| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols | |
| Enterprise | T1102 | .002 | 网络服务: Bidirectional Communication |
One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators.[1] |
| Enterprise | T1105 | 输入工具传输 |
CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account.[1] |
|