ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0087×

53 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
GroupAPT39

APT39 leveraged spearphishing emails with malicious links to initially compromise victims.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

T1588.002
Tool
GroupAPT39

APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.