Cobalt Group has used public sites such as and to upload files and then download them to victim computers.[106][1] The group's JavaScript backdoor is also capable of downloading files.[107]

OSX/Shlayer can download payloads, and extract bytes from files. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.[318][319][320][321]

