) [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com [LLM] Log4Shell outbound JNDI callback from Java process to LDAP/RMI (CVE-2021-44228) [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget [LLM] Java process outbound LDAP/RMI to fetch remote class — SnakeYAML JNDI gadget [LLM] Python child-of-python making download-and-exec egress to non-PyPI host [LLM] Lockfile injection: npm/yarn fetching dependencies from GitHub gist/repo instead of the registry [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) [LLM] Outbound connection to Spring4Shell Mirai staging IPs (107.174.133.167 / 194.31.98.186) [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) [LLM] Java process making outbound LDAP/RMI callout to public host (JNDI egress) [LLM] Java process outbound LDAP/RMI egress (CVE-2021-44832 remote JNDI data source load) [LLM] Log4Shell JNDI class fetch: java process outbound to LDAP/RMI ports [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) [LLM] Java process outbound to LDAP/RMI/DNS callback port — Log4Shell JNDI fetch [LLM] Java process outbound LDAP/RMI to public IP (Log4Shell JNDI callback) [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store [LLM] ImageMagick convert lineage egress to public IP (url() delegate / netcat reverse shell) [LLM] strong_password 0.0.7 backdoor: Ruby app server fetches second-stage payload from pastebin.com/raw/xa456PFtArticles citing this technique (117)
crit Don’t swing at everything art-106
crit Begun, the Patch Wars have art-150
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Injection art-257
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590